QOS Layer7 in RC3

Home Page Forums Network Management ZeroShell QOS Layer7 in RC3

This topic contains 4 replies, has 0 voices, and was last updated by  mr_sarge 4 years, 4 months ago.

Viewing 6 posts - 1 through 6 (of 6 total)
  • Author
    Posts
  • #43754

    mr_sarge
    Member

    Hi,

    Does the Layer7 work in RC3 ? Because I’ve tried many type and I can’t ge it to work…

    Thank you

    #52954

    Saszka
    Member

    Hi there,

    I have the same problem.

    When I worked at Zeroshell 1.16beta QoS+ L7 work perfect.
    Properly recognize all the packages (SIP, RTP, HTTP).

    After installing 2.0RC2 and 2.0RC3 (2.0RC1 caused Kernell error) QoS does not work properly with the L7.

    Zeroshell works as the main router.
    WAN<


    Zeroshell(NAT,DHCP,VLAN)


    >LAN

    #52955

    Maklaut
    Member

    I have the same problem with l7-filter on 2.0RC3.
    Look at iptables mangle table – only original iptables rules (direct ip/port) works:


    Chain QoS (1 references)
    pkts bytes target prot opt in out source destination
    957K 693M MARK all -- * * 0.0.0.0/0 0.0.0.0/0 MARK and 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto bittorrent MARK set 0xc
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto edonkey MARK set 0xc
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto fasttrack MARK set 0xc
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto gnutella MARK set 0xc
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto directconnect MARK set 0xc
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto sip MARK set 0xb
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto rtp MARK set 0xb
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto rtsp MARK set 0xb
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto skypetoskype MARK set 0xb
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto skypeout MARK set 0xb
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto h323 MARK set 0xb
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    201 50280 MARK tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:22 MARK set 0xd
    201 50280 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 MARK set 0xd
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:23 MARK set 0xd
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:23 MARK set 0xd
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 LAYER7 l7proto ftp MARK set 0xe
    0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    6 3536 MARK all -- * * 77.72.169.0/24 0.0.0.0/0 MARK set 0xb
    6 3536 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    5 3557 MARK all -- * * 0.0.0.0/0 77.72.169.0/24 MARK set 0xb
    5 3557 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    850 170K MARK all -- * * 77.72.168.0/24 0.0.0.0/0 MARK set 0xb
    850 170K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    917 183K MARK all -- * * 0.0.0.0/0 77.72.168.0/24 MARK set 0xb
    917 183K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0
    #52956

    Maklaut
    Member

    I’m just posted a bug report

    #52957

    imported_fulvio
    Participant

    Hi,
    I use the L7 filters on a traffic shapper where the WAN and LAN network interfaces are in a layer 2 bridge and all works as expected. On my opinion they should work also in routing mode, but I have not tested that configuration yet.

    Regards
    Fulvio

    #52958

    Pit
    Member

    Hi,

    kernel 3.x.y has no support for layer7. Layer7 filter can not work.
    For this reason i asked Fulvio several times to give us back the kernel 2.x.y.

    No respoinse til today. Please build a lobby for this and ask again and again.

    Regards Pit

Viewing 6 posts - 1 through 6 (of 6 total)

You must be logged in to reply to this topic.