TOS packet marking can be cancelled by IPTables?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Greetings to everyone!

Hope you can help me with a question. :)

I'm implementing a traffic control (shaping) scheme on
my job, based on the TOS value of the IP packet, and
next on Different Services configured on the router
(by the TOS marking).

At the moment, the scheme works this way:

1) The browser requests access to a site, using a
proxy server;

2) The proxy server identifies the user, and mark the
TOS field of the outgoing packet with an specific
value (for an example, 0x1c);

3) Looking the tcpdump records for this traffic (on
the proxy server), the packet is receiving the mark
normally. But when we try to see the traffic
"mirrored", for the exit communication links (Internet
Links), the packets lose their marking, turning to
0x00 (normal).

As the traffic goes normally (just the marks
disappear), i see that the packets are not being
dropped or rejected. I think that in any way the
packets are marked again as normal on the firewall,
but i can't confirm that.

I got two questions:

1) Does the firewall (IPTables) remove any marking
done by the proxy server?
2) If this really happens, is there any way to mark
the packets again, before they go to the router?

Any help would be very appreciated. Thanks in advance!


André 




	



	
		
_______________________________________________________ 
Yahoo! doce lar. Faça do Yahoo! sua homepage. 
http://br.yahoo.com/homepageset.html 



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux