Project

General

Profile

Actions

Bug #15546

open

when trafic sphaper; delimiters are applied do not work in linux client over nat

Added by sezer h 6 months ago. Updated 6 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Traffic Shaper (Limiters)
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.7.2
Affected Architecture:

Description

when i set limiters from trafic shapers 10Mbit/s source address the nat rule not working correctly for just linux clients, i change limiters 15 Mbit/s its works nat rule.

if i changed firewall rules !this firewall its working everything

here it is nat rules

rdr on igb1 proto tcp from { 192.168.1.0/24 } to !(igb1) port 80 -> 127.0.0.1 port 8080 
rdr on igb1 proto tcp from { 192.168.1.0/24 } to !(igb1) port 443 -> 127.0.0.1 port 8081
00001:  10.000 Mbit/s    0 ms burst 0 
q131073  50 sl. 0 flows (1 buckets) sched 65537 weight 0 lmax 0 pri 0 droptail
 sched 65537 type FIFO flags 0x1 256 buckets 0 active
    mask:  0x00 0xffffffff/0x0000 -> 0x00000000/0x0000
00002:  10.000 Mbit/s    0 ms burst 0 
q131074  50 sl. 0 flows (1 buckets) sched 65538 weight 0 lmax 0 pri 0 droptail
 sched 65538 type FIFO flags 0x1 256 buckets 0 active
    mask:  0x00 0x00000000/0x0000 -> 0xffffffff/0x0000


Files

limiters.png (25.7 KB) limiters.png sezer h, 06/07/2024 10:30 AM
Actions #1

Updated by Chris W 6 months ago

What are you changing about the firewall rule which makes it work, and which pipe are you using (In or Out)? Pf doesn't care what operating system is sending it packets and from within a firewall rule's editor page, you can only switch the limiter on or off.

Actions #2

Updated by sezer h 6 months ago

Chris W wrote in #note-1:

What are you changing about the firewall rule which makes it work, and which pipe are you using (In or Out)? Pf doesn't care what operating system is sending it packets and from within a firewall rule's editor page, you can only switch the limiter on or off.

hi chris,

if closed nat rules its work everything, but i opened nat rules my source address its not works same value 10Mbit/source 10Mbit/destination, if i change 15Mbit/source address its works with nat rules.

but there is not exist bug 2.7.1 version of pfsense,

Actions

Also available in: Atom PDF