On Sat, 23 Jul 2016 08:22:02 -0700 Tom Eastep <teas...@shorewall.net> wrote:
> On 07/20/2016 02:21 PM, jonetsu wrote: > > Hello, > > > > Some time ago I did a user interface for DSCP marking, taking the > > documentation from the tcrules of that time, in which it was > > mentioned that the DSCP mark can be follwoed by either F (forward > > chain) or T (postrouting - default). The current mangle > > documentation page does not have these. > > First question, why ? :) > The page *does* have them: [snip] > DSCP is one of the possible commands. Thanks. The default has changed from postrouting to forward. When MARK_IN_FORWARD_CHAIN=Yes. If not the default is prerouting. If I understand correctly, packets were being by default dscp-marked in the postrouting chain (in previous Shorewall versions according the to the tcrules page of that time) and now they're in the forward chain. With DSCP marks, are the vast majority of uses cases going to the forward chain ? What is the difference in effect between the two ? Thanks. ------------------------------------------------------------------------------ What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic patterns at an interface-level. Reveals which users, apps, and protocols are consuming the most bandwidth. Provides multi-vendor support for NetFlow, J-Flow, sFlow and other flows. Make informed decisions using capacity planning reports.http://sdm.link/zohodev2dev _______________________________________________ Shorewall-users mailing list Shorewall-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/shorewall-users