From: Andy Furniss <andy.furniss@dsl.pipex.com>
To: lartc@vger.kernel.org
Subject: Re: AW: AW: [LARTC] urgent question about tcng!
Date: Wed, 04 May 2005 14:23:57 +0000 [thread overview]
Message-ID: <4278DAFD.8020808@dsl.pipex.com> (raw)
In-Reply-To: <PDC8QMTiuEmmfnUmLbx00000035@pdc.ikarus.local>
Thomas Mandl wrote:
> Sorry for the stupid question, but how would I rate limit connections using
> iptables?
>
I was thinking of the patch-o-matic-ng patches connlimit and connrate,
though I've never used either and they may or may not be expensive for
many connections compared to perflow.
Connrate lets you mark packets if they are above limits - you could then
drop those later in a filter table or with a TC filter/queue.
> regards
> Thomas
> -----Ursprüngliche Nachricht-----
> Von: Andy Furniss [mailto:andy.furniss@dsl.pipex.com]
> Gesendet: Dienstag, 03. Mai 2005 16:43
> An: Andy Furniss
> Cc: mandl.t@ikarus.at; 'LARTC'
> Betreff: Re: AW: [LARTC] urgent question about tcng!
>
> Andy Furniss wrote:
>
>
>>I don't know tcng, but the reason I suggested perflow is that you want
>>each flow to have a ceil - unless you make a class and rule to match
>>each flow I can't see how you can do this. Also iptables could limit
>>the number of connections - tc can't, perflow can.
>
>
> Forgot to say you can also use iptables to limit rate per connection.
>
> Andy.
>
>
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc
prev parent reply other threads:[~2005-05-04 14:23 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-04-27 16:11 [LARTC] urgent question about tcng! Thomas Mandl
2005-04-27 16:17 ` Sylvain BERTRAND
2005-04-27 18:25 ` Jason Boxman
2005-04-27 21:22 ` Andy Furniss
2005-04-28 7:34 ` AW: " Thomas Mandl
2005-05-03 13:45 ` Andy Furniss
2005-05-03 14:42 ` Andy Furniss
2005-05-03 23:05 ` AW: " Thomas Mandl
2005-05-04 14:23 ` Andy Furniss [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4278DAFD.8020808@dsl.pipex.com \
--to=andy.furniss@dsl.pipex.com \
--cc=lartc@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.