Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 6 Oct 2006 12:37:32 +0200
From:      <Tyrone@TelecityRedbus.se>
To:        <freebsd-ipfw@freebsd.org>, <freebsd-isp@freebsd.org>
Subject:   RE: Dummynet,VLAN and CARP broken??
Message-ID:  <D3BBF0C6F2FC0448BFCA2F965F2192631DED9B@sto1.tcy.prv>
In-Reply-To: <D3BBF0C6F2FC0448BFCA2F965F2192631DED9A@sto1.tcy.prv>

next in thread | previous in thread | raw e-mail | index | archive | help
I found out that you still need to let carp packets through even though
all you doing is traffic shaping=20

So ipfw add 1 allow carp from any to any=20

Did the trick for me=20

Regards

tyrone


-----Original Message-----
From: owner-freebsd-isp@freebsd.org
[mailto:owner-freebsd-isp@freebsd.org] On Behalf Of
Tyrone@TelecityRedbus.se
Sent: den 6 oktober 2006 11:46
To: freebsd-ipfw@freebsd.org; freebsd-isp@freebsd.org
Subject: Dummynet,VLAN and CARP broken??

Hi

Running FreeBSD6.1-RC
Kernel compiled with the following=20

options         IPFIREWALL              #firewall
options         IPFIREWALL_VERBOSE      #enable logging to syslogd(8)
options         IPFIREWALL_FORWARD      #enable transparent proxy
options         IPFIREWALL_VERBOSE_LIMIT=3D100    #limit verbosity
options         IPFIREWALL_DEFAULT_TO_ACCEPT    #allow everything by
options         IPDIVERT                #divert sockets
options         DUMMYNET
options         BRIDGE
options	      	HZ=3D1000=09
options         FAST_IPSEC
options         TCP_SIGNATURE
device          crypto
device          cryptodev
device		carp

Problem is with the CARP addresses staying in the "master" "master"
position when I have dummynet stripping bandwidth on that vlan. I take
the dummnet config away then the carp interfaces go to "master" and
"backup" as required.

My dummynet configs look like this

ipfw pipe 100 config bw 10500Kbit/s #setup shaping pipes 10Mbit
ipfw queue 1 config pipe 100 weight 100
ipfw queue 2 config pipe 100 weight 100
ipfw add 1000 queue 1 ip from any to any in via vlan148 =20
ipfw add 1000 queue 2 ip from any to any out via vlan148

I have an open FW so no carp message should be blocked is dummynet
broken?


Regards

Tyrone
This e-mail is intended only for the use of the addressees named above
and may be confidential.=20
If you are not an addressee you must not use any information contained
in nor copy it nor inform any person other than the addressees of its
existence or contents.=20


_______________________________________________
freebsd-isp@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-isp
To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
This e-mail is intended only for the use of the addressees named above an=
d may be confidential. =

If you are not an addressee you must not use any information contained in=
 nor copy it nor inform any person other than the addressees of its exist=
ence or contents. =

=0D



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?D3BBF0C6F2FC0448BFCA2F965F2192631DED9B>