[Shorewall-users] tc advice: ceil value

2010-06-07 Thread Raphael Bauduin
Hi, I'm setting up traffic shaping with shorewall, and I have one question about the ceil values to set in tcclasses. The outgoing interface is defined like this in tcdevices: $IF_NET 4000kbit4000kbit I've done some tests with http and https downloads to check that all is working

Re: [Shorewall-users] tc advice: ceil value

2010-06-07 Thread Sam
On 06/07/2010 04:38 AM, Raphael Bauduin wrote: > Hi, > > I'm setting up traffic shaping with shorewall, and I have one question > about the ceil values to set in tcclasses. > > The outgoing interface is defined like this in tcdevices: > $IF_NET 4000kbit4000kbit > > I've done some te

[Shorewall-users] Error

2010-06-07 Thread Orlandinei Vujanski
Know me know why the error? [Root @ CONLNX01 ~] # / etc / init.d / shorewall restart Compiling ... WARNING: Using an interface to the masq SOURCE Requires the interface to Be u When p and configured Shorewall starts / restarts / etc / shorewall / masq (line 3) Shorewall configuration compiled t

Re: [Shorewall-users] tc advice: ceil value

2010-06-07 Thread Tom Eastep
On 6/7/10 2:38 AM, Raphael Bauduin wrote: > > If my understanding of the situation is correct (link saturated), what > is the advised solution to assign the maximum bandwidth without > blocking new connections for another service? > You don't mention which version of Shorewall you are running,

Re: [Shorewall-users] Error

2010-06-07 Thread Tom Eastep
On 6/7/10 9:21 AM, Orlandinei Vujanski wrote: > Know me know why the error? > > [Root @ CONLNX01 ~] # / etc / init.d / shorewall restart > Compiling ... >WARNING: Using an interface to the masq SOURCE Requires the interface > to Be u > When p and configured Shorewall starts / restarts / etc /

[Shorewall-users] Error - resolved.

2010-06-07 Thread Orlandinei Vujanski
resolved. /etc/shorewall/masq There is a long tradition of specifying an interface name in the SOURCE column of this file. Masquerading/SNAT occurs in the Netfilter POSTROUTING chain where an incoming interface may not be specified in iptables rules. Consequently, while processing the *shorewal