similar to: shaping using source IP after NAT

Displaying 20 results from an estimated 700 matches similar to: "shaping using source IP after NAT"

2007 May 17
2
IPCLASSIFY - patch based on IPMARK
Hello everybody! Some time ago I''ve decided that using the MARK property of the Linux IP packet structure for the needs of traffic control is not very useful. So I wrote an iptables patch called IPCLASSIFY. It is fully based on IPMARK but it uses the PRIORITY field instead of MARK. The relation between IPCLASSIFY<->CLASSIFY is the same as IPMARK<->MARK. By using
2007 May 26
14
big problem with HTB/CBQ and CPU for more than 1.700 customers
2007 Jun 02
7
u32 classifier
Hi folks...!!! I´ve a problem that i did not solve it. i want to limit the DOWNLOAD to my hosts (upstream traffic for the firewall) using IMQ, If i classify by PORT (source or destination) all seems to be fine, but...BUT...if i want to restrict by IP addresss (internal IP address) i can´t do it, because my hosts go to Internet toward the firewall using NAT, so after NAT my IP address in
2007 Sep 24
3
trouble when using IPMARK module
Hello, I am trying to use iptables together with tc I need to use IPMARK module of iptables, but I got a strange error after I run ''iptables -t mangle -A POSTROUTING -o eth0 -j IPMARK --addr=dst --and-mask=0xffff --or-mask=0x1000'' The command is copied from iptables manual itself (of course interface changed) I only got " iptables v1.3.5: Unknown arg
2007 Jun 06
4
how hierarchical is HTB?
Hi there! I''ve using HTB for a while and now I an faced with a ''problem''. How hierarchical is HTB? Let''s say I have this 3 layer HTB setup: root class 1: (rate=100, ceil=100) 1: children classes 1:10 (30,100) and 1:20 (70,100) 1:10 children classes 1:100 (10,100) and 1:101 (20,100) 1:20 children classes 1:200 (30,100) and 1:201 (70,100) I managed to have
2003 Jun 19
0
[Bug 100] New: NETFILTER_VERSION -> IPTABLES_VERSION in libipt_IPMARK.c
https://bugzilla.netfilter.org/cgi-bin/bugzilla/show_bug.cgi?id=100 Summary: NETFILTER_VERSION -> IPTABLES_VERSION in libipt_IPMARK.c Product: iptables userspace Version: unspecified Platform: All OS/Version: All Status: NEW Severity: normal Priority: P2 Component: iptables
2006 Dec 13
3
Multi Operator
Hi, Actually on my setup all outgoing calls are going trhu a SIP unique account A have a second SIP account with another operator and I would like my setup to use alternatively each of the two accoutns Call 1=> Dial SIP/phone1 Call 2=> Dial SIP/phone2 Call 3=> Dial SIP/phone1 <...> If you have an sample please let me know
2007 Apr 24
1
IPMark won''t compile on a vanilla 2.6.20 kernel
Hello, IPMark won''t compile on a vanilla 2.6.20 kernel I obtain this error during the compilation under debian sarge 3.1 CC [M] net/ipv4/netfilter/ipt_TTL.o CC [M] net/ipv4/netfilter/ipt_IPMARK.o net/ipv4/netfilter/ipt_IPMARK.c: In function `target'': net/ipv4/netfilter/ipt_IPMARK.c:37: error: structure has no member named `nfmark''
2016 Jan 18
2
how to flush user input before READ()
On Mon, 18 Jan 2016, Ethy H. Brito wrote: >> how to flush user input before READ()? How about a read() to a dummy variable with a 1 second timeout to consume the octothorpe and password? -- Thanks in advance, ------------------------------------------------------------------------- Steve Edwards sedwards at sedwards.com Voice: +1-760-468-3867 PST
2015 Oct 20
4
asterisk core dumped after UBUNTU 14.04 dist-upgrade
Hi I had a bad experience upgrading Ubuntu a few months ago. Today I made a "dd" copy to another harddisk and tried to dist-upgrade. I get "Illegal instruction (core dumped)" running "service asterisk debug" at random places. Any help will be appreciated to spot this problem. I think it is worth to mention that the dadhi hardware is not present at the copied
2015 Jan 30
2
SSL traffic on RTP instance without an SSL session
Hi All We've been reading this in the CLI a lot lately: Received SSL traffic on RTP instance '0x7fe7481faad8' without an SSL session How can we find details about this particular RTP instance? "rtp set debug" needs an IP which is precisely what I want to know (and I don't)! Cheers Ethy
2007 Jun 08
5
CBQ + Layer7 x Emule
Hi All , My first message and I have a little problem with my FC6 box trying to block emule traffic using layer7 . Here my network : Internet --------- ADSL Router ------------------- FC6 Box -------------------- Emule Box external ADSL : Dynamic Internal ADSL : 192.168.254.1 external FC6 : 192.168.254.3 internal FC6 : 192.168.253.1 Emule Box : 192.168.253.3 I guess that everything
2015 Apr 28
2
Function IMPORT and Local channels
Hi all These questions were asked back in 2009 at lists.digium.com and got unanswered: - Has someone been successful in using IMPORT on a Local channel ? - Is there a known limitation in doing so ? I run into the same problem. ${IMPORT(Local/1234 at example-abcd;2,CALLERID(dstchannel))} returns nothing. But I can read the dstchannel for it into the CDR. Asterisk is 11.7.0~dfsg-1ubuntu1
2005 Dec 19
3
match''ing packets by size
I visited yesican.chsoft.biz and the author proposes a way to match packets by less than some size . Here is the thing: match u16 0x0000 0xffb0 at 2 With this match he says that packet with less than 80 bytes will match the rule. Well, 0xffb0 translates to 1111 1111 1011 0000 (which is -80 BTW). So, if I am correct any packet with bits 4 and/or 5 set (together with any of the 4
2015 Sep 11
3
cdr table's "dst" column
Hi All What, by definition, goes to the cdr table's "dst" column ?? In our setup, to get outside the user has to dial X before any number. This goes to the dst with the X stripped out. I recently made some changes in a macro and after that the X appeared in this dst column! I run through the script and see no differences between the old and the new one. Then the question: What,
2015 Nov 24
2
subscriber state before dial
Hi All After a Dial() I get: WARNING[7964][C-000075a8]: app_dial.c:2437 dial_exec_full: Unable to create channel of type 'SIP' (cause 20 - Subscriber absent) if the subscriber is not registered. Is there a way from dialplan to know, *before* Dial(), if a destination Subscriber is a) not registered or b) busy ? I need to redirect a call to some other Subscriber if (s)he is not there
2006 Jan 26
8
nat table remenbering nat''s
Dear All Why NAT rules stays valid even if I flush nat anf table chains?? I have: iptables -P FORWARD DROP iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A FORWARD -s SOME_IP -d SOME_BCP_5_IP --dport 1234 -j ACCEPT iptables -i nat -A PREROUTING -s SOME_IP -d MY_INTERNET_IP \\ --dport 1234 -j DNAT --to-destination SOME_BCP_5_IP The conection is
2016 Jan 15
2
how to flush user input before READ()
Hi how to flush user input before READ()? I wrote a small script to ask for user password before granting access to outside, but some telefones memorize the full user input, including "#". So, when the user press redial, for instance 5556789#123, asterisk accepts the number and the password "123" and gives access to the outside word to whomever redials that terminal. Any
2015 May 28
2
chan_sip.c: Hanging up call
Hi All I have a few lines like this at asterisk/messages. [May 25 15:22:42] WARNING[27725] chan_sip.c: Hanging up call 5a2600300339934f704528bb14ed05e9 at MyAsterisk:5060 - no reply to our critical packet (see https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions). Since we have hundreds of clients with hundreds of simultaneous calls, how is it possible to know to which customer/IP
2015 May 28
1
chan_sip.c: Hanging up call
On Thu, 28 May 2015 11:15:45 -0500 Scott Griepentrog <sgriepentrog at digium.com> wrote: > The string "5a2600300339934f704528bb14ed05e9 at MyAsterisk:5060" is the unique > identifier for the call in SIP known as the Call-ID. If you have a packet > capture of the port 5060 SIP traffic, that identifier will be in each SIP > message related to the call, which also