I need a little help. I handle the networking for a client in a multi-tenant building. years ago I was asked to handle another client there and I split off a crappy Comcast connection to save them all money. flash forward and it is out of control. I have 14 clients their now and 1gb fiber with a /27. I now need to do some rate limiting and QOS but my current setup doesn't work.
my setup is simple. I have a rb1100(not x2) that for all intensive purposes are acting like a switch. I let each customer have a public IP to put on their router and then the RB has a bridge to the WAN. however, I can't port based throttle because the ports are (slave) because of the bridge. and I cant packet mark as the traffic doesn't seem to be routered, it is just switched. I tried turning on bridge firewall and everything broke.
here is my thought. I have a spare CCR-1009 and a spare ubiquity edgeswitch 48 port. I would like to do Vlans for each customer and trunk a set of connections to the edgeswitch. then assign customers a port on the edgeswitch and rate limit the VLAN. that way if they ever need a second port the VLAN will make sure they are still limited instead of getting double the bandwidth. this also should allow me to put in wireless with a grandstream gwn7600 as they support 16 SSID though VLANs and are WAVE2 compatible.
Am I on the right track? I have seen an ISP do this with routerboard before but they had some sweet setup that auto built vlans and queues. it was really cool. I just need something simple that keeps customers within their bandwidth limit. most will get 200/200mbps. right now they all have full gig and I worry that one bad customer might ruin it for everyone with a torrent server or something.