All of lore.kernel.org
 help / color / mirror / Atom feed
* [LARTC] limiting outbound passive ftp
@ 2004-07-29 21:57 nix4me
  0 siblings, 0 replies; only message in thread
From: nix4me @ 2004-07-29 21:57 UTC (permalink / raw)
  To: lartc

Hi,
I am trying to use the following script to limit my passive ftp traffic 
to 35KBytes.
Problem is, it kill's the entire connection on that computer.  The 
script is running on the same machine as the ftp server.  I was hoping 
to limit the ftp traffic, and only the ftp traffic, leaving the computer.
It seems to limit everything, i tried transfering a file with samba and 
the whole computer came to a screeching halt.
Any words of wisdom?


#!/bin/bash
#shaping passive ftp traffic

# mark the outbound passive ftp packets on ports 50000-51000
iptables -t mangle -D POSTROUTING -o eth0 -j MYSHAPER-OUT 2> /dev/null > 
/dev/null
iptables -t mangle -F MYSHAPER-OUT 2> /dev/null > /dev/null
iptables -t mangle -X MYSHAPER-OUT 2> /dev/null > /dev/null
 
iptables -t mangle -N MYSHAPER-OUT
iptables -t mangle -I POSTROUTING -o eth0 -j MYSHAPER-OUT

iptables -t mangle -A MYSHAPER-OUT -p tcp --dport 50000:51000 -j MARK 
--set-mark 1

# shape the traffic to 35Kbytes
tc qdisc del dev eth0 root
tc qdisc add dev eth0 root handle 1: htb
tc class add dev eth0 parent 1: classid 1:1 htb rate 35kbps
tc filter add dev eth0 parent 1:  prio 0 protocol ip handle 1 fw flowid 1:1
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2004-07-29 21:57 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-07-29 21:57 [LARTC] limiting outbound passive ftp nix4me

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.