On Sat, 2011-02-05 at 02:07 -0400, Optimum Wireless Services wrote: > Now, for the upload I cant get it shape with squid running in the > middle. If I remove squid then, traffic shaping works ok. > If you are doing egress shaping on the internet facing interface for the upload (which I assume you are - you can't use HTB on ingress), then it will not work for Squid. That's because Squid's traffic leaving the server is coming from the server's IP address, not from the client's IP address (Squid is generating the traffic, not the client). Therefore, your filter will never match the traffic. Normal traffic from a client is forwarded and retains its source IP address. One way to shape Squid traffic per client source IP address would be to mark the packets that are coming in from the local network (as you were doing before) and then use Squid's mark preservation feature to retain the packet's mark. However, you can't use U32 classifiers - you'll have to go back to marking packets. > Andy recommended to use ifb but, I don't know where to get the download > from. Is supposed to be on kernel 2.26.20 and up and I'm running a > kernel that "qualifies" but, cant really get ifb to do anything. No need for IFB in your case. That's only if you want to shape multiple interfaces within one qdisc. Andy -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html