Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




22063 posts

Uber Geek
+1 received by user: 4683

Trusted
Subscriber

# 36579 29-Jun-2009 08:15
Send private message

I have to look into rate limiting the connection here since the torrenting activities of others are starting to actually go fast enough to make browsing unplesent (I can tolerate youtube slowness when they are using it) - and voip is going choppy now - thats even with them limiting the speed in utorrent.

Firewall machine is running debian linux  - have no idea what version at the moment, it used to be woody but things have been changed and updated so many times on it... I would consider putting something else in but the machine is also my asterisk machine.

Just need a basic howto on setting it up to do the following

bridge 2 nics together - one my stuff, one the AP to the other guys
Give them second priority for anything going onto the internet when compared to my machines, but allow for full speed between the lans.

Easily doable?




Richard rich.ms

Create new topic
Professional yak shaver
1599 posts

Uber Geek
+1 received by user: 8

Trusted
BitSignal
Lifetime subscriber

  # 229094 29-Jun-2009 08:42
Send private message

Certainly not easily for first-timers, but quite possible.

A starting point is http://www.debian-administration.org/articles/187 for the basics of rate-limiting with iptables. You can evolve from there.




"Roads? Where we're going, we don't need roads." - Doc Emmet Brown

8033 posts

Uber Geek
+1 received by user: 390

Trusted
Subscriber

  # 229150 29-Jun-2009 11:16
Send private message

You can probably find some precooked scripts for a standard QoS setup with a bit of googling.  If you are lazy like me you might want to use a distro designed to be a firewall proxy on a old pc between as your gateway eg: Smoothwall, Monowall, pfsense etc.

Most of the the above distro's come with simple to use web ui's for setting things up thesedays.  


 
 
 
 


mjb

923 posts

Ultimate Geek
+1 received by user: 21

Trusted

  # 229490 30-Jun-2009 10:54
Send private message

magu: Certainly not easily for first-timers, but quite possible.

A starting point is http://www.debian-administration.org/articles/187 for the basics of rate-limiting with iptables. You can evolve from there.


That's just connection rate limiting - while useful, it's no good for high throughput established connections. for that, you want tc. which gets oh so brain poppingly confusing until you get your head around it.

This is just one example: http://luxik.cdi.cz/~devik/qos/htb/manual/userg.htm

So, ultimately, Ragnor is right - you probably want an all-in-one firewall package that has the magic to do all this already, with a nice easy to use web interface for configuration. I believe some of the packages Ragnor lists do this, I've not used any so can't help there sorry.

edit: hah, he actually mentions web interfaces. mjb reading comprehension: fail. :)




contentsofsignaturemaysettleduringshipping


887 posts

Ultimate Geek
+1 received by user: 62

Subscriber

  # 229512 30-Jun-2009 12:12
Send private message

Start with this:
http://www.voip-info.org/wiki/view/QoS+Linux+with+HFSC

(it also requires tc to be installed) but at least its a pretty good useful example. My problem with traffic shaping is not so much national bandwidth but international. You have to limit your connection for shaping to work properly, but you dont want to limit your national traffic to your international speed and if you factor in different speeds to different countries (china will be much slower than USA for example) it gets more complex :)

I use output from geoip for my tc rules at the moment but its far too complex for my liking I've been meaning to investigate other solutions.

I would add one comment while all in one distro's such as pfsense are great I don't like being limited to their feature set so also run debian on our firewall.

Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Video game market in New Zealand passes half billion dollar mark
Posted 24-May-2019 16:15


WLG-X festival to celebrate creativity and innovation
Posted 22-May-2019 17:53


HPE to acquire supercomputing leader Cray
Posted 20-May-2019 11:07


Techweek starting around NZ today
Posted 20-May-2019 09:52


Porirua City Council first to adopt new council software solution Datascape
Posted 15-May-2019 12:00


New survey provides insight into schools' technology challenges and plans
Posted 15-May-2019 09:30


Apple Music now available on Alexa devices in Australia and New Zealand
Posted 15-May-2019 09:11


Make a stand against cyberbullying this Pink Shirt Day
Posted 14-May-2019 20:23


Samsung first TV manufacturer to launch the Apple TV App and Airplay 2
Posted 14-May-2019 20:11


Vodafone New Zealand sold
Posted 14-May-2019 07:25


Kordia boosts cloud performance with locally-hosted Microsoft Azure ExpressRoute
Posted 8-May-2019 10:25


Microsoft Azure ExpressRoute in New Zealand opens up faster, more secure internet for Kiwi businesses
Posted 8-May-2019 09:39


Vocus Communications to deliver Microsoft Azure Cloud Solutions through Azure ExpressRoute
Posted 8-May-2019 09:25


Independent NZ feature film #statusPending to premiere during WLG-X
Posted 6-May-2019 22:13


The ultimate dog photoshoot with Nokia 9 PureView #ForgottenDogsofInstagram
Posted 6-May-2019 09:41



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.