Tadd M. Balfour
2014-May-13 21:46 UTC
new to shorewall > need help with incorrect eth_wan link negotiation
I'm new to Shorewall, but not to Linux. I've been brought on to a project where the Shorewall seems to be hindering the overall bandwidth out to the cloud. The business has a 50M x 5M fiber circuit with TW Cable. When they run a speed test from inside the LAN, they are getting horrible download speeds. Less than 3MB! The TW Level III Tech indicated that he felt that it was the Firewall that was causing the issues. My job is to figure out if that is the case. After poking around, I ran the following command: /sbin/mii-tool -v eth_wan and got these results: eth_wan: negotiated 100baseTx-FD flow-control, link ok product info: vendor 00:50:43, model 11 rev 1 basic mode: autonegotiation enabled basic status: autonegotiation complete, link ok capabilities: 1000baseT-FD 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD advertising: 1000baseT-FD 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD flow-control link partner: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD flow-control That looks to me like it is negotiating only a 100 Megabit connection. Is that correct? What else can I do to see what is going on? Here is some more info: Linux firewall 3.2.1-gentoo-r2 #2 SMP Fri Sep 21 16:28:20 CDT 2012 x86_64 Intel(R) Atom(TM) CPU D525 @ 1.80GHz Genuine Intel GNU/Linux I'm afraid to make any changes as I don't want to bring this entire business down, but I need to positive identify, if not resolve the issue. Can anyone kindly please advise? Thanks! Tadd in Austin, TX ------------------------------------------------------------------------------ "Accelerate Dev Cycles with Automated Cross-Browser Testing - For FREE Instantly run your Selenium tests across 300+ browser/OS combos. Get unparalleled scalability from the best Selenium testing platform available Simple to use. Nothing to install. Get started now for free." http://p.sf.net/sfu/SauceLabs