Configure Application Traffic Shaping on Sophos Firewall
Application Traffic Shaping allows Sophos Firewall to prioritise or limit individual applications such as Microsoft Teams, VoIP, OneDrive, or backup services. The complete application-based workflow is:
- Under System services > Traffic shaping, create a policy with Policy association > Applications.
- Under Applications > Application filter, configure detection for the required application.
- Under Applications > Traffic shaping default, assign the policy to the application or category.
- Under Rules and policies > Firewall rules, select the Application Filter and enable Apply application-based traffic shaping policy.
A policy with Policy association > Rules in the Shape traffic field is a different method: It shapes all traffic that matches the firewall rule, not only the application selected in the Application Filter.
⚠️ Traffic Shaping does not create additional bandwidth. It distributes a bottleneck more predictably. If the connection is constantly saturated, capacity, backups, cloud synchronisation, and other sources of load still need to be investigated.
Traffic shaping limits a data rate, not the total amount of data transferred. For consumable time or data allowances, use surfing quota and network traffic quota instead.
Plan Prerequisites and Bandwidth
Before configuring Traffic Shaping, clarify the following:
- Application Control is required for application-based shaping. It is part of Web Protection and is also included in the Standard Protection bundle. Check the status under System > Administration > Licensing. A Rules policy, however, does not require application detection.
- The firewall detects the affected application, and the traffic passes through a known firewall rule.
- Logging is enabled for this rule.
- It is clear whether upload, download, or both directions are constrained and which WAN gateway or SD-WAN path is used.
- The intended effect is defined: Guarantee reserves minimum bandwidth and allows traffic up to the limit; Limit only sets a maximum.
Sophos displays shaping values in KBps, while speed tests usually use kbps or Mbps. 1 KBps equals 8 kbps. Therefore, 100 Mbps is approximately 12,500 KBps, and 20 Mbps is approximately 2,500 KBps.
Use stable measurements, not the provider’s advertised rate. If a nominal 100/20 Mbps connection reliably delivers only 80/15 Mbps, plan with approximately 10,000/1,875 KBps. Values above the actual bottleneck cannot control it effectively.
For asymmetric connections, enable Limit upload/download separately. Teams, VoIP, VPN, and cloud backups often suffer first when the upload is saturated. The global values under System services > Traffic shaping settings only apply to outbound traffic that the firewall forwards to the WAN zone. Individual traffic-shaping policies can instead apply to inbound and outbound forwarded traffic. QoS also does not apply to system-generated firewall traffic such as pattern updates or licence synchronisation.
Configure Application-Based Traffic Shaping
The following example prioritises up to four simultaneous Teams video meetings at a small site with a stable connection of approximately 80/15 Mbps. In its Teams bandwidth requirements, Microsoft recommends approximately 2,500 kbps upload and 4,000 kbps download per endpoint for a video meeting. The example values reserve this shared requirement but must be compared with local measurements and the actual number of simultaneous meetings.
Create a Traffic Shaping Policy
Under System services > Traffic shaping, create a new policy with values such as:
- Name:
Teams Guarantee - Policy association:
Applications - Rule type:
Guarantee - Limit upload/download separately:
Enable - Priority:
1(highest priority) - Upload Guarantee / Limit:
1,250 / 1,500 KBps - Download Guarantee / Limit:
2,000 / 5,000 KBps - Bandwidth usage type:
Shared
1,250 KBps equals 10 Mbps, and 2,000 KBps equals 16 Mbps. With Shared, all applications or categories assigned to this policy share the same pool. Individual makes the value available per assigned object. Do not spread high guarantee values across too many policies because their sum must remain within the bandwidth actually available.

Traffic Shaping policies cannot be edited after they have been created. If different values are required later, first document all assignments, create a replacement policy with a new name, and initially migrate only a limited scope. Move the remaining assignments after validation, and remove the old policy only when no references remain. To roll back, reassign the old policy or None.
Create an Application Filter
Under Applications > Application filter, create a filter that contains only the required traffic:
- Enter a name such as
Microsoft Teams. - Add an application rule.
- Search the Smart Filter for
microsoft teams. - Select the relevant Teams applications and save them with Allow.

