Fast internet does not automatically mean low latency. If your connection feels smooth until someone starts a download or upload, bufferbloat is often the real problem. This guide shows how to fix pfSense bufferbloat using limiters, FQ-CoDel, and one floating rule so your router handles congestion properly instead of letting queues build up uncontrollably.
Why Fast Internet Can Still Feel Laggy
Bufferbloat happens when packets hit your router or ISP equipment faster than they can be processed, causing long queues and unnecessary delay. The result is high ping under load, rubber-banding in games, choppy VoIP calls, and a connection that feels inconsistent even when you have plenty of bandwidth.
A bigger internet package does not solve this on its own. More bandwidth is like adding more lanes to a motorway, but if traffic is still entering chaotic junctions with no control, latency spikes remain. What matters is queue management, not just raw speed.
What pfSense Does Better With Limiters
The modern pfSense bufferbloat fix is to use limiters with FQ-CoDel. Instead of relying on basic tail drop behaviour, FQ-CoDel actively manages queue delay and spreads bandwidth more fairly across different flows. That keeps one heavy download, update, or upload from ruining latency for everything else.
Older traffic shaper wizard setups can still work, but for most current home and small office networks, limiters are the cleaner and more practical option. They are easier to configure, easier to troubleshoot, and better suited to reducing gaming lag and keeping VoIP stable.
Before You Start
Run a bufferbloat test before changing anything so you have a baseline. A typical bad result might show a Grade C and well over 100 ms of extra latency during download or upload. After a correct limiter setup, that can drop dramatically, often into A or A+ territory with only a few milliseconds of added delay.
You should also know your real ISP speeds, not just the advertised plan. The limiter values need to sit slightly below your actual maximum throughput so pfSense controls the queue first instead of your ISP modem or upstream equipment.
Recommended pfSense FQ-CoDel Settings
Why you should under-provision slightly
Set your WAN download and upload limiters a little below your measured line rate. For example, a 600 Mbps download connection might use a 550 Mbps limiter, and an 80 Mbps upload connection might use a 75 Mbps limiter. This small sacrifice in peak throughput is usually worth it because it massively improves responsiveness under load.
Core settings to use
- Scheduler: FQ_CODEL
- Queue Length: 1000
- Enable ECN: Yes
- Bandwidth: Slightly below your real tested WAN speed
- Create a child queue for both upload and download limiter pipes
Step-by-Step pfSense Bufferbloat Fix
1. Create the download limiter
- Go to Firewall > Traffic Shaper > Limiters.
- Add a new limiter named WanDown.
- Set the bandwidth slightly below your real download speed.
- Set the Scheduler to FQ_CODEL.
- Set Queue Length to 1000.
- Enable ECN.
- Save the limiter.
2. Create the child download queue
- Under WanDown, create a child queue named WanDownQ.
- Enable the child queue.
- Leave the rest of the settings at their defaults unless you have a specific reason to change them.
- Save the queue.
3. Create the upload limiter
- Add another limiter named WanUp.
- Set the bandwidth slightly below your real upload speed.
- Set the Scheduler to FQ_CODEL.
- Set Queue Length to 1000.
- Enable ECN.
- Save the limiter.
4. Create the child upload queue
- Under WanUp, create a child queue named WanUpQ.
- Enable the child queue.
- Leave the remaining settings at default.
- Save the queue.
5. Create the floating rule
- Go to Firewall > Rules > Floating.
- Add a new rule with Action set to Pass.
- Check Quick.
- Set Interface to WAN.
- Set Direction to Out.
- Set Protocol to Any.
- Set Source to WAN address.
- Set Destination to Any.
- Open Advanced Options and find the In/Out Pipe section.
- Set the first box to WanUpQ.
- Set the second box to WanDownQ.
- Save and apply changes.
Why the Floating Rule Matters
The floating rule is what actually attaches your limiter queues to the WAN traffic. Without it, the pipes exist but do not shape the traffic the way you expect. This is one of the most common reasons people think their pfSense limiters are not working.
Because pfSense is stateful, new shaping rules usually apply to new connections rather than old ones that are already established. That means your first retest can look unchanged even when the setup is correct.
Test Results You Should Expect
A properly tuned setup often trades a small amount of peak speed for a huge latency improvement. In one example, a connection that originally scored Grade C with 123 ms of added latency improved to A+ with only around 4 ms of extra delay during downloads. That kind of improvement is far more valuable for gaming, calls, and general responsiveness than holding onto every last megabit.
For gaming, this is where bufferbloat fixes become noticeable. Matchmaking might still feel normal on a bloated line, but once the network gets busy, packet delay causes inconsistent hit registration, rubber-banding, and sudden ping spikes. Good queue management fixes the part that bandwidth alone cannot.
How to Properly Set Up Port Forwarding for Gaming and Remote Access
Troubleshooting When Your Score Does Not Improve
Clear old states first
If your retest does not improve immediately, clear firewall states or restart the device and browser you used for testing. Existing sessions may still be bypassing the new floating rule behaviour because they were created before the limiter was applied.
Common mistakes
Setting the limiter bandwidth too close to ISP maximum
Forgetting to create child queues
Applying the wrong pipes in the floating rule
Testing again without clearing old states
Assuming high bandwidth automatically means low latency
Check your local network too
Bufferbloat is a WAN queue problem, but poor local networking can still add latency on top. If you are gaming over weak wireless, congested 2.4 GHz, or a router filled with slow legacy clients, you may still feel delay even after fixing WAN shaping.
Why Your Wi-Fi Is Slow (Even With a Fast Plan)
Is This Worth It for Home and Small Office Networks?
Yes. This setup is especially useful for households with gaming, streaming, cloud backups, video calls, and multiple users sharing the same line. It is also valuable in small office setups where one large transfer can otherwise disrupt VoIP quality or remote work sessions.
The main trade-off is simple: you intentionally cap throughput slightly below the line maximum so pfSense controls the queue properly. In practice, that is almost always a good trade when the reward is much lower latency and a more stable network under load.
Final Takeaway
The best pfSense bufferbloat fix is not a complicated wizard or endless tuning. It is a clean limiter setup with FQ-CoDel, ECN enabled, child queues created correctly, and a floating WAN rule that applies those queues to traffic. Once that is in place, your connection stops feeling overloaded every time someone uses it heavily.
FAQ
It usually reduces maximum throughput slightly because you intentionally set the limiter below your true line rate. That small drop is what allows pfSense to manage the queue first and reduce latency far more effectively.
A queue length of 1000 is a common and effective starting point for this setup. It is simple, practical, and works well for many home and small office deployments.
High speed does not prevent poor queue management. If uploads or downloads create long packet queues, your ping can spike badly even on a fast connection. That is exactly what bufferbloat causes.
In most cases, no. Limiters are the simpler and more modern method for reducing bufferbloat on current networks, especially when the goal is lower latency rather than complex application-specific shaping.
Existing firewall states often keep using the old path. Clear states, restart the browser, or reconnect the test device so new sessions pass through the floating rule and limiter queues.



