net.inet.ip.fw.one_pass=0 for complex WISP shaping



  • Hi all, this is my first post here. I currently have over 700 customer connected to a pfsense gateway. I want to disable net.inet.ip.fw.one_pass so that i can pass traffic through a chain of pipes/queues for example, the first pipe limits each user to 20mbits download using a /32 mask and the next pipe limits a group of subnets (total traffic over a p2p link) to 100mbits with a queue to dynamically share the bandwidth in that pipe. I can simulate this with a couple of pfsense boxes in series but it just seems like a wast when one box has more than enough cpu power to do it. What i run sysctl net.inet.ip.fw.one_pass=0, i get an unknown oid error. Can anyone help?

    Thank in advance.