All of lore.kernel.org
 help / color / mirror / Atom feed
* [LARTC] interesting expert problem - shaping over VPN
@ 2004-09-17 13:57 lartc
  2004-09-24  7:26 ` lartc
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: lartc @ 2004-09-17 13:57 UTC (permalink / raw)
  To: lartc

Here's a challenging problem for you experts to tackle:
                                                                                                                     
I'm trying to shape traffic going into an IPSEC interface which then goes
over a DSL PPPoE interface.  I figure I need to shape the DSL interface to
keep it's hardware queue mostly empty, and to prioritize between IPSEC and
non-IPSEC traffic.  I also have to shape going into the IPSEC, which
carries VoIP (high pri), VNC (med pri) and other (email, etc, low pri).
                                                                                                                     
I have it all set up and working, except that the IPSEC shaping doesn't
seem to do any good whatsoever.  Even if I allocate 99% of the bandwidth
to the VoIP and 99% to IPSEC over PPPoE I still get break-ups in the VoIP
signal when I do some heavy VNC.  I tried such drastic things as reducing
the "ceiling" to half of what the DSL line was spec'd (and tested) as
supporting.  I played with the numbers until they were really skewed (99%)
in favor of VoIP, but still no joy.
                                                                                                                     
So my question is, am I missing something fundamental conceptually
regarding shaping traffic into an IPSEC/VPN interface and then shaping
that along with non-VPN traffic out over the single internet connection?
Is there some buffering/queue stuff in IPSEC or PPPoE that would prevent
me shaping properly?
                                                                                                                     
I am using FreeSWAN IPSEC on Fedora Core 1.
                                                                                                                     
Thanks for your help.

_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-12-03 17:31 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-09-17 13:57 [LARTC] interesting expert problem - shaping over VPN lartc
2004-09-24  7:26 ` lartc
2004-09-26 13:26 ` lartc
2004-12-03 17:31 ` lartc

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.