From mboxrd@z Thu Jan 1 00:00:00 1970 From: Andre Correa Date: Mon, 31 Jan 2005 13:55:36 +0000 Subject: Re: [LARTC] simple questions about imq Message-Id: <41FE38D8.7070506@pobox.com> List-Id: References: <41FD1304.1080305@sch.bme.hu> In-Reply-To: <41FD1304.1080305@sch.bme.hu> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable To: lartc@vger.kernel.org Cool Toth, please let us know if you make it work. Just take care to=20 hook IMQ in the right place if you are doing NAT. You can choose to hook=20 it after or before NAT. Good luck! Andre T=F3th N=E1ndor wrote: > Hi! >=20 > I have read all informations i could find, but some things are still not = > clear. >=20 > My setup is: > ---INTERNET1(eth0)-\ /- Local net1 (eth2) > GW > ---INTERNET2(eth1)-/ \- Local net2 (eth3) >=20 > I have NAT and a working setup using HTB,SFQ, classifying with the=20 > iptables -j CLASSIFY way. I shape only the traffic coming from the=20 > internet heading to the intranet. >=20 > I would like to have a configuration like this: > ---INTERNET1(eth0)-\ /- Local net1 (eth2) > GW--imq0 > ---INTERNET2(eth1)-/ \- Local net2 (eth3) >=20 > I think it can be done this way: > iptables -t mangle -A PREROUTING -i eth0 -j IMQ --todev 0 > iptables -t mangle -A PREROUTING -i eth1 -j IMQ --todev 0 >=20 > But it would include traffic heading to the gateway directly, wouldn't=20 > it? Can i put these rules to the POSTROUTING chain? >=20 > And i can still have my CLASSIFY targets in the POSTROUTING chain,=20 > because IMQ queing will happen after it according to=20 > http://lartc.org/howto/lartc.imq.html. > So for example: > $IPTABLES -t mangle -A POSTROUTING -o $eth2 ... -j CLASSIFY --set-class=20 > 1:30 > $IPTABLES -t mangle -A POSTROUTING -o $eth3 ... -j CLASSIFY --set-class=20 > 1:30 > $IPTABLES -t mangle -A POSTROUTING -o $eth2 ... -j RETURN > $IPTABLES -t mangle -A POSTROUTING -o $eth3 ... -j RETURN >=20 > If i managed to do this, i promise, i will document it to the imq wiki. >=20 > Any advice/help is appreciated! >=20 _______________________________________________ LARTC mailing list / LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/