--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: shorewall: speed problem when using simple traffic control and a value for OUT-BANDWIDTH
- From: Anders Lagerås <anders.lageras@gmail.com>
- Date: Sun, 16 Jan 2011 17:21:49 +0100
- Message-id: <20110116162149.22445.21580.reportbug@streamdredger.cutthroat.eu.org>
Package: shorewall
Version: 4.4.16-1
Severity: important
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
When using a tcinterfaces file that look like this
#INTERFACE TYPE IN-BANDWIDTH OUT-BANDWIDTH
eth0 external 9300kbit:100kb 9300kbit:100kb
does the limit work for in-bandwith, it becomes around 9Mb/s.
But it does not work for out-bandwidth, the out-bandwidth is limited to 0.2Mb/s,
not close to 9.3.
If the out-bandwith setting is removed does is work as normal, and the speed is adount 9Mb/s.
- -- System Information:
Debian Release: 6.0
APT prefers unstable
APT policy: (500, 'unstable'), (500, 'testing'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.32-5-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=sv_SE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Versions of packages shorewall depends on:
ii bc 1.06.95-2 The GNU bc arbitrary precision cal
ii debconf [debconf-2.0] 1.5.38 Debian configuration management sy
ii iproute 20100519-3 networking and traffic control too
ii iptables 1.4.10-1 administration tools for packet fi
ii perl-modules 5.10.1-17 Core Perl modules
shorewall recommends no packages.
Versions of packages shorewall suggests:
ii linux-image-2.6.26-2-amd 2.6.26-26lenny1 Linux 2.6.26 image on AMD64
ii linux-image-2.6.32-5-amd 2.6.32-30 Linux 2.6.32 for 64-bit PCs
ii make 3.81-8 An utility for Directing compilati
pn shorewall-doc <none> (no description available)
- -- Configuration Files:
/etc/default/shorewall changed:
startup=1
OPTIONS=""
/etc/shorewall/shorewall.conf changed:
STARTUP_ENABLED=Yes
VERBOSITY=1
LOGFILE=/var/log/firewall
STARTUP_LOG=/var/log/shorewall-init.log
LOG_VERBOSITY=2
LOGFORMAT="firewall: %s:%s:"
LOGTAGONLY=No
LOGLIMIT=60/min:20
LOGALLNEW=
BLACKLIST_LOGLEVEL=
MACLIST_LOG_LEVEL=info
TCP_FLAGS_LOG_LEVEL=info
SMURF_LOG_LEVEL=info
LOG_MARTIANS=Yes
IPTABLES=
IP=
TC=
IPSET=
PERL=/usr/bin/perl
PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin
SHOREWALL_SHELL=/bin/sh
SUBSYSLOCK=""
MODULESDIR=
CONFIG_PATH=/etc/shorewall:/usr/share/shorewall
RESTOREFILE=
IPSECFILE=zones
LOCKFILE=
DROP_DEFAULT="Drop"
REJECT_DEFAULT="Reject"
ACCEPT_DEFAULT="none"
QUEUE_DEFAULT="none"
NFQUEUE_DEFAULT="none"
RSH_COMMAND='ssh ${root}@${system} ${command}'
RCP_COMMAND='scp ${files} ${root}@${system}:${destination}'
IP_FORWARDING=Off
ADD_IP_ALIASES=No
ADD_SNAT_ALIASES=No
RETAIN_ALIASES=No
TC_ENABLED=Simple
TC_EXPERT=No
TC_PRIOMAP="2 3 3 3 2 3 1 1 2 2 2 2 2 2 2 2"
CLEAR_TC=Yes
MARK_IN_FORWARD_CHAIN=No
CLAMPMSS=No
ROUTE_FILTER=Yes
DETECT_DNAT_IPADDRS=No
MUTEX_TIMEOUT=60
ADMINISABSENTMINDED=Yes
BLACKLISTNEWONLY=Yes
MODULE_SUFFIX=ko
DISABLE_IPV6=Yes
DYNAMIC_ZONES=No
PKTTYPE=Yes
NULL_ROUTE_RFC1918=No
MACLIST_TABLE=filter
MACLIST_TTL=
SAVE_IPSETS=No
MAPOLDACTIONS=No
FASTACCEPT=Yes
IMPLICIT_CONTINUE=No
HIGH_ROUTE_MARKS=No
OPTIMIZE=15
EXPORTPARAMS=Yes
EXPAND_POLICIES=Yes
KEEP_RT_TABLES=No
DELETE_THEN_ADD=Yes
MULTICAST=No
DONT_LOAD=
AUTO_COMMENT=Yes
MANGLE_ENABLED=Yes
USE_DEFAULT_RT=No
RESTORE_DEFAULT_ROUTE=Yes
AUTOMAKE=No
WIDE_TC_MARKS=No
TRACK_PROVIDERS=No
ZONE2ZONE=2
ACCOUNTING=No
DYNAMIC_BLACKLIST=Yes
OPTIMIZE_ACCOUNTING=Yes
LOAD_HELPERS_ONLY=No
REQUIRE_INTERFACE=No
FORWARD_CLEAR_MARK=
COMPLETE=No
BLACKLIST_DISPOSITION=DROP
MACLIST_DISPOSITION=REJECT
TCP_FLAGS_DISPOSITION=DROP
- -- debconf information:
shorewall/invalid_config:
shorewall/dont_restart:
shorewall/major_release:
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAk0zGxkACgkQw5UvgfnzqGowFgCgtEGvkovHkhwcaX2v0sWXXYxE
GJcAoL1g31XYkNtc0zPurRkQikbynINc
=k9MZ
-----END PGP SIGNATURE-----
--- End Message ---