All of lore.kernel.org
 help / color / mirror / Atom feed
* [LARTC] beginner question about imq
@ 2003-09-10 10:23 Szálka Tamás
  2003-09-10 11:33 ` Raghuveer
                   ` (9 more replies)
  0 siblings, 10 replies; 11+ messages in thread
From: Szálka Tamás @ 2003-09-10 10:23 UTC (permalink / raw)
  To: lartc

Hi!

I have to make a firewall which guarantees bandwidth to several clients 
(both upstream and downstream should be limitied). It has three interfaces, 
eth0 facing to the internet, eth1 to local network with several ip 
addresses (different subnets) and eth2 to dmz (webserver). Egress traffic 
is ok, I set up the tc rules to eth0 and the upstream limiting is fine. But 
I have to manage bandwidth of downloading too.
While eth0 has one public ip address, the firewall does masquerading to the 
local subnets (with local ip ranges). So should I set up an imq device on 
eth1 with iptables mangle through the prerouting chain to do traffic 
shaping to the subnets? In this case the packets arrive to eth1 already 
masqueraded (am I right?) and I can limit the ingress traffic of local 
adresses. Or should I use the imq on eth0? Doesn't it bothers egress 
shaping? I'm confused a little bit... :-s
Can you help me?

Thanks
Tom



_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2003-09-12 21:22 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-09-10 10:23 [LARTC] beginner question about imq Szálka Tamás
2003-09-10 11:33 ` Raghuveer
2003-09-10 18:13 ` Szálka Tamás
2003-09-10 18:36 ` Stef Coene
2003-09-10 19:16 ` Szálka Tamás
2003-09-11 12:39 ` Toshiro Viera
2003-09-11 17:15 ` Stef Coene
2003-09-12 15:22 ` Szálka Tamás
2003-09-12 16:58 ` Stef Coene
2003-09-12 19:07 ` Szálka Tamás
2003-09-12 21:22 ` Stef Coene

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.