Do not treat Microsoft 365 as a single application by default. Teams, Exchange, SharePoint, and OneDrive generate different traffic and should initially be monitored separately. If the objective is detection and blocking rather than bandwidth, see Set Up and Test Sophos Firewall Application Control.
Assign the Policy to the Application
Under Applications > Traffic shaping default, locate Microsoft Teams or the relevant application category, open the entry, and select Teams Guarantee.
A policy assigned to an individual application takes precedence over a policy assigned to its category. If several shaping levels match simultaneously, Sophos uses this order: application, application category, web category, user, group, and finally firewall rule.
Enable the Firewall Rule
Under Rules and policies > Firewall rules, open the rule that actually handles the Teams traffic. In Other security features:
- Under Identify and control applications (App control), select the
Microsoft Teamsfilter. - Enable Apply application-based traffic shaping policy.
- Save the rule and generate traffic.

The Applications policy is not selected in the Shape traffic field; it comes from Traffic shaping default. If several shaping levels match at the same time, the documented order is application, application category, web category, user, group, and finally firewall rule. The Rules policy in Shape traffic therefore has the lowest priority. Combine several levels only deliberately and verify them with real traffic.
Rule order remains critical: If the traffic already matches a broader rule higher up, neither the filter nor the shaping of the later rule is applied.
Rule-Based Traffic Shaping for an Entire Rule
If all traffic of a clearly scoped firewall rule should receive the same values, a Rules policy is simpler:
- Under System services > Traffic shaping, create a policy with Policy association > Rules.
- Under Rules and policies > Firewall rules, open the affected rule.
- Under Shape traffic, select the Rules policy.
- Do not enable Apply application-based traffic shaping policy unless additional Applications policies are used.

An Application Filter does not automatically restrict a Rules policy to that application. Either limit the firewall rule itself by source, destination, and services, or use the application-based workflow. DSCP marking is not a substitute for shaping either: DSCP marks packets for downstream devices, while the shaping policy on the firewall guarantees or limits bandwidth.
Verify the Effect and Safely Adjust the Policy
After the change, do not rely on a speed test alone. Check whether:
- The traffic matches the expected firewall rule.
- Application Control logs show the expected application or Application ID.
- Reports such as Top Applications and the rule counters confirm the expected assignment.
- The affected direction is actually saturated during the test.
- Bandwidth, latency, packet loss, or call quality changes as expected.
- The test uses the same WAN gateway and SD-WAN path as production traffic.
- Feedback from users of real-time services confirms the technical measurements in practice.
For a reliable before-and-after comparison, use the same source, destination, direction, and, if possible, time period. Test Sophos Firewall Performance with iPerf and Speedtest explains suitable measurement methods. For multiple connections, also see Check Sophos Firewall SD-WAN Routing for Reply Packets and System Traffic.
Because the policy cannot be edited, create a new version with conservatively adjusted values for further tuning. Assign it first to a limited application, category, or rule, monitor logs and user feedback, and remove the old policy only after successful validation. Document the purpose, affected rule, values, owner, and review date.
When Traffic Shaping Does Not Work as Expected
The Application Is Not Detected
First, verify that the correct Application Filter is selected in the firewall rule that the traffic actually matches. For broad or encrypted cloud services, use the detected Application ID in the Application Control log to confirm classification.
Shaping Makes No Difference
If the connection is not saturated during the test, there is no visible bottleneck to control. Other common causes include values above the actual bandwidth, the wrong direction, a broader firewall rule higher up, or a different SD-WAN path.
Application-based shaping also requires all three assignments to be correct: a policy with Applications, its assignment under Traffic shaping default, and the enabled option in the firewall rule. The option alone does not assign bandwidth.
Application Traffic Stops Intermittently
SFOS 22.0 MR2 Build 546 fixes NC-178197, an issue that could intermittently stop application traffic when an application-based bandwidth policy was applied. If this symptom occurs on SFOS 22.0 GA or MR1, check the firmware version before redesigning the policies and update to MR2 or a later approved version.
Microsoft 365 or the Guest Network Remains Problematic
Assess Microsoft 365 separately for Teams, Exchange, SharePoint, and OneDrive instead of blindly guaranteeing or limiting the entire category. For the guest network, verify that its traffic matches the intended rule and that both upload and download are limited where necessary.