Re: Re: Confuse, putting packets in wrong mangle table.

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Rio Martin. wrote:
On Tuesday 25 January 2005 12:41, Andy Furniss wrote:

Is there only one proxy running?

I need to shape incoming traffic to both of these ips but i am affraid i
have to face that i am not able to shape traffic which is generate from
this box unless those two IPs were outside the box.

Maybe true - maybe not you would need to test with imq. There is also a kernel option to do with nat of local connections.

If i have one more public IP than i should not so much worry about, cause
i can shape it using IMQ.



I'll make it simple for you as possible.

i have linux box which have eth0 220.1.1.1 as primary ip and aliasses: eth0:1 192.168.1.1 , eth0:1 192.168.1.2

Both 192.168.1.1 & 192.168.1.2 NATed to 220.1.1.1
OKay, now my question is:

How do i manage and limit traffic generated from those ips (192.168.1.1 & 192.168.1.2) ? Not just traffic outside, but traffic coming to those ips from Internet.
I found it so difficult because traffic coming from internet to eth0 will be using 220.1.1.1 not 192.168.x.x

If you use IMQ and get it to hook after NAT in PREROUTING then forwarded traffic should have been denatted and have local addresses. You can use TC filters to classify for htb etc.


Traffic from internet to squid will probably have 220. IP address.

If you want to try a way without IMQ then AIUI you can patch squid so you can classify hit/miss traffic and then you could shape traffic as egress on eth0. I don't use squid - but I assume here it limits the rate it pulls miss pages to the rate that client requests.

http://www.docum.org/docum.org/faq/cache/65.html

Andy.


_______________________________________________ LARTC mailing list / LARTC@xxxxxxxxxxxxxxx http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux