From: Nagy Gabor Peter <linux42@freemail.hu>
To: lartc@vger.kernel.org
Subject: [LARTC] traffic shaping question
Date: Mon, 22 Jan 2007 14:31:04 +0000 [thread overview]
Message-ID: <20070122143104.GC17795@swordfish.capgemini.hu> (raw)
In-Reply-To: <marc-lartc-105466836109505@msgid-missing>
Hi list,
I have read the lartc 9th chapter, the bandwidth management part.
I think I understand the principle, but I have a question.
So I have a firewall that has several different interfaces. The most
important for my question is the Internet interface, which is a 2mbps
leased line.
I have an interface into the protected network, I have a DMZ interface,
and I have an interface with direct connection to a client.
Here is what I need:
Internet -> DMZ + Internet -> LAN + Internet -> firewall traffic
together should not exceed 1.5mbps
At the moment I have a tbf, that limits everything that goes to the LAN,
and another that limits everything going to the internet.
I would like to shape the incoming traffic from the internet. OK, I
understand that I cannot influence the senders out there not to try to
send me packets, I can only influence how fast these packets are sent
from me.
But can I somehow treat all incoming traffic together?
Because my knowledge at the moment is only some shaping possibilities on
the LAN interface and on the DMZ interface.
I have only one idea, but I don't know if it is feasible, and if it is,
how to do that.
So I thought that I will create a virtual interface, and route all
traffic from the Internet through this one. So incoming on Internet
interface, outgoing on virtual interface, and from there incoming on the
firewall machine, or outgoing on the LAN or the DMZ interface.
Does it sound good? How can I do that? (I suppose I have to read other
chapters in the lartc guide. Could you point me out where to start? What
to look for?)
Or is there another solution? What would you recommend?
Cheers,
Gabor
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc
next prev parent reply other threads:[~2007-01-22 14:31 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-06-03 19:24 [LARTC] traffic shaping question Shawn
2003-06-03 19:37 ` Shawn
2007-01-22 14:31 ` Nagy Gabor Peter [this message]
2007-01-22 16:26 ` Marco Berizzi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20070122143104.GC17795@swordfish.capgemini.hu \
--to=linux42@freemail.hu \
--cc=lartc@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.