All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel Borkmann <daniel@iogearbox.net>
To: Huan Le <huan@apcera.com>
Cc: netdev@vger.kernel.org
Subject: Re: tc ingress filters not applied
Date: Mon, 06 Jul 2015 19:43:13 +0200	[thread overview]
Message-ID: <559ABE31.9000405@iogearbox.net> (raw)
In-Reply-To: <loom.20150706T190215-28@post.gmane.org>

On 07/06/2015 07:24 PM, Huan Le wrote:
> Erik Hugne <erik.hugne <at> ericsson.com> writes:
>
>>
>> I'm having troubles with TC policing, the ingress filters does not seem to be
>> applied.
>>
>>
>> Kernel: net-next/latest
>> iproute2: shemminger/master
>>
>> //E
>>
>
> I observed similar behavior when configuring a filter on ingress qdisc.
> Test shows that traffic was rate-limited to the configured value.
> However, "tc filter show" does not show any filtering rule.
>
> (1) add ingress qdisc on eth1
> # tc qdisc add dev eth1 ingress
> # tc qdisc show dev eth1 ingress
> qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap \
>   1 2 2 2 1 2 0 0 1 1 1 1 1 1 1 1
> qdisc ingress ffff: parent ffff:fff1 ----------------
>
> (2) add filter under ingress qdisc
> # tc filter add dev eth1 parent ffff: protocol all \
>   u32 match ip src 0.0.0.0/0 \
>   police rate 256kbit burst 10k drop flowid :1
> # tc filter show dev eth1

You have to add the handle/parent here, otherwise this shows egress filters.

> (3) verified sch_ingress kernel module is installed
> # lsmod  | grep sch_ingress
> sch_ingress            12866  1
>
> (4) uname -a (if needed for debugging)
> Linux huan-lnx 3.16.0-30-generic #40~14.04.1-Ubuntu SMP
> Thu Jan 15 17:43:14 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux
>
> I am testing this using ubuntu 14.04 on a virtualbox VM
> (eth1 is a host-only adapter).
>
> Thanks,
> Huan
>
> --
> To unsubscribe from this list: send the line "unsubscribe netdev" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>

      reply	other threads:[~2015-07-06 17:43 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-03-30 14:15 tc ingress filters not applied Erik Hugne
2015-03-30 17:00 ` Cong Wang
2015-03-31  6:32   ` Erik Hugne
2015-07-06 17:24 ` Huan Le
2015-07-06 17:43   ` Daniel Borkmann [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=559ABE31.9000405@iogearbox.net \
    --to=daniel@iogearbox.net \
    --cc=huan@apcera.com \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.