PF and ALTQ queue option.

Tom Judge tom at tomjudge.com
Mon Nov 27 10:42:44 PST 2006


Hi,

I am looking at using cbq to prioritise video conference traffic over 
all of the rest of the traffic crossing our VPN.  I was just wondering 
if the following configuration would to this (The vpn link is 2Mbit, in 
I will be running pf+altq at both ends of the link).



altq on em0 cbq qbandwidth 2Mb queue { normal, vidconf }
queue normal bandwidth 1Mb priority 0 cbq(ecn)
queue vidconf bandwidth 1Mb priority 1 cbq(ecn)

pass in on em0 from 172.17.0.123 to 10.0.0.123 queue vidconf
pass out on em0 from 10.0.0.123 to 172.17.0.123 queue vidconf

pass in on em0 from any to any queue normal
pass out on em0 from any to any queue normal

pass in quick on em0 from 172.17.0.0/16 to 10.0.0.0/16
pass out quick on em0 from 10.0.0.0/16 to 172.17.0.0/16


The main question I have is which queue will the traffic between 
10.0.0.123 and 172.17.0.123.  In the pf world it would seem it gets 
queued in normal, is this correct? if it is i guess i have to invert the 
rules like so:

pass in on em0 from any to any queue normal
pass out on em0 from any to any queue normal

pass in on em0 from 172.17.0.123 to 10.0.0.123 queue vidconf
pass out on em0 from 10.0.0.123 to 172.17.0.123 queue vidconf


Thanks

Tom


More information about the freebsd-pf mailing list