Re: Bandwidth Throttling?
Kevin Hanser <[email protected]> Wed, 05 Oct 2005 14:00:32 -0400
| Newsgroups | gmane.network.nocat |
|---|---|
| Message-ID | <[email protected]> |
ulrich schwarz wrote: >without the option "bounded" throttling is done only when other classes >use up the available bandwidth. with that option the clients get >throttled wether there is free bandwidth or not. > >so this should work with a client connected per crossover cable. > >you could check iptables -L in order to see in which class you client >gets permitted by taking a look at the FW mark. as long as i remember, >it goes like this: > >FW mark | class >1 | owner (authentication needed and presence in nocat.conf) >2 | member/coop (authentication needed) >3 | public (pressed SKIP at login) > > > > After I've logged in, my iptables -L shows this: [root@nocatgw nocat]# iptables -L Chain FORWARD (policy ACCEPT) target prot opt source destination NoCat all -- anywhere anywhere Chain INPUT (policy ACCEPT) target prot opt source destination Chain NoCat (1 references) target prot opt source destination NoCat_Ports all -- anywhere anywhere NoCat_Inbound all -- anywhere anywhere ACCEPT all -- 192.168.123.0/24 anywhere MARK match 0x1 ACCEPT all -- 192.168.123.0/24 anywhere MARK match 0x2 ACCEPT tcp -- 192.168.123.0/24 host14-195-91-207.mica.net tcp dpt:http ACCEPT tcp -- host14-195-91-207.mica.net 192.168.123.0/24 tcp spt:http ACCEPT tcp -- 192.168.123.0/24 host14-195-91-207.mica.net tcp dpt:https ACCEPT tcp -- host14-195-91-207.mica.net 192.168.123.0/24 tcp spt:https ACCEPT all -- nocatgw.mica.net 192.168.123.0/24 ACCEPT tcp -- 192.168.123.0/24 nocatgw.mica.net tcp dpt:domain ACCEPT udp -- 192.168.123.0/24 nocatgw.mica.net udp dpt:domain DROP tcp -- !host14-195-91-207.mica.net anywhere tcp dpt:5280 DROP all -- anywhere anywhere Chain NoCat_Inbound (1 references) target prot opt source destination ACCEPT all -- anywhere 192.168.123.200 Chain NoCat_Ports (1 references) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination Which looks to me like my client (192.168.123.200) is being put in BOTH firewall marks?? Any idea why that would be happening? I don't have any owners configured in my nocat.conf, and I also don't have my test user added to the owner group.. The nocat.log looks like this when I login: [2005-10-05 13:54:47] Connection to 192.168.123.1 from 192.168.123.200 [2005-10-05 13:54:47] Capturing 192.168.123.200 for http://www.cnn.com/ [2005-10-05 13:54:47] Notifying parent of Capture on peer 00:01:02:C8:11:DB [2005-10-05 13:54:47] Spawning child process 27039. [2005-10-05 13:54:47] Got notification Capture of peer 00:01:02:C8:11:DB [2005-10-05 13:54:47] Child process returned 1 [2005-10-05 13:54:58] Connection to 207.91.195.56 from 207.91.195.14 [2005-10-05 13:54:58] Spawning child process 27042. [2005-10-05 13:54:58] Received notify 00:01:02:C8:11:DB from 207.91.195.14 gpgv: Signature made Wed Oct 5 14:27:53 2005 EDT using DSA key ID A88EBC5D gpgv: Good signature from "MICA Networks NoCat AuthServ Test (Mars) <[email protected]>" [2005-10-05 13:54:58] Got auth msg Member Member Redirect http://www.cnn.com/ Mac 00:01:02:C8:11:DB Action Permit User memtest Mode login Timeout 86400 Token $1$92898461$Twg199K0wBoX.xUsn8KBv0 [2005-10-05 13:54:59] User (Member Any) v. trusted (Any) [2005-10-05 13:54:59] User memtest permitted in class Member [2005-10-05 13:54:59] Notifying parent of Permit on peer 00:01:02:C8:11:DB [2005-10-05 13:54:59] Available MACs: 00:01:02:C8:11:DB [2005-10-05 13:54:59] Responding with: User memtest Token $1$1$9Kskd3v8sk3fnuN0nf/Qo. Timeout 86400 [2005-10-05 13:54:59] Got notification Permit of peer 00:01:02:C8:11:DB [2005-10-05 13:54:59] Child process returned 1 and admintool -l shows this: [kmh@mars nocat]$ sudo bin/admintool -l Member Users in group 'Member' (* = admin): memtest [kmh@mars nocat]$ sudo bin/admintool -l Owner Users in group 'Owner' (* = admin): kmh As you can see, the user I'm testing with, memtest, is only in the member group... yet when I login and look @ the iptables rules... it looks like memtest is getting set in both firewall marks..? ideas? thx! k