[ previous ] [ next ] [ threads ]
 From:  Kev Latimer <kev at ne23 dot net>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Traffic shaping in IPSec - alternatives?
 Date:  Tue, 21 Dec 2004 17:01:59 +0000
Hallo all,

My m0n0wall is all in and working but I've just had a flash of the 
blindingly obvious on something I'm trying to do.  I've been trying to 
traffic shape the data going up my VPN tunnel, specifically trying to 
prioritise the Terminal Services traffic.  A quick browse of the lists 
seems to confirm what I thought, that the traffic becomes ESP before the 
shaping "thing" (ipfw?) can see it.

Do you think shaping the traffic before it becomes ESP is something that 
will ever be feasible, or if not,does anyone have any suggestions on 
alternatives to prioritise the TS traffic?  So far, my only guess would 
be to have two tunnels and prioitise the traffic of one over the other 
but I'm just thinking out loud at the mo.