Bug #7050
closedLimiter with PFsense 2.4 transparent proxy
100%
Description
Good morning Luiz, is as follows, transparent proxy use with the limiter by ip, what happens is that when setada the bandwidth control for a given ip of the network, navigation to, which I did test, formatted from scratch With the last beta of pfsense 2.4, just installed squid, I activated it as transparent, create it in the limiter tab a download rule and another upload, so with their configured speeds, I went in rules and created a rule setting a certain ip so that The control is made in / out, leaving the download first and the uplod second. If the limiter is deactivated, it returns to normal navigation, if it applies again to, thanks
Files
Updated by Kill Bill almost 8 years ago
Not sure what's special about 2.4 here; this has never worked since the hidden rules created by the package when set to transparent just do not apply any limiters. IOW, read this to get this working: https://forum.pfsense.org/index.php?topic=84725.msg464691#msg464691
(Hopefully should work on 2.4, on 2.3.x it'd just kill the traffic due to a well known bug with limiters and NAT.)
Is there something wrong with using Traffic Mgmt - Overall/Per-Host Throttling natively via Squid?
If someone wants to shuffle this under Packages - Squid category as a feature request, someone eventually might get to it. Certainly has nothing to do with "Developer tools", and it's not 2.4 specific either.
Updated by Luiz Souza almost 8 years ago
Nelson, can you submit (even privately if you prefer) a copy of your working settings for the 2.1.x version and also a copy of the 2.4 settings ?
Updated by Nelson Junior almost 8 years ago
- File BKP_2.1.5_FuncionandoPerfeitamente.xml BKP_2.1.5_FuncionandoPerfeitamente.xml added
- File BKP_2.4_Beta.xml BKP_2.4_Beta.xml added
Luiz good afternoon, I have two files as you requested, one working perfectly, which is called BKP_2.1.5_FunctionandoPerfectly, this is on the network 192.168.0.0/24, with an alias picking up the ips that I want them to do called ControlPandaPorIP, the other Is the beta 2.4 called BKP_2.4_Beta that is in a network 172.16.0.0/16, this with problems that apply to the rule for ip 172.16.0.2 it for a navigation, this is an alias only apply direct not Rules in / Out, but I already tested in all forms, with aliases etc ....
Updated by Luiz Souza almost 8 years ago
- Category changed from Developer Tools to Traffic Shaper (Limiters)
Updated by Luiz Souza almost 8 years ago
- Subject changed from Limiter Per IP Problem, with PFsense 2.4 transparent proxy to Limiter with PFsense 2.4 transparent proxy
- Status changed from New to Confirmed
The issue here is limiter (dummynet) and pf redir on the same interface.
The transparent proxy adds a rdr rule to redirect the HTTP traffic to squid and that cause issues with dummynet on same interface.
It works with squid only or limiters only, but both will cause intermittent failures.
Updated by Kill Bill almost 8 years ago
Luiz Otavio O Souza wrote:
The issue here is limiter (dummynet) and pf redir on the same interface.
The transparent proxy adds a rdr rule to redirect the HTTP traffic to squid and that cause issues with dummynet on same interface.
It works with squid only or limiters only, but both will cause intermittent failures.
Dunno, but this still sounds exactly the same as Bug #4326.
Updated by Luiz Souza almost 8 years ago
yeah, sort of. this is a fallout of 4326 not being properly tested under all conditions (nat, binat and rdr) - they have subtle implementation differences.
Updated by Luiz Souza almost 8 years ago
- Status changed from Confirmed to Feedback
- % Done changed from 0 to 100
Updated by Nelson Junior almost 8 years ago
- File 01 - Configuração do limiter.jpg 01 - Configuração do limiter.jpg added
- File 02 - Aplicação na Rule.jpg 02 - Aplicação na Rule.jpg added
- File 03 - Teste de download de arquivo.jpg 03 - Teste de download de arquivo.jpg added
- File 04 - Teste no velocimetro.jpg 04 - Teste no velocimetro.jpg added
Luiz Otavio O Souza wrote:
Fixed in the latest snapshot.
https://github.com/pfsense/FreeBSD-src/commit/994e779f035e9ed49909936d5773f930adfc4075
https://github.com/pfsense/FreeBSD-src/commit/4c908ee9021b280805f8f240274e7cb06bba80db
Solved, print attached screens. Thank you so much.
Updated by Renato Botelho almost 8 years ago
- Status changed from Feedback to Resolved