Re: ipfw rules consuming CPU

2012-06-09 Thread Michael Spratt
I have Linux FreeBSD systems running ipfw with 80 rules with 70Mb/s symmetric, passing traffic for about 1000-1200 hosts. Alexander V. Chernikov wrote: On 09.06.2012 01:56, Sami Halabi wrote: Hi, I Manage a FreeBSD server as an edge router firewall. the setup has 10G interfaces

Re: kern/168190: pfil hook leaving ip_len in wrong byte order (ipfw?)

2012-06-05 Thread Michael Spratt
Dear respected sir/s, How can I mangle all forwarded packets on freebsd/pf/ipfw/ stamping them with a hard set MSS like 512, I need to clamp my mss on the freebsd forwarder/router because of gre tunnels breaking MTUPD for extranet clients, and some sites like yahoo/hotmail will often not

Re: soft-cap,

2011-01-05 Thread Michael Spratt
Freddie Cash wrote: On Tue, Jan 4, 2011 at 2:33 PM, Michael Spratt m...@magicislandtechnologies.com wrote: Dear friends, linux/ipfw/dummynet/transparent-bridge, am trying to cap users to upload/TX rates, but allow them to go over if the link is not congested. The example below limits each

Re: Transparent Squid and traffic control

2011-01-05 Thread Michael Spratt
John Nielsen wrote: On Jan 4, 2011, at 8:01 AM, Fazal Ahmed Malik wrote: I have problem in running transparent squid along with dummynet on FreeBSD 7. I have mpd5 for dialin pppoe which is working perfect along with ipfw dummynet traffic control. Now i want to setup transparent squid

soft-cap,

2011-01-04 Thread Michael Spratt
Dear friends, linux/ipfw/dummynet/transparent-bridge, am trying to cap users to upload/TX rates, but allow them to go over if the link is not congested. The example below limits each src-ip mask-IP's TX from 10.10.0.0/20 to 128Kbp/s, and from 10.20.0.0/20 to 1024Kbp/s.

Re: dummynet: waking up pipe

2010-01-22 Thread Michael Spratt
you should use vstat or something to see if its interrupts eating your cpu.. Luigi Rizzo wrote: On Fri, Jan 22, 2010 at 07:42:46PM +0300, Evgenii Davidov wrote: , On Fri, Jan 22, 2010 at 02:46:28PM +0100, Luigi Rizzo ?: On Fri, Jan 22, 2010 at 04:35:35PM +0300, Evgenii

Re: out xmit (demux) pipe bw accounting

2009-08-19 Thread Michael Spratt
Chuck Swiger wrote: Hi-- On Aug 17, 2009, at 7:32 AM, Michael Spratt wrote: Could not find answer to following question. Given : # pipe 1 config bw 1Mbit/sec # ipfw 1000 add pipe 1 ip from any to any out xmit em0 Will the bandwidth limit include layer 2 Ethernet headers or will only

out xmit (demux) pipe bw accounting

2009-08-17 Thread Michael Spratt
Could not find answer to following question. Given : # pipe 1 config bw 1Mbit/sec # ipfw 1000 add pipe 1 ip from any to any out xmit em0 Will the bandwidth limit include layer 2 Ethernet headers or will only the IP datagram itself be included in the accounting mechanism? Total output on the