| To: | Linux Advanced Routing and Traffic Control <lartc@mailman.ds9a.nl> |
|---|---|
| Subject: | [LARTC] newbie needs policing help |
| From: | Mike Wright <xktnniuymlla@mailinator.com> |
| Date: | Fri, 20 Jul 2007 13:45:14 -0700 |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | lartc-list@securepoint.com |
| Delivered-to: | lartc@outpost.ds9a.nl |
| List-archive: | <http://mailman.ds9a.nl/pipermail/lartc> |
| List-help: | <mailto:lartc-request@mailman.ds9a.nl?subject=help> |
| List-id: | "Mailinglist of the Linux Advanced Routing & Traffic Control project" <lartc.mailman.ds9a.nl> |
| List-post: | <mailto:lartc@mailman.ds9a.nl> |
| List-subscribe: | <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=subscribe> |
| List-unsubscribe: | <http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc>, <mailto:lartc-request@mailman.ds9a.nl?subject=unsubscribe> |
| Sender: | lartc-bounces@mailman.ds9a.nl |
| User-agent: | Mozilla Thunderbird 1.0.2-6 (X11/20050513) |
Hi listizens,Complete tc newbie here. I'm in a pinch because of a mail assault on a server. I've firewalled away many of the most egregious offenders but non-smtp services are still being DOS'ed because of all the mail traffic.
Here is what I've tried. (I did say newbie ;)
-----------------
#!/bin/sh
#
# policing parent
tc qdisc add dev eth0 handle ffff: ingress
#
# filter should slow tcp smtpd traffic to 64k max
tc filter add dev eth0 parent ffff: protocol ip prio 50 \
u32 match ip dport 0x25 0xFFFF match ip protocol 0x06 0xff \
police rate 55kbit burst 9k drop flowid :1
-----------------
...but I haven't the slightest idea how to check up on it. e.g. with
iproute2 I could say "ip route list" to see what was in there, but how
can I check tc rules? "tc qdisk show" gives some cryptic output but "tc
filter show dev eth0" returns nothing.
(I'm not even sure if the above rules make any sense :( ) Any helpers out there? TIA, Mike Wright :m) _______________________________________________ LARTC mailing list LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [LARTC] Re: gateway failover with linux, Grant Taylor |
|---|---|
| Next by Date: | Re: [LARTC] [SOLVED] newbie needs policing help, Mike Wright |
| Previous by Thread: | [LARTC] gateway failover with linux, Abhijit Menon-Sen |
| Next by Thread: | Re: [LARTC] [SOLVED] newbie needs policing help, Mike Wright |
| Indexes: | [Date] [Thread] [Top] [All Lists] |