Re: [LARTC] Terrible problem, some men in my net changed their MACs! :/

2005-05-31 Thread Krystian Antoni
for user verification pptp can be used. its free :-) On 5/31/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Yes, I have this problem too. And I came up with two ideas: one moneycomsuming, one time consuming. Money comsuming: get management switches everywhere, and limit MAClearning per port. My

Re: [LARTC] Terrible problem, some men in my net changed their MACs! :/

2005-05-30 Thread Krystian Antoni
here is my one cent :-)propably somebody is changing a MAC so you DHCP will grant them specific IP. u can try nmap them them to see whos behind that MAC (at the moment where there is only one station turned on). then by using unplug and seek-the-hacker method u can find from what switch/port he's

Re: [LARTC] Leaky bucket in TC

2005-05-27 Thread Krystian Antoni
if by leaky bucket u mean drop everything above a certain rate then htb can do this as a part of normal operation. On 5/26/05, Fatih Dzova [EMAIL PROTECTED] wrote: Hi,I am trying to control bandwidths of the connections by using TC withHTB. But I want to implement Leaky Bucket on this structure so

Re: [LARTC] HTB + IMQ + IPtables marking.

2005-05-19 Thread Krystian Antoni
1. lines: /usr/sbin/iptables -t mangle -A PREROUTING -i eth0 -j IMQ --todev 1/usr/sbin/iptables -t mangle -A PREROUTING -i eth0 -j IMQ --todev 1/usr/sbin/iptables -t mangle -A PREROUTING -i eth0 -d 202.x.1.0/24 -j MARK --set-mark 10/usr/sbin/iptables -t mangle -A PREROUTING -i eth0 -d

Re: [LARTC] ip_conntrack limit --- torrent , DC++ , eMule

2005-05-19 Thread Krystian Antoni
i think hashlimit is the new dstlimit with wider capabilities On 5/16/05, foxy 202 [EMAIL PROTECTED] wrote: Hi all,i need advice how can i limit ip_conntrack per IP.clients of network that i support often usestorrent , DC++ , eMule clients and i have lost packagesbecause they open too many ports.i

Re: [LARTC] equal bandwidth for all IPs

2005-05-19 Thread Krystian Antoni
you will have to use classful traffic shaping (QOS) with HTB / CBQ / HSFC. go to www.lartc.org and they have a pretty good document on how to get it up and running pretty fast :-) if u run in to any problems come back and ask :-)On 5/19/05, ro0ot [EMAIL PROTECTED] wrote: Hi,How can I set equal

[LARTC] iptables traversing read

2005-05-19 Thread Krystian Antoni
Hi Is there a program which allow me to see how my traffic goes through my iptables rules? Which accept it, which deny? Right now my router has a little bit of traffic and its hard to see only mine traffic.-- Miego DniaKrystian Antoni ___ LARTC mailing

Re: [LARTC] wanted A tool to measure bandwidth....

2005-05-11 Thread Krystian Antoni
U can configure MRTG to measure traffic counted by iptables FORWARD chain. This way u will measure how much each host is taking without installing snmp. On 5/12/05, KartheeK [EMAIL PROTECTED] wrote: Hello Everybody, I have configured a Linux box that does traffic shaping. Its working wonderfully

Re: [LARTC] Routing by interface as opposed to ip address?

2005-05-09 Thread Krystian Antoni
-From: Krystian Antoni [mailto: [EMAIL PROTECTED]] Sent: Sunday, May 08, 2005 12:52 PMTo: Joe DevichSubject: Re: [LARTC] Routing by interface as opposed to ip address? there is a iptables target module named ROUTE. it can help u On 5/6/05, Joe Devich [EMAIL PROTECTED] wrote: Hello all,Does anyone

Re: [LARTC] HTB stalling

2005-04-24 Thread Krystian Antoni
I have a normal kernel + vanilla one with SMP turned off.On 4/24/05, Andy Furniss [EMAIL PROTECTED] wrote:Andy Furniss wrote: Is anyone who gets the stalls using CPU as timer? I see Arpad is - another difference possibly - do you have smp as kerneloption but have one processor. I don't know if

Re: [LARTC] HTB stalling

2005-04-24 Thread Krystian Antoni
the stalls might last as long as 5 seconds and when they happen, everything including a web browser stops working. ill be back tuesday evening so then i'll try to look at my system.On 4/24/05, Andy Furniss [EMAIL PROTECTED] wrote:Andy Furniss wrote: I'll have a go at shaping on eth and see if I

Re: [LARTC] HTB stalling

2005-04-23 Thread Krystian Antoni
so i checked using your way: HTB init, kernel part version 3.17. On 4/23/05, gypsy [EMAIL PROTECTED] wrote: Krystian Antoni wrote: How to check version of HTB?? I have standart one which came with kernel 2.6.11.7, my tc says I have TC HTB version 3.3. Is this my HTB version? :-) No, it isn't.3.3

Re: [LARTC] HTB stalling

2005-04-22 Thread Krystian Antoni
The problem started with arrival of 2.6 kernels.On 4/22/05, Kunszt Arpad [EMAIL PROTECTED] wrote: Hi allHi! iam also facing the same problem what Mr Antoni have even i have done many kind of experment, but i could not resolve is this bug in FC3, but when i does the FC1 its working fine I found

Re: [LARTC] HTB stalling

2005-04-22 Thread Krystian Antoni
How to check version of HTB?? I have standart one which came with kernel 2.6.11.7, my tc says I have TC HTB version 3.3. Is this my HTB version? :-) Im not using FC3 kernel but a vanilla one so there is no much beta in it :) besides I cut most of the stuff out just for experimentation and still

Re: [LARTC] HTB stalling

2005-04-20 Thread Krystian Antoni
changing them :-) And I dont really now what is that I screw up :-) Wonna see my qos scripts? :D On 4/19/05, Andy Furniss [EMAIL PROTECTED] wrote: Krystian Antoni wrote: Hi Couple months ago I started to have a strange problem with HTB. My setup is Fedora Core 2 + Pentium 2 233 + 128 MB of ram