From mboxrd@z Thu Jan 1 00:00:00 1970 From: Subject: bandwidth problems [Linux 2.4.20] [iptables 1.2.7a] Date: Tue, 10 Feb 2004 18:28:56 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: Reply-To: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org Hi! My configuration: ================= O-------------o O-----------------------o | WinXP | | eth0 | eth1 | | 10.10.1.100 |----| 10.10.1.254 | D H C P |----INTERNET | | | | | O-------------o O-----------------------o My Computer My NAT-Computer NAT-Computer: Linux 2.4.20-4GB load average: 0.08, 0.05, 0.06 iptables v1.2.7a All the NICs I use are 3com 3C905-TX When I do some bandwidth tests on the NAT-Computer (provider's service page) my bandwidth is about 1MBit/second When I do the same on my computer I only get about 100kbit/second Now I wonder if there are any problems with my configuration...? Would be nice if you could help me... Thanks in advance Florian St. Root(AT)scheuchenstuel(DOT)com My iptables-configuration: ========================== ############################################################################ ###### #!/bin/bash # modprobe iptable_nat echo 1 > /proc/sys/net/ipv4/ip_forward ########## CLEARING TABLES iptables -F iptables -t nat -F iptables -t mangle -F iptables -X ########## SETTING POLICIES iptables -P INPUT DROP iptables -P OUTPUT ACCEPT iptables -P FORWARD DROP ########## NAT iptables -A INPUT -i eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE ########## LOOPBACK SETTINGS iptables -A INPUT -i lo -j ACCEPT iptables -A INPUT -s 127.0.0.1/32 -j ACCEPT ########## EXTERNAL OPEN PORTS iptables -A INPUT -i eth1 -p tcp --dport 80 -j ACCEPT ########## INTERNAL OPEN PORTS iptables -A INPUT -s 10.10.1.100/32 -j ACCEPT ######### NAT FORWARDING iptables -A FORWARD -s 10.10.1.100/32 -j ACCEPT iptables -A FORWARD -d 10.10.1.100/32 -j ACCEPT ############################################################################ ######