Blame doc/actions/ifb-README

Packit d3f73b
Packit d3f73b
IFB is intended to replace IMQ.
Packit d3f73b
Advantage over current IMQ; cleaner in particular in in SMP;
Packit d3f73b
with a _lot_ less code.
Packit d3f73b
Packit d3f73b
Known IMQ/IFB USES
Packit d3f73b
------------------
Packit d3f73b
Packit d3f73b
As far as i know the reasons listed below is why people use IMQ.
Packit d3f73b
It would be nice to know of anything else that i missed.
Packit d3f73b
Packit d3f73b
1) qdiscs/policies that are per device as opposed to system wide.
Packit d3f73b
IFB allows for sharing.
Packit d3f73b
Packit d3f73b
2) Allows for queueing incoming traffic for shaping instead of
Packit d3f73b
dropping. I am not aware of any study that shows policing is
Packit d3f73b
worse than shaping in achieving the end goal of rate control.
Packit d3f73b
I would be interested if anyone is experimenting.
Packit d3f73b
Packit d3f73b
3) Very interesting use: if you are serving p2p you may want to give
Packit d3f73b
preference to your own locally originated traffic (when responses come back)
Packit d3f73b
vs someone using your system to do bittorent. So QoSing based on state
Packit d3f73b
comes in as the solution. What people did to achieve this was stick
Packit d3f73b
the IMQ somewhere prelocal hook.
Packit d3f73b
I think this is a pretty neat feature to have in Linux in general.
Packit d3f73b
(i.e not just for IMQ).
Packit d3f73b
But i won't go back to putting netfilter hooks in the device to satisfy
Packit d3f73b
this.  I also don't think its worth it hacking ifb some more to be
Packit d3f73b
aware of say L3 info and play ip rule tricks to achieve this.
Packit d3f73b
--> Instead the plan is to have a conntrack related action. This action will
Packit d3f73b
selectively either query/create conntrack state on incoming packets.
Packit d3f73b
Packets could then be redirected to ifb based on what happens -> eg
Packit d3f73b
on incoming packets; if we find they are of known state we could send to
Packit d3f73b
a different queue than one which didn't have existing state. This
Packit d3f73b
all however is dependent on whatever rules the admin enters.
Packit d3f73b
Packit d3f73b
At the moment this 3rd function does not exist yet. I have decided that
Packit d3f73b
instead of sitting on the patch for another year, to release it and then
Packit d3f73b
if there is pressure i will add this feature.
Packit d3f73b
Packit d3f73b
An example, to provide functionality that most people use IMQ for below:
Packit d3f73b
Packit d3f73b
--------
Packit d3f73b
export TC="/sbin/tc"
Packit d3f73b
Packit d3f73b
$TC qdisc add dev ifb0 root handle 1: prio
Packit d3f73b
$TC qdisc add dev ifb0 parent 1:1 handle 10: sfq
Packit d3f73b
$TC qdisc add dev ifb0 parent 1:2 handle 20: tbf rate 20kbit buffer 1600 limit 3000
Packit d3f73b
$TC qdisc add dev ifb0 parent 1:3 handle 30: sfq
Packit d3f73b
$TC filter add dev ifb0 protocol ip pref 1 parent 1: handle 1 fw classid 1:1
Packit d3f73b
$TC filter add dev ifb0 protocol ip pref 2 parent 1: handle 2 fw classid 1:2
Packit d3f73b
Packit d3f73b
ifconfig ifb0 up
Packit d3f73b
Packit d3f73b
$TC qdisc add dev eth0 ingress
Packit d3f73b
Packit d3f73b
# redirect all IP packets arriving in eth0 to ifb0
Packit d3f73b
# use mark 1 --> puts them onto class 1:1
Packit d3f73b
$TC filter add dev eth0 parent ffff: protocol ip prio 10 u32 \
