[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[altq 1289] Using ALTQ on our gateway: lost in config trouble :(
Hello all,
I'm in charge of the network of the company
I work for (well, I'm a journalist but
I have been for around five years a network
administrator) and I've got some trouble
with the setup here.
Previously, we were using a Windows 2k
gateway with recurrent problems (crashes,
dns problems and so on). So we are moving
to DSL and I have installed a new gateway.
This gateway is a Pentium 133 Mhz, with 32
Mb Ram. It runs OpenBSD 3.0 with all patches
applied and up to date. It has two network
cards, one to the Cisco (which is linked to
the DSL) and an other one to a hub (with
32 ports). This week I must move everyone
from the old SL (Specialized Line 256 Kbit)
to the DSL (512 Kbit).
Here is my current setup:
DSL --> Cisco 1400 --> PC --> Users on Hub
The DSL is a 512 Kbit line, with bursts
up to 2 Mbit (we have 512 Kbit all the
time and it can go up to 2 Mbit; I have
to consider it like a 2 Mbit link).
The Cisco 1400 is under control of our
ISP. I have no control over it. Its
configuration is:
IP: 192.168.1.1
Mask: 255.255.255.252
The PC has two Realtek cards, rl0 and
rl1. rl1 is connected to the Cisco router,
so we have this:
DSL --> Cisco (192.168.1.1) -->
PC (192.168.1.2)
The rl0 is connected to the Hub. All
users will be using this Hub to connect,
and their configuration will be:
IP: from 192.168.1.4 to 192.168.1.x
Mask: 255.255.255.0
Gateway: 192.168.1.3
I have installed and tested the
gateway, it works fine. Anyone that
connects on the hub using 192.168.1.3
as gateway and any IP of the form
192.168.1.x (from 192.168.1.4 to
192.168.1.254 ; last one being the
broadcast IP) can ping the net, surf
and so on.
Now my problem is: I have two kind
of people where I work. Some need
a prioritary access, and others
don't. So I would like to create
two classes: 50 % of the 2 Mbit
bandwidth would be allocated to
the first class (prioritary people)
and the other 50 % of the 2 Mbit
would be distributed to all other
users. Since we have never been
using this DSL link, perhaps I will
have to change this to 70/30 or
something else. I don't know yet :p
I have been reading the ALTQ TIPS
file, the altq.conf man page and
I have spent all my day trying to
configure ALTQ and I'm quite lost,
I get nowhere :p
I don't want to use different
network masks because people here
must see each other all the time,
and I'm using a 32 ports hub, not
a switch so if I start moving
prioritary people to a distinct
sub-network from others they're
not going to see each other :p
I would like (if possible using
ALTQ ?) to give 50 % of the 2Mbit
to a few select IP from the
range 192.168.1.4 to 192.168.1.254
(with a fair sharing of those 50 %
between those people) and to have
all other IPs (from the same
range) get the other 50 % (with
the fair sharing too).
Is that possible with ALTQ ?
Someone who already posted on
this list told me to use Dummynet,
but he gave me ipfw commands and
ipfw is no longer available
under OpenBSD after version 2.9
and I wish to use pf, not ipfw.
So ALTQ should be the best answer,
but I don't know how to set it up
correctly and because I have a lot
of work (and my boss want that
stuff to be working this week...)
I'm getting in trouble here and
I'm now asking for help here. :p
Please do not ask me to create
sub-nets if possible. Because of
the way journalists work here and
file exchanges I must keep everyone
on the same network and I'm just
tired of people launching GetRight
and eating all the bandwidth..
Well, hope you can help me. If I had
more time I would have continued
searching (yeap, I don't like asking
for help) but I've got too few time
and after one day working on it
I feel without any clue. Too me 20 min
to install OpenBSD and set it up as
gateway (pf not configured yet though)
and 8 hours working on ALTQ.. :(
Sorry for this long email. I'm a damn
too verbose dude, but you got all
the details so perhaps you can get
me out of this hole ;)
Greets to all,
--
Gilbert Fernandes
Login: Column Editor
Designed Network Admin :p