All of lore.kernel.org
 help / color / mirror / Atom feed
From: Andy Furniss <andy.furniss@dsl.pipex.com>
To: lartc@vger.kernel.org
Subject: Re: [LARTC] Re: Confuse, putting packets in wrong mangle table.
Date: Thu, 27 Jan 2005 12:37:53 +0000	[thread overview]
Message-ID: <41F8E0A1.4060108@dsl.pipex.com> (raw)
In-Reply-To: <200501191657.15767.rio@martin.mu>

Rio Martin. wrote:
> On Tuesday 25 January 2005 12:41, Andy Furniss wrote:
> 
>>Is there only one proxy running?
>>
>>>I need to shape incoming traffic to both of these ips but i am affraid i
>>>have to face that i am not able to shape traffic which is generate from
>>>this box unless those two IPs were outside the box.
>>
>>Maybe true - maybe not you would need to test with imq.
>>There is also a kernel option to do with nat of local connections.
>>
>>>If i have one more public IP than i should not so much worry about, cause
>>>i can shape it using IMQ.
> 
> 
> 
> I'll make it simple for you as possible.
> 
> i have linux box which have eth0 220.1.1.1 as primary ip and aliasses: eth0:1 
> 192.168.1.1 , eth0:1 192.168.1.2
> 
> Both 192.168.1.1 & 192.168.1.2 NATed to 220.1.1.1
> OKay, now my question is:
> 
> How do i manage and limit traffic generated from those ips (192.168.1.1 & 
> 192.168.1.2) ? Not just traffic outside, but traffic coming to those ips from 
> Internet.
> I found it so difficult because traffic coming from internet to eth0 will be 
> using 220.1.1.1 not 192.168.x.x

If you use IMQ and get it to hook after NAT in PREROUTING then forwarded 
traffic should have been denatted and have local addresses. You can use 
TC filters to classify for htb etc.

Traffic from internet to squid will probably have 220. IP address.

If you want to try a way without IMQ then AIUI you can patch squid so 
you can classify hit/miss traffic and then you could shape traffic as 
egress on eth0. I don't use squid - but I assume here it limits the rate 
it pulls miss pages to the rate that client requests.

http://www.docum.org/docum.org/faq/cache/65.html

Andy.


_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

  parent reply	other threads:[~2005-01-27 12:37 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-01-19 10:05 [LARTC] Re: Confuse, putting packets in wrong mangle table Rio Martin.
2005-01-25 12:41 ` Andy Furniss
2005-01-26 11:08 ` Rio Martin.
2005-01-27 12:37 ` Andy Furniss [this message]
2005-01-28  6:48 ` Rio Martin.
2005-01-29  0:55 ` Andy Furniss
2005-01-29 11:30 ` Rio Martin.
2005-01-31 23:17 ` Andy Furniss
2005-02-01  5:41 ` Rio Martin.
2005-02-05 12:30 ` Andy Furniss

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=41F8E0A1.4060108@dsl.pipex.com \
    --to=andy.furniss@dsl.pipex.com \
    --cc=lartc@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.