Using PF + ALTQ in FreeBSD 6.2

Chris Marlatt cmarlatt at rxsec.com
Mon Aug 13 13:28:19 UTC 2007


David DeSimone wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> I'm curious what you think your router can do to prevent hosts on the
> internet from sending traffic too fast.
> 
> Once you have received the packets, it is too late to limit their
> arrival rate.
> 

Can't ipfw do this through dummynet? It seems to work fine for me in my 
tests.

Now yes it's not really preventing them from sending traffic, but it 
should still be able to queue it and invoke latency to simulate a slower 
link/pipe.

Regards,

	Chris


More information about the freebsd-pf mailing list