Re: Strategy for penalising IPs with too many simultaneous sessions

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi

On Sat, Nov 04, 2006 at 07:08:04AM +0530, Mohan Sundaram wrote:
> What you are doing makes sense only if the number of connections is a 
> constrained resource. If bandwidth is the constraint, then shaping by 
> source IP irrespective of number of connections will do the job. As far 
> as I've seen, routers can support 200k connections and this is 
> sufficient for many large LANs - say 500 node LAN with 400 connections 
> per node.

I have this situation where the source IPs change on a wireless mesh.
I want fair nat. I found the fairnat script and have been reading the
lartc howto, but am not sure how to proceed.
(fairnat at http://www.metamorpher.de/fairnat/)

I want everyone to burst to (almost, a specified percentage like 90%)
full, but when all IPs are on, to share fairly irrespective of number of
connections. The IPs change dynamically. If the user doesn't know why
their P2P or download manager is slowing them down, their problem. They can 
run whatever they want. I just don't want one user to flood out the rest,
and there should be a little spare so it doesn't take time to correct
for light users.

Oh, and upload limiting (also fairly) for the lot would be good, as this
rate is limited, e.g. 512 down and 128 up. 

And it is running on freifunk on a Linksys WRT 54 GL, so performance
might be an issue on the 200Mhz processor. At the moment freifunk comes
with ingress (by internal destination IP) limiting quite nicely. The
number of clients is expected to be 0 to 64. I can deal with large
numbers of clients later, if it ever happens.

cheers,
Jan
-- 
   .~.
   /V\     Jan Groenewald
  /( )\    www.aims.ac.za
  ^^-^^
_______________________________________________
LARTC mailing list
LARTC@xxxxxxxxxxxxxxx
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc

[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux