Hi folks,

First of all let me say an enormous THANK YOU for shorewall in
general!  It is so easy to write powerful firewall configurations with
this tool!

Well, it was until I wanted to fiddle with QoS ... now it is not so
easy unfortunately :-(

I just got VOIP at home a few weeks ago and my connection was
deplorable, which forced me to turn on QoS on my Ubuntu 12.10
firewall.    That solved my VOIP issue but it clobbered my smoking
fast HTTP speeds, and I just can't figure out why.   I'm finding the
tc files in shorewall not as easy to understand as the other stuff.  I
think I've got it right from an example I found online and don't think
it should be throttling me, but it is.

Does someone have a working example they can share?

Or alternately, I have been reading about this method of traffic
shaping where you mark packets using iptables as they come in, and
then you write your QoS rules to simply use the marks to shape.

http://www.andybev.com/index.php/Fair_traffic_shaping_an_ADSL_line_for_a_local_network_using_Linux

That looks like a good alternative for me because some of the other
QoS stuff I've read makes me believe that I might be able to just
write my own QoS script and tell shorewall to use my script instead of
the tc files per-se.

But I'm not sure how to tell shorewall to mark packets like that as
they come in.

thanks,
-Alan

-- 
“Don't eat anything you've ever seen advertised on TV”
         - Michael Pollan, author of "In Defense of Food"

------------------------------------------------------------------------------
Own the Future-Intel(R) Level Up Game Demo Contest 2013
Rise to greatness in Intel's independent game demo contest. Compete 
for recognition, cash, and the chance to get your game on Steam. 
$5K grand prize plus 10 genre and skill prizes. Submit your demo 
by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
_______________________________________________
Shorewall-users mailing list
Shorewall-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to