Linux Advanced Routing and Traffic Control list
 help / color / mirror / Atom feed
From: Arindam Haldar <ahiam@yahoo.com>
To: lartc@vger.kernel.org
Subject: Re: [LARTC] iptables mark & iproute related !
Date: Fri, 04 Jan 2002 05:48:15 +0000	[thread overview]
Message-ID: <marc-lartc-101012329521583@msgid-missing> (raw)
In-Reply-To: <marc-lartc-100994719519192@msgid-missing>

hi,

Stef Coene wrote:

> On Thursday 03 January 2002 15:17, Arindam Haldar wrote:
>>hi
>>i did those test & as i said in my last mail there is trafic passing thru
>>ir bytes counter r increasing but the tc command doesnt show any
>>restircition. seem like marked pkts r not going thru the iproute
>>
> Sorry, you wrote to encrypted for me to understand everything ;-)
> If I understand correctly, everything works if you use CBQ & SFQ, but the fw 
> filter is not working like it should be ? 

YES !!! .. UR ABSOLUTELY RIGHT !!!! :-)

> 
>>any suggestions ??
>>
> Can you post the scripts you are using so I can try them myself ?
> 
> Stef
> 
THIS IS MY TRUNCATED SCRIPT(MARK RELATED) !


iptables -A INPUT -i eth4 -s 192.168.1.1 -j ACCEPT

iptables -A FORWARD -o eth0 -s 192.168.1.1 -j ACCEPT
iptables -A PREROUTING -t nat -i eth4 -p 6 --dport 80 -j REDIRECT 
--to-port 3128
iptables -A PREROUTING -t mangle -i eth4 -s 192.168.1.1 -d a.b.c.d -j 
MARK --set-mark 55
iptables -A PREROUTING -t mangle -i eth4 -s 192.168.1.1 -d ! a.b.c.d -j 
MARK --set-mark  51
iptables -A POSTROUTING -t mangle -o eth0 -s 192.168.1.1 -j MASQUERADE


iptables -A PREROUTING -t nat -i eth0 -d 192.168.1.1 -s a.b.c.d -j MARK 
--set-mark 56
iptables -A PREROUTING -t mangle -i eth0 -d 192.168.1.1 -s ! a.b.c.d -j 
MARK --set-mark 52

###--32kbps for x-LAN
tc class add dev eth4  parent 5:1 classid 5:191 est 2sec 10sec cbq 
bandwidth 512Kbit rate 32Kbit allot 5\1514 weight 3.2Kbit prio 2 
maxbrust 5 avpkt 1500 bounded
tc qdisc add dev eth4 parent 5:191 sfq perturb 10
tc filter add dev eth4 parent 5:0 protocol ip prio 10 handle 51 fw 
flowid 5:191
tc filter add dev eth4 parent 5:0 protocol ip prio 10 handle 52 fw 
flowid 5:191
###--128 for LAN
tc class add dev eth4  parent 5:1 classid 5:192 est 2sec 10sec cbq 
bandwidth 512Kbit rate 128Kbit allot 5\1514 weight 3.2Kbit prio 2 
maxbrust 5 avpkt 1500 bounded
tc qdisc add dev eth4 parent 5:192 sfq perturb 10
tc filter add dev eth4 parent 5:0 protocol ip prio 10 handle 55 fw 
flowid 5:192
tc filter add dev eth4 parent 5:0 protocol ip prio 10 handle 56 fw 
flowid 5:192

similar for eth0 too !!
thanx in anticipation

arindam haldar


_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://ds9a.nl/lartc/

      parent reply	other threads:[~2002-01-04  5:48 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-01-02  4:53 [LARTC] iptables mark & iproute related ! Arindam Haldar
2002-01-02 10:31 ` Stef Coene
2002-01-03 14:29 ` Arindam Haldar
2002-01-03 15:23 ` Stef Coene
2002-01-04  5:48 ` Arindam Haldar [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=marc-lartc-101012329521583@msgid-missing \
    --to=ahiam@yahoo.com \
    --cc=lartc@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox