Displaying 20 results from an estimated 10000 matches similar to: "u32 filter usage"
2005 Oct 17
5
TC show filter command shows all u32 filters defined with different priority iin all priority.
Hi,
I am currently working on the TC.
I have seen some behaviour which seems to be odd.
I know someone in the mailing list would have seen this problem or may
have some fix for this problem.
When I try to include u32 filters with different priority or pref, I
could see the filters being set on all the priority''s irrespective of
the priority number.
See my sample script below and the
2006 Apr 07
0
PRIO and u32 matching problem
Hi to everybody
I''m trying to use PRIO qdisc to prioritize the traffic but i have
strange problem maybe I''m missing sometging.
First i add root qdisc like this
tc qdisc add dev eth0 root handle 1: prio
it''s fine after this i try to match traffic by tos field but i get error
invalid match
tc filter add dev eth0 parent 1:0 prio 1 protocol ip u32 \
match ip tos 0x10 0xff
2003 Oct 31
2
tc filter oddities
I shape my upstream cable link with HTB from a script. My voip traffic
(from the 192.168.0.14 host) gets priority over everything else to the
near-starvation of other classes; the rest of the traffic is split up
based on some priority rules (qos, empty ack packets, etc). eth1 is the
uplink
I''ve been using HTB and fw marking for the job until recently, when I
changed the queue structure
2003 Nov 07
0
Understanding the U32 filter.
Hi,
I am trying to understand filters.
1) Under the U32 section of the lartc howto there is
an example (to match ACKs on packets smaller than 64
bytes):
# tc filter add dev ppp14 parent 1:0 protocol ip prio
10 u32 \
match ip protocol 6 0xff \
match u8 0x05 0x0f at 0 \
match u16 0x0000 0xffc0 at 2 \
match u8 0x10 0xff at 33 \
flowid 1:3
The howto says ''the filter above
2003 Aug 16
0
offset mask usage in u32 filter
iproute2 distribution in README.iproute2+tc includes
toward the end an example of usage of syntax ''offset
mask'' as follows:
# Lookup hash table, if it is not fragmented frame
# Use protocol as hash key
$TC filter add dev eth1 parent 1:0 prio 5 handle ::1
u32 ht 800:: \
match ip nofrag \
offset mask 0x0F00 shift 6 \
hashkey mask 0x00ff0000 at 8 \
link 1:
Also, identical
2006 Jul 14
1
I need help with tc filters!!!!!
Hi Everybody!
I need help! I''m doing a tc script with tc filters that have match the Type of Service field in the IP header. This is the script I am using to setup the filters.
tc filter add dev $DEV parent 1: protocol ip prio $PRIO_CONTROL u32 match ip protocol 6 0xff \
match u32 00190000 00ff0000 at 0 flowid 1:10
tc filter add dev $DEV protocol ip parent 1: prio $PRIO_VIDEO
2001 Jun 29
1
u32 nexthdr problem
I''m having trouble with nexthdr.
tc filter add dev eth0 protocol ip parent 10:0 prio 1 u32 \
match ip protocol 0x6 0xff match u8 0x02 0x12 at nexthdr+13 flowid 10:3
fails to match my test packets whereas
tc filter add dev eth0 protocol ip parent 10:0 prio 1 u32 \
match ip protocol 0x6 0xff match u8 0x02 0x12 at 33 flowid 10:3
does match them.
Of course, the second one is really wrong
2007 Nov 21
0
Problem with ingress policing on bridged device
I''m having trouble getting ingress policing to work on a bridged device.
The bridge contains several interfaces: peth0, vif0.0, vif[1-7]0.1,
vif[25].1 . (This is under xen, in case the vif''s didn''t give that
away, so peth0 is renamed eth0.)
The tc rules I have are:
tc qdisc del dev peth0 root
tc qdisc del dev peth0 ingress handle ffff:
tc qdisc add dev peth0 root
2002 Dec 06
0
u32 filter
Hello!
What is the significance of "handle" in a u32 filter??
For example, if I have a HTB class 1:1 and three child classes 1:11, 1:12,
and 1:13. Within 1:11, I define dsmark, say 2:0, and let it mark packets
with certain DSCP. Now, using the u32 filter I need to classify packets of a
certain flow (e.g., based on src ip address and dest port), then can someone
give me an example of
2005 Dec 15
1
iptables mark and u32 filter
Hi All
I''d like to use an iptables mark together with u32 filter. Something like this, for instance:
tc filter add dev imq0 protocol ip parent 1:0\
prio 2 handle 55\
u32 match u8 1 0xff at 0x09 flowid 1:22
(all icmp packets marked with 55 goes to class 1:22)
But I got ''Illegal filter ID'' as answer. Is this combination possible?
--
Ethy H. Brito /"\
2003 Jan 05
1
U32 filter for IPSEC (ESP)
Hi all,
After reading a lot and searching on the INternet, I want to filter ASP
and/or AH traffic
According to /etc/protocols ESP and AH are IP protos 50 and 51
so this u32 filter should work ? (I can use fw filter because the
firewall/VPN can''t mark pakets :-(
tc filter add dev ethX parent X:0 protocol ip prio X u32 match ip protocol
50 0xff flowid X:XX ?
Can someone confirm this ?
2003 Nov 23
4
u32 filter won''t match
Hi!
I really need help with a u32 filter that won''t match what I think I''m
telling it to. The situation is that I have set up an internal
computer to change the TOS value of packets sent by certain processes
to 0x1E (If anyone known of a better way to mark packets, please tell
me. I would love to find some module that adds an IP option with UIDs
and GIDs to the packets - does
2001 Jul 04
0
u32 nexthdr -> iptables --protocol tcp
I still think that nexthdr should be fixed, but I''d like to mention
that iptables --protocol tcp can do pretty much the same thing.
That is,
tc filter add dev $1 protocol ip parent 10:0 prio 1 u32 \
match ip protocol 0x6 0xff match u8 0x02 0x16 at nexthdr+13 flowid 10:3
can be replaced by
iptables -A PREROUTING -t mangle -p tcp --syn -j MARK --set-mark 2
tc filter add dev $1 protocol
2002 Jul 13
0
Advanced routing (Tc filter)
Greetings,
I am working in a project , and we are concerned about usin Traffic Conrol tool in iproute2 package, but unfortunately we are facing some problems using u32 filters to match the ip protocol.
Frankly we used:
# tc filter add dev eth0 parent 1:0 protocol ip pref 2 u32 match ip protocol
1 0xff classid 1:4 ( to match icmp protocol )
and then we tried to use
# tc filter add dev
2006 Feb 21
6
invert u32 match selector
Is it possible to negate the "match" to the ip? I want to match all
traffic to dport 80 NOT going to dst 1.2.3.4:
$TC filter add dev ${DEV_IFB} parent 1:0 prio 2 protocol ip u32 \
match ip protocol 0x6 0xff \
match ip dport 80 0xffff \
match ip dst 1.2.3.4/32 \
classid 1:14
I can''t find it in the docs. I tried "!" "\!" and "not" in several
2001 Dec 08
0
tc filter u32 nexthdr, chained filters?
Hi.
Is there anyone who has understood of how u32 nexthdr addressing is supposed
to work? (including the "tcp/icmp/.." matches who implicitly uses nexthdr)
From reading the kernel code it apparently is using the location set by
"offset at", but this seems to only be evaluated on hash parents, and only
for it''s children..
I.e. the logic for u32 filter rule
2002 Sep 20
2
u32 filter question
Hi guys I have a config as follows for one of my networks. I want to give the xxx.xxx.xxx.xxx/xx network 64kbit for everything from the internet but 8000kbit from our internal servers on yyy.yyy.yyy.yyy/yy network. It does not work. I only want to use u32 filters. I think what's happening is the first flowid of 1:21 is catching them and not getting to the 1:40 flowid. Is this right? The box
2007 Sep 23
0
Add U32 Filter with libnl
Hello,
I try to add a U32 source port filter with libnl. My filter can be
succesfully added with the library (no error occured) but the filter is not
active.
If I run "tc filter show dev eth0" I get:
filter parent 1: protocol ip pref 100 u32 filter parent 1: protocol ip pref
100 u32 fh 800: ht divisor 1 filter parent 1: protocol ip pref 100 u32 fh
800::800 order 2048 key ht 800 bkt 0
2006 Jun 23
1
tc filter change (Please)
The filter -> tc filter add dev eth1 parent 1:0 protocol all prio 1 u32
match u8 0x6 0xff at 9 match u32 0xa640105 0xffffffff at 16 offset at 0 mask
0f00 shift 6 eat link 5:0:0
Can anyone please tell me how to change it ?
I''ve being searching and trying to make sense of the man pages all day.
_______________________________________________
LARTC mailing list
LARTC@mailman.ds9a.nl
2004 Jul 09
3
tc filter + bridging + htb -- works only if ip_forward = 0
I thought that the below email would be of interest to LARTC readers. I
wasted quite a bit of time tracking down this "feature" (bug?). Any
comments that shed light on this would be appreciated. In short, "tc
filter" + htb + bridging works only with ip_forward off.
Andrew Athan
-----------------------------------------------------------------------
All:
It seems that