Packit d3f73b
match u32 0 0 flowid 1:1 \
Packit d3f73b
action ipt -j MARK --set-mark 1 \
Packit d3f73b
action mirred egress redirect dev ifb0
Packit d3f73b
Packit d3f73b
--------
Packit d3f73b
Packit d3f73b
Packit d3f73b
Run A Little test:
Packit d3f73b
Packit d3f73b
from another machine ping so that you have packets going into the box:
Packit d3f73b
-----
Packit d3f73b
[root@jzny action-tests]# ping 10.22
Packit d3f73b
PING 10.22 (10.0.0.22): 56 data bytes
Packit d3f73b
64 bytes from 10.0.0.22: icmp_seq=0 ttl=64 time=2.8 ms
Packit d3f73b
64 bytes from 10.0.0.22: icmp_seq=1 ttl=64 time=0.6 ms
Packit d3f73b
64 bytes from 10.0.0.22: icmp_seq=2 ttl=64 time=0.6 ms
Packit d3f73b
Packit d3f73b
--- 10.22 ping statistics ---
Packit d3f73b
3 packets transmitted, 3 packets received, 0% packet loss
Packit d3f73b
round-trip min/avg/max = 0.6/1.3/2.8 ms
Packit d3f73b
[root@jzny action-tests]#
Packit d3f73b
-----
Packit d3f73b
Now look at some stats:
Packit d3f73b
Packit d3f73b
---
Packit d3f73b
[root@jmandrake]:~# $TC -s filter show parent ffff: dev eth0
Packit d3f73b
filter protocol ip pref 10 u32
Packit d3f73b
filter protocol ip pref 10 u32 fh 800: ht divisor 1
Packit d3f73b
filter protocol ip pref 10 u32 fh 800::800 order 2048 key ht 800 bkt 0 flowid 1:1
Packit d3f73b
  match 00000000/00000000 at 0
Packit d3f73b
        action order 1: tablename: mangle  hook: NF_IP_PRE_ROUTING
Packit d3f73b
        target MARK set 0x1
Packit d3f73b
        index 1 ref 1 bind 1 installed 4195sec  used 27sec
Packit d3f73b
         Sent 252 bytes 3 pkts (dropped 0, overlimits 0)
Packit d3f73b
Packit d3f73b
        action order 2: mirred (Egress Redirect to device ifb0) stolen
Packit d3f73b
        index 1 ref 1 bind 1 installed 165 sec used 27 sec
Packit d3f73b
         Sent 252 bytes 3 pkts (dropped 0, overlimits 0)
Packit d3f73b
Packit d3f73b
[root@jmandrake]:~# $TC -s qdisc
Packit d3f73b
qdisc sfq 30: dev ifb0 limit 128p quantum 1514b
Packit d3f73b
 Sent 0 bytes 0 pkts (dropped 0, overlimits 0)
Packit d3f73b
qdisc tbf 20: dev ifb0 rate 20Kbit burst 1575b lat 2147.5s
Packit d3f73b
 Sent 210 bytes 3 pkts (dropped 0, overlimits 0)
Packit d3f73b
qdisc sfq 10: dev ifb0 limit 128p quantum 1514b
Packit d3f73b
 Sent 294 bytes 3 pkts (dropped 0, overlimits 0)
Packit d3f73b
qdisc prio 1: dev ifb0 bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 1 1
Packit d3f73b
 Sent 504 bytes 6 pkts (dropped 0, overlimits 0)
Packit d3f73b
qdisc ingress ffff: dev eth0 ----------------
Packit d3f73b
 Sent 308 bytes 5 pkts (dropped 0, overlimits 0)
Packit d3f73b
Packit d3f73b
[root@jmandrake]:~# ifconfig ifb0
Packit d3f73b
ifb0    Link encap:Ethernet  HWaddr 00:00:00:00:00:00
Packit d3f73b
          inet6 addr: fe80::200:ff:fe00:0/64 Scope:Link
Packit d3f73b
          UP BROADCAST RUNNING NOARP  MTU:1500  Metric:1
Packit d3f73b
          RX packets:6 errors:0 dropped:3 overruns:0 frame:0
Packit d3f73b
          TX packets:3 errors:0 dropped:0 overruns:0 carrier:0
Packit d3f73b
          collisions:0 txqueuelen:32
Packit d3f73b
          RX bytes:504 (504.0 b)  TX bytes:252 (252.0 b)
Packit d3f73b
-----
Packit d3f73b
Packit d3f73b
You send it any packet not originating from the actions it will drop them.
Packit d3f73b
[In this case the three dropped packets were ipv6 ndisc].
Packit d3f73b
Packit d3f73b
cheers,
Packit d3f73b
jamal