From owner-freebsd-pf@FreeBSD.ORG Mon Nov 12 14:33:45 2007 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 118B316A417 for ; Mon, 12 Nov 2007 14:33:45 +0000 (UTC) (envelope-from mail.listesi@gmail.com) Received: from rn-out-0102.google.com (rn-out-0910.google.com [64.233.170.190]) by mx1.freebsd.org (Postfix) with ESMTP id AD6B613C48E for ; Mon, 12 Nov 2007 14:33:44 +0000 (UTC) (envelope-from mail.listesi@gmail.com) Received: by rn-out-0102.google.com with SMTP id s42so490317rnb for ; Mon, 12 Nov 2007 06:33:32 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=zUxtDmKyfJs7SLCXR4v9UCslHeA5MBeKZ8ORsyxHixI=; b=AEfcdDbhjCGTbKHMtUdOlo/5tMipvdjCnXDBIDOyVGiqt0qclguy/pRogtRBCePnFEeGnlMN/YTsvfGoalC+XNOhqP+z72w3fJK7OjTx7AVAb+qF/ccoPCqCMc1Qoqb1dvgr6JrPFBuoTkob4A7Ba9raGNKC/EpEqyH2qs2cisg= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=YeiSTjygYzTczqttaA1fo31EVaocT8tPRrqZKs635BemE7rGmvbROVBEKu/F7jRKVYGsl0j2ZXwnzkSiDJxxLE5b/yenO/t9l+W+Uq3s6beu1CZ+uhAKmrbOmdlqL1UJWhlKeDif03YRLuBHGw4iHWFV6iq4IVpsCpJUrOku/o8= Received: by 10.142.229.4 with SMTP id b4mr1208565wfh.1194878010518; Mon, 12 Nov 2007 06:33:30 -0800 (PST) Received: by 10.143.29.20 with HTTP; Mon, 12 Nov 2007 06:33:30 -0800 (PST) Message-ID: Date: Mon, 12 Nov 2007 16:33:30 +0200 From: Jeremy To: "Rob Shepherd" In-Reply-To: <47382493.9040202@techniumcast.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Content-Disposition: inline References: <47382493.9040202@techniumcast.com> Cc: freebsd-pf@freebsd.org Subject: Re: Giving all hosts on network same bandwidth X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 12 Nov 2007 14:33:45 -0000 On Nov 12, 2007 12:01 PM, Rob Shepherd wrote: > > If the question is: "Can I assign all hosts on a network to a single queue?", > then YES. no, i dont want to assign each addresses to single queue or every addresses to more queues one by one, is there solution in network address rules just like that pass out on dc0 inet proto tcp from $employeehosts to any port 80 keep state queue employees altq on dc0 scheduler cbq bandwidth 10Mb queue { std, http, mail, ssh } queue std bandwidth 10% cbq(default) queue http bandwidth 60% priority 2 cbq(borrow red) { employees, developers } queue developers bandwidth 75% cbq(borrow) queue employees bandwidth 15% queue mail bandwidth 10% priority 0 cbq(borrow ecn) queue ssh bandwidth 20% cbq(borrow) { ssh_interactive, ssh_bulk } queue ssh_interactive bandwidth 100% priority 7 queue ssh_bulk bandwidth 100% priority 0 pass out on dc0 inet proto tcp from $employeehosts to any port 80 keep state queue employees this example qives employeehosts 15% of total bandwidth but i want to give each hosts to same bandwidth ( for example i have 10Mb bandwidth and 20 hosts iwant to give each of hosts to 512 K .if i use 10M in altq rules some hosts' have 9M bandwitdh and some have 1M ) . is that possible writing without all of ip addresses in rules pass out on dc0 inet proto tcp from $employee1 to any port 80 keep state queue employees pass out on dc0 inet proto tcp from $employee2 to any port 80 keep state queue employees pass out on dc0 inet proto tcp from $employee3 to any port 80 keep state queue employees pass out on dc0 inet proto tcp from $employee4 to any port 80 keep state queue employees pass out on dc0 inet proto tcp from $employee5 to any port 80 keep state queue employees pass out on dc0 inet proto tcp from $employee6 to any port 80 keep state queue employees ....... pass out on dc0 inet proto tcp from $employee20 to any port 80 keep state queue employees this is silly > > queue assignment is by pf rules; whatever you can match you can assign to a queue. > > There is an example of matching whole networks and assigning to queues at the > bottom of http://www.openbsd.org/faq/pf/queueing.html > > Rob > > -- > Rob Shepherd BEng PhD | Computer and Network Engineer | CAST Ltd > Technium CAST | LL57 4HJ | http://www.techniumcast.com >