[ANNOUNCE] Proceedings of Netfilter Developer Workshop 2004

Piotr Gasidło quaker at pandora.barbara.ds.polsl.gliwice.pl
Mon Sep 27 16:31:16 CEST 2004


On Sat, 25/09, 11:33:22PM, Harald Welte wrote:
> |---------------------------+----------------------------------------+--------|
> |IPMARK                     |why is tc not enough to do this? Too    |No      |
> |                           |obscure                                 |        |
> |---------------------------+----------------------------------------+--------|

Target is useful when using MASQUERADE or SNAT. Using tc we are *unable*
to put outgoing trafic from single IP (behind masquerade) into queue
created on outgoing interface. With this target we can mark packets from
each internal IP and then, using tc filter fw put it into queues. This
target replaces many MARK rules, which can be really CPU hog.

-- 
Piotr 'QuakeR' Gasidło, BOFH @ pandora.barbara.eu.org
############## sending lusers to /dev/null since 1998
##### Waiting for tomorrow, for a little ray of light
### Waiting for tomorrow just to see your smile again
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 232 bytes
Desc: Digital signature
Url : /pipermail/netfilter-devel/attachments/20040927/f78dc0c1/attachment.bin


More information about the netfilter-devel mailing list