On Sat, 23 Jul 2016 08:22:02 -0700
Tom Eastep <teas...@shorewall.net> wrote:

> On 07/20/2016 02:21 PM, jonetsu wrote:
> > Hello,
> > 
> > Some time ago I did a user interface for DSCP marking, taking the 
> > documentation from the tcrules of that time, in which it was 
> > mentioned that the DSCP mark can be follwoed by either F (forward 
> > chain) or T (postrouting - default).  The current mangle 
> > documentation page does not have these.

> > First question, why ? :)
 
> The page *does* have them:

[snip]

> DSCP is one of the possible commands.

Thanks.  The default has changed from postrouting to forward.  When
MARK_IN_FORWARD_CHAIN=Yes.  If not the default is prerouting.

If I understand correctly, packets were being by default dscp-marked in
the postrouting chain (in previous Shorewall versions according the
to the tcrules page of that time) and now they're in the forward chain.

With DSCP marks, are the vast majority of uses cases going to the
forward chain ?  

What is the difference in effect between the two ?

Thanks.




------------------------------------------------------------------------------
What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic
patterns at an interface-level. Reveals which users, apps, and protocols are 
consuming the most bandwidth. Provides multi-vendor support for NetFlow, 
J-Flow, sFlow and other flows. Make informed decisions using capacity planning
reports.http://sdm.link/zohodev2dev
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to