AW: AW: [LARTC] qos inside ipsec tunnel

2006-11-03 Thread Martin Bene
Hi Mohan, > > What should work is to mark the packets in PREROUTING in the mangle > > table and assign them to the classes you want based on the fwmark: > Has anyone tested this? Does the mark get carried across > encapsulations or is the packet context a new one on > encapsulation? Yes, I h

Re: [LARTC] Strategy for penalising IPs with too many simultaneous sessions

2006-11-03 Thread Mohan Sundaram
Graham Leggett wrote: Hi all, I have been trying to investigate traffic shaping in an effort to solve the "unfriendly network apps" problem on a test network. I have a basis by which I'd like to shape traffic, but studying the howto doesn't uncover and existing qdisc that seems to fit what I

Re: AW: [LARTC] qos inside ipsec tunnel

2006-11-03 Thread Mohan Sundaram
Martin Bene wrote: Hi Marco, Hello everybody. I would like to do some kind of shaping inside an ipsec tunnel implemented by Openswan and linux 2.6.18.x with xfrm (no KLIPS): for example, to limit outbound smtp traffic inside the tunnel. Question: where should I attach the qdisc to? Eth0? I'm as

Re: [LARTC] Strategy for penalising IPs with too many simultaneous sessions

2006-11-03 Thread Stephen Hemminger
On Sat, 04 Nov 2006 02:09:03 +0200 Graham Leggett <[EMAIL PROTECTED]> wrote: > Hi all, > > I have been trying to investigate traffic shaping in an effort to solve > the "unfriendly network apps" problem on a test network. > > I have a basis by which I'd like to shape traffic, but studying the

[LARTC] Strategy for penalising IPs with too many simultaneous sessions

2006-11-03 Thread Graham Leggett
Hi all, I have been trying to investigate traffic shaping in an effort to solve the "unfriendly network apps" problem on a test network. I have a basis by which I'd like to shape traffic, but studying the howto doesn't uncover and existing qdisc that seems to fit what I would like to do. T

AW: [LARTC] qos inside ipsec tunnel

2006-11-03 Thread Martin Bene
Hi Marco, > Hello everybody. > I would like to do some kind of shaping inside an > ipsec tunnel implemented by Openswan and linux > 2.6.18.x with xfrm (no KLIPS): for example, to > limit outbound smtp traffic inside the tunnel. > Question: where should I attach the qdisc to? Eth0? > I'm asking thi

[LARTC] qos inside ipsec tunnel

2006-11-03 Thread Marco Berizzi
Hello everybody. I would like to do some kind of shaping inside an ipsec tunnel implemented by Openswan and linux 2.6.18.x with xfrm (no KLIPS): for example, to limit outbound smtp traffic inside the tunnel. Question: where should I attach the qdisc to? Eth0? I'm asking this, because tcpdump only s