[ previous ] [ next ] [ threads ]
 From:  Justin Ellison <justin at techadvise dot com>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Shaping Bridge Observations
 Date:  Mon, 17 Jan 2005 10:05:47 -0600
Hi all,

Just to see if it could be done, I wanted to see if I could get m0n0 to
work in a "shaping bridge" configuration.  

First, I bridged the OPT1 interface to the WAN interface, and enabled
the filtering bridge.  I then added rules to allow everything on both
the OPT1 and WAN interfaces.

Then onto the shaper.  I created two pipes, one for upload, and one for
download.  Now, for the interesting part.  In the bridged config, only
incoming shaper rules would match.  For example, to limit the download
of a PC on the OPT1 interface, I had to create a rule that shaped
inbound traffic on the WAN with a destination of the IP of the client on
the OPT1 interface.  If I created a rule that shaped outbound traffic
from the OPT1 interface, it wouldn't work.  The same thing vice-versa
with uploads.

Can anyone explain to me why this is the case?  I'm guessing that it's
the way that ipfw sees bridged interfaces?