• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Traffic shaper changes [90% completed, please send money to complete bounty]

Scheduled Pinned Locked Moved Completed Bounties
375 Posts 72 Posters 515.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E Offline
    eri--
    last edited by Jun 5, 2008, 9:08 AM

    Can you please send me your rules.debug to ermal at pfsense.org just to check the order of the evaluation or it might be that the rules produced by the wizard are without the quick keyword and you can edit the floating rules to be terminating but that will mostly break the policy.
    I am sorry there is no easy fix to such a thing since there is no easy way to update the existing policy to conform to the new shaper :(.

    For the DMZ - LAN problem i would suggest trying living the queue policy in effect only for the internet connections ie on the Traffic shaper config delete the queue policy for LAN and DMZ and see if it suits you with shaping only on outbound. Usually it would suffice since the other part is throtled by the ISP and packets will be driven by the outgoing policy.

    If you need a more specific answer please give me some more detailed specification even in private if you wish.

    1 Reply Last reply Reply Quote 0
    • D Offline
      dps
      last edited by Jun 9, 2008, 8:17 AM

      Guys,

      How can i have access to the image with the multi nic shapper?

      Thank You!

      Duarte Santos

      1 Reply Last reply Reply Quote 0
      • P Offline
        Perry
        last edited by Jun 9, 2008, 9:00 AM

        If you donate xxx$ to it you'll get access.

        Please read every reply in this topic before asking any additional questions.

        /Perry
        doc.pfsense.org

        1 Reply Last reply Reply Quote 0
        • M Offline
          medien
          last edited by Jun 9, 2008, 12:01 PM

          multi lan in 1 WAN is very interesting.i hope you can develop per ip bandwidth limiting.thats what everybodys newbie waiting i think.

          1 Reply Last reply Reply Quote 0
          • E Offline
            eri--
            last edited by Jun 9, 2008, 5:04 PM

            Well expect surprises fro 1.3 or give it a thought/contribution for 1.2 :P.

            1 Reply Last reply Reply Quote 0
            • C Offline
              ccfiel
              last edited by Jun 28, 2008, 12:03 AM

              Good Day to all!

              Our small company needs a firewall with the following features. Does pfSense support the following requirements? We are willing to donate if it can fulfill the needs stated below.

              1. Support Dual WAN
              2. Traffic Shaper for Dual WAN ( distribute bandwidth equally for every workstation that uses the internet ) <–- i think this is the bounty?
              3. Web Proxy
              4. Samba

              Hope somebody can give me some info. Thanks and more power!

              Chris

              1 Reply Last reply Reply Quote 0
              • E Offline
                eri--
                last edited by Jun 28, 2008, 10:39 AM

                The current implementation that is ported to 1.2 that the bounty covered offers this through CBQ and with intimate knowledge with HFSC.

                Actually 1.3 would be the release which will really be my recommendation for this.

                AFAIK you can sponsor it somemore to get the 1.3 improvements to 1.2.

                Ermal

                1 Reply Last reply Reply Quote 0
                • T Offline
                  tomdchi
                  last edited by Jun 28, 2008, 3:00 PM

                  I just sent $100 to paypal@chrisbuechler.com.  I just started using pfsense last week and 1.3 would be a great help!

                  My paypal address used was billing@alumnipropertygroup.com

                  Thanks!
                  Tom

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    tomdchi
                    last edited by Jun 30, 2008, 1:34 AM

                    Just upgraded and WOW, this new shaper is AWESOME!!  Just what I needed!!

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      sullrich
                      last edited by Jun 30, 2008, 4:23 AM

                      @tomdchi:

                      Just upgraded and WOW, this new shaper is AWESOME!!  Just what I needed!!

                      Nice!!!

                      1 Reply Last reply Reply Quote 0
                      • C Offline
                        ccfiel
                        last edited by Jul 1, 2008, 3:24 PM

                        Hello I have donated $25 to paypal@chrisbuechler.com. Hope this little donation can bring more innovations! :) How can test this features? Thanks in advance and more power!

