From owner-freebsd-net@FreeBSD.ORG Mon Oct 3 20:47:04 2005 Return-Path: X-Original-To: freebsd-net@freebsd.org Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C945D16A41F for ; Mon, 3 Oct 2005 20:47:04 +0000 (GMT) (envelope-from max@love2party.net) Received: from moutng.kundenserver.de (moutng.kundenserver.de [212.227.126.188]) by mx1.FreeBSD.org (Postfix) with ESMTP id 328E743D45 for ; Mon, 3 Oct 2005 20:47:03 +0000 (GMT) (envelope-from max@love2party.net) Received: from p54A3DC90.dip.t-dialin.net [84.163.220.144] (helo=donor.laier.local) by mrelayeu.kundenserver.de with ESMTP (Nemesis), id 0MKxQS-1EMXDA0yMB-0001Li; Mon, 03 Oct 2005 22:47:00 +0200 From: Max Laier To: freebsd-net@freebsd.org Date: Mon, 3 Oct 2005 22:46:43 +0200 User-Agent: KMail/1.8.2 References: <20051003191704.39154.qmail@web30308.mail.mud.yahoo.com> In-Reply-To: <20051003191704.39154.qmail@web30308.mail.mud.yahoo.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="nextPart2469819.RaaeHssqsM"; protocol="application/pgp-signature"; micalg=pgp-sha1 Content-Transfer-Encoding: 7bit Message-Id: <200510032246.57786.max@love2party.net> X-Provags-ID: kundenserver.de abuse@kundenserver.de login:61c499deaeeba3ba5be80f48ecc83056 Cc: Arne =?utf-8?q?W=F6rner?= Subject: Re: pf / queue+stateful / r generated rules assigned to the right queue? X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 03 Oct 2005 20:47:04 -0000 --nextPart2469819.RaaeHssqsM Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Arne, On Monday 03 October 2005 21:17, Arne W=F6rner wrote: > Since my server cannot process gracefully a 20Mb/s stream on one > NIC, while ntpd (or ping) runs on the other NIC (round trip times > increase from about 60msec to 300msec), I tried to limit the > sporadic big data stream to not more than 9Mb/s. it is impossible to limit incoming traffic! In order to limit this, you ne= ed=20 to queue on a gateway "in front" of the server. > When I look at "pfctl -s queue -vv" it looks like, just one way is > mentioned in the statistic, while the generated corresponding rule > (I use "keep state") isn't a member of any queue, which would be a > bug... I have problems to understand what you are saying here. Keep some things i= n=20 mind: 1) One can only queue *OUT*going traffic 2) All unclassified outgoing traffic ends up in the default queue 3) Don't forget about 1) I might, however, completely misunderstand you problem/question. In any ca= se=20 you could try to take this to freebsd-pf@ which is a more specialized=20 mailinglist. The people there can certainly help you with your setup. =2D-=20 /"\ Best regards, | mlaier@freebsd.org \ / Max Laier | ICQ #67774661 X http://pf4freebsd.love2party.net/ | mlaier@EFnet / \ ASCII Ribbon Campaign | Against HTML Mail and News --nextPart2469819.RaaeHssqsM Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQBDQZjBXyyEoT62BG0RAsiSAJ46W2m15+BXhFwsm5ptNlNnsG+oxACeNzYF BehDWg7lt4S+An1Z8wn5M6Q= =aYt1 -----END PGP SIGNATURE----- --nextPart2469819.RaaeHssqsM--