Project

General

Profile

Actions

Bug #1575

closed
EL

Limiters are bypassed by local applications injecting rules

Bug #1575: Limiters are bypassed by local applications injecting rules

Added by Ermal Luçi over 15 years ago. Updated about 7 years ago.

Status:
Resolved
Priority:
Low
Assignee:
-
Category:
Traffic Shaper (Limiters)
Target version:
-
Start date:
06/02/2011
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:

Description

Taking a look at http://forum.pfsense.org/index.php/topic,37399.0.html
it would be good to teach the match action about limiters as well to avoid such kind of issues.

CB Updated by Chris Buechler over 15 years ago Actions #1

  • Target version deleted (2.0)

NS Updated by Nikolay Stoyanov over 14 years ago Actions #2

I have same problem in latest 2.0.1-RELEASE.
http://forum.pfsense.org/index.php/topic,46469.0.html

BC Updated by Bipin Chandra about 14 years ago Actions #3

will this be fixed or is it fixed in 2.1?

EL Updated by Ermal Luçi almost 14 years ago Actions #4

Normally this can be overcommed with match rules on floating tab.
It is present there on 2.1 and i am pushing the fix to allow the rule for limiters as well.

Just create a Match rule under floating rules with limiters you want and it would be applied to these rules.

EL Updated by Ermal Luçi almost 14 years ago Actions #5

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

Applied in changeset commit:84464c9ab0b94b9602c6ec62502dc4ad3e7a8c0a.

BC Updated by Bipin Chandra over 13 years ago Actions #6

does seem to work still, upnp devices bypass limiter

EL Updated by Ermal Luçi over 13 years ago Actions #7

Can you provide any analysis of how you do your checking?
Also provide a

ipfw pipe show
ipfw queue show
pfctl -vvsr
pfctl -vvsn
pfctl -a miniupnpd -vvsn
pfctl -a miniupnpd -vvsr

BC Updated by Bipin Chandra over 13 years ago Actions #8

this was discussed here
http://forum.pfsense.org/index.php/topic,56092.0.html

the easy way to test this is, enable upnp, create limiters, create match rules under floating tab with limiters applied then u first do a speed test and it will be limited fine, now that same speed limit should apply but start a torrent download using utorrent or any such software and make it open a random port using upnp and then notice the download and upload speed exceed the limiter value and this way u know it never works once any application tries to open a port using upnp, the limiter almost becomes dead, it does work fine for other ports not opened by upnp

EL Updated by Ermal Luçi over 13 years ago Actions #9

In that forum post i do not see any limiters configured on the ruleset posted.
So please provide the information if you want this to be pursued.

BC Updated by Bipin Chandra over 13 years ago Actions #10

plz remove post after u have read it

EL Updated by Ermal Luçi over 13 years ago Actions #11

Can you try by removing the quick option on the match rules, if you have selected it?

BC Updated by Bipin Chandra over 13 years ago Actions #12

yes its ticked, trying without that now but if we untick then i guess in the past there was a problem of traffic for those clients not going to proper queues and i guess u only mentioned in the forum a very long time back that it needs to be ticked but for now i didnt assign any queues to those rules so no issues

BC Updated by Bipin Chandra over 13 years ago Actions #13

tried it still same, clients upload speed exceeds limiter values

CB Updated by Chris Buechler almost 12 years ago Actions #14

  • Category set to Traffic Shaper (Limiters)
  • Affected Version changed from 2.0 to All

Updated by Anonymous over 7 years ago Actions #15

Is this issue still present in the latest development build?

JP Updated by Jim Pingle about 7 years ago Actions #16

  • Status changed from Feedback to Resolved
Actions

Also available in: Atom