                        Chris

                        1 Reply Last reply Reply Quote 0
                        • E Offline
                          eri--
                          last edited by Jul 2, 2008, 5:00 PM

                          For all of you that are running the new shaper with multiple interfaces there is a bug that will prevent it from working correctly.
                          Please see http://cvstrac.pfsense.org/chngview?cn=23485 and make the change manually for now until a new update is released to you.

                          @ccfiel
                          read your private messages.

                          1 Reply Last reply Reply Quote 0
                          • C Offline
                            ccfiel
                            last edited by Jul 3, 2008, 2:21 AM

                            I have tried the new filter.inc. but there is an error when loading pfsense. Fatal error: Call to undefined function: get_configured_interface_with_descr() in /etc/inc/filter.inc on line 431. any ideas? :)

                            Chris

                            1 Reply Last reply Reply Quote 0
                            • E Offline
                              eri--
                              last edited by Jul 3, 2008, 6:44 AM

                              Just change the lines i have sent in the link above.

                              What you have done is taking the filter.inc from RELENG_1(aka 1.3), DO NOT DO THAT.
                              RELENG_1 is way changed from RELENG_1_2.

                              Ermal

                              1 Reply Last reply Reply Quote 0
                              • C Offline
                                ccfiel
                                last edited by Jul 3, 2008, 9:32 AM Jul 3, 2008, 9:24 AM

                                hello ermal , oh i see. I just want to make sure if what i did is correct. this is what i have in line 2170. so i have to delete this 4 lines?

                                let out anything from the firewall host itself and decrypted IPsec traffic

                                pass out on $lan proto icmp keep state label "let out anything from firewall host itself"
                                pass out on $wan proto icmp keep state label "let out anything from firewall host itself"
                                pass out on $wanif all keep state label "let out anything from firewall host itself"

                                and add this 3 lines ?

                                let out anything from the firewall host itself and decrypted IPsec traffic

                                pass  out  on  {$oc['if']}  proto  icmp  keep  state  label  "let  out  anything  from  firewall  host  itself"
                                pass  out  on  {$oc['if']}  all  keep  state  label  "let  out  anything  from  firewall  host  itself"

                                is this correct?

                                Chris

                                1 Reply Last reply Reply Quote 0
                                • E Offline
                                  eri--
                                  last edited by Jul 3, 2008, 11:16 AM

                                  Just replace the file in /etc/inc/filter.inc with the content from this LINK and you should be ok.

                                  Otherwise you just need to delete this 2 lines:
                                  pass  quick on  {$oc['if']}  proto  icmp  keep  state  label  "let  out  anything  from  firewall  host  itself"
                                  pass  quick on  {$oc['if']}  all  keep  state  label  "let  out  anything  from  firewall  host  itself"

                                  and make them

                                  pass  out  on  {$oc['if']}  proto  icmp  keep  state  label  "let  out  anything  from  firewall  host  itself"
                                  pass  out  on  {$oc['if']}  all  keep  state  label  "let  out  anything  from  firewall  host  itself"

                                  Whichever your prefer.

                                  Ermal

                                  1 Reply Last reply Reply Quote 0
                                  • V Offline
                                    venis_LA
                                    last edited by Jul 3, 2008, 3:04 PM

                                    i'm a newbie and want to know where and how can i contribute to get a copy to test 1.3 … many thanks thanks

                                    1 Reply Last reply Reply Quote 0
                                    • E Offline
                                      eri--
                                      last edited by Jul 3, 2008, 3:52 PM

                                      You want access to the new shaper on 1.2 or have you replied on the wrong thread?

                                      1 Reply Last reply Reply Quote 0
                                      • V Offline
                                        venis_LA
                                        last edited by Jul 3, 2008, 5:27 PM

                                        i want access to the new shaper .. thanks

                                        1 Reply Last reply Reply Quote 0
                                        • E Offline
                                          eri--
                                          last edited by Jul 3, 2008, 6:20 PM

                                          Well you can send the offerings at ermal.luci@gmail.com and i will give you the link to the new shaper.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            [[user:consent.lead]]
                                            [[user:consent.not_received]]