From: Adam Rosi-Kessel <adam@rosi-kessel.org>
To: netfilter@lists.netfilter.org
Subject: Re: HTTP slower than SSH on client behind iptables
Date: Tue, 7 Feb 2006 19:46:31 -0500 [thread overview]
Message-ID: <20060208004630.GA10508@bostoncoop.net> (raw)
In-Reply-To: <20060202145613.GA12056@bostoncoop.net>
On Thu, Feb 02, 2006 at 09:56:13AM -0500, Adam Rosi-Kessel wrote:
> On Tue, Jan 31, 2006 at 10:10:53AM +0100, Boryan Yotov wrote:
> > >On clients behind the NAT box, however, HTTP connections seem to top out
> > >around 70 kilobytes per second. ssh connections (e.g., rsync) get the
> > >full throughput of the Internet connection.
> > >As far as NAT goes, I don't hvae any special settings.
> > >Can anyone think of an explanation for this behavior? It doesn't make any
> > >sense to me.
> > Are you sure, you don't have some kind of a traffic shaping
> > active on the NAT gateway's internal interface?
> > For example: If tc is used, you could check that using:
> > tc class show dev <nat_box_internal_interface>
> > and
> > tc filter show dev <nat_box_internal_interface>
> I figured it out. Apparently I was missing some kernel modules that were
> causing wondershaper to behave oddly. I rebuilt the kernel with all QOS
> and netfilter configuration options enabled (or built as modules) and now
> internal clients can download HTTP at full speed. I suspect there was
> some option that was causing tc to not distinguish between interfaces
> despite the fact that wondershaper instructed it to only throttle the
> external interface. I'm not sure exactly which kernel setting fixed it,
> but it is now fixed.
Actually, I didn't figure it out! Apparently, just rebooting the NAT
system returns everything to full speed. Something happens, either over
time, or as the result of some occasional event, that causes internal
connections to be throttled. Any ideas what this could be?
next prev parent reply other threads:[~2006-02-08 0:46 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-01-31 3:35 HTTP slower than SSH on client behind iptables Adam Rosi-Kessel
2006-01-31 9:18 ` Boryan Yotov
[not found] ` <43DF299D.9070105@prosyst.com>
2006-01-31 14:11 ` Adam Rosi-Kessel
2006-01-31 15:33 ` Boryan Yotov
2006-01-31 15:06 ` Adam Rosi-Kessel
2006-02-02 14:56 ` Adam Rosi-Kessel
2006-02-08 0:46 ` Adam Rosi-Kessel [this message]
2006-02-08 17:16 ` Boryan Yotov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060208004630.GA10508@bostoncoop.net \
--to=adam@rosi-kessel.org \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.