It looks like act_conndscp has been shot down by the kernel people, at least in 
its current form.  Setting a conntrack mark from tc is regarded as “not sure if 
it is a good idea”.  The other way (conntrack to skb) is fine.  That’s sort of 
good news in that ingress is the hard bit as it’s problematic with iptables.

egress is within iptables coverage - ‘just’ need a way to store a DSCP & flag 
to conntrack mark.


Cheers,

Kevin D-B

gpg: 012C ACB2 28C6 C53E 9775  9123 B3A2 389B 9DE2 334A

_______________________________________________
Cake mailing list
Cake@lists.bufferbloat.net
https://lists.bufferbloat.net/listinfo/cake

Reply via email to