Home
last modified time | relevance | path

Searched hist:e5dfb815181fcb186d6080ac3a091eadff2d98fe (Results 1 – 3 of 3) sorted by relevance

/openbmc/linux/net/sched/
H A DMakefilee5dfb815181fcb186d6080ac3a091eadff2d98fe Thu Jan 31 20:37:42 CST 2008 Patrick McHardy <kaber@trash.net> [NET_SCHED]: Add flow classifier

Add new "flow" classifier, which is meant to extend the SFQ hashing
capabilities without hard-coding new hash functions and also allows
deterministic mappings of keys to classes, replacing some out of tree
iptables patches like IPCLASSIFY (maps IPs to classes), IPMARK (maps
IPs to marks, with fw filters to classes), ...

Some examples:

- Classic SFQ hash:

tc filter add ... flow hash \
keys src,dst,proto,proto-src,proto-dst divisor 1024

- Classic SFQ hash, but using information from conntrack to work properly in
combination with NAT:

tc filter add ... flow hash \
keys nfct-src,nfct-dst,proto,nfct-proto-src,nfct-proto-dst divisor 1024

- Map destination IPs of 192.168.0.0/24 to classids 1-257:

tc filter add ... flow map \
key dst addend -192.168.0.0 divisor 256

- alternatively:

tc filter add ... flow map \
key dst and 0xff

- similar, but reverse ordered:

tc filter add ... flow map \
key dst and 0xff xor 0xff

Perturbation is currently not supported because we can't reliable kill the
timer on destruction.

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
H A Dcls_flow.ce5dfb815181fcb186d6080ac3a091eadff2d98fe Thu Jan 31 20:37:42 CST 2008 Patrick McHardy <kaber@trash.net> [NET_SCHED]: Add flow classifier

Add new "flow" classifier, which is meant to extend the SFQ hashing
capabilities without hard-coding new hash functions and also allows
deterministic mappings of keys to classes, replacing some out of tree
iptables patches like IPCLASSIFY (maps IPs to classes), IPMARK (maps
IPs to marks, with fw filters to classes), ...

Some examples:

- Classic SFQ hash:

tc filter add ... flow hash \
keys src,dst,proto,proto-src,proto-dst divisor 1024

- Classic SFQ hash, but using information from conntrack to work properly in
combination with NAT:

tc filter add ... flow hash \
keys nfct-src,nfct-dst,proto,nfct-proto-src,nfct-proto-dst divisor 1024

- Map destination IPs of 192.168.0.0/24 to classids 1-257:

tc filter add ... flow map \
key dst addend -192.168.0.0 divisor 256

- alternatively:

tc filter add ... flow map \
key dst and 0xff

- similar, but reverse ordered:

tc filter add ... flow map \
key dst and 0xff xor 0xff

Perturbation is currently not supported because we can't reliable kill the
timer on destruction.

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
H A DKconfige5dfb815181fcb186d6080ac3a091eadff2d98fe Thu Jan 31 20:37:42 CST 2008 Patrick McHardy <kaber@trash.net> [NET_SCHED]: Add flow classifier

Add new "flow" classifier, which is meant to extend the SFQ hashing
capabilities without hard-coding new hash functions and also allows
deterministic mappings of keys to classes, replacing some out of tree
iptables patches like IPCLASSIFY (maps IPs to classes), IPMARK (maps
IPs to marks, with fw filters to classes), ...

Some examples:

- Classic SFQ hash:

tc filter add ... flow hash \
keys src,dst,proto,proto-src,proto-dst divisor 1024

- Classic SFQ hash, but using information from conntrack to work properly in
combination with NAT:

tc filter add ... flow hash \
keys nfct-src,nfct-dst,proto,nfct-proto-src,nfct-proto-dst divisor 1024

- Map destination IPs of 192.168.0.0/24 to classids 1-257:

tc filter add ... flow map \
key dst addend -192.168.0.0 divisor 256

- alternatively:

tc filter add ... flow map \
key dst and 0xff

- similar, but reverse ordered:

tc filter add ... flow map \
key dst and 0xff xor 0xff

Perturbation is currently not supported because we can't reliable kill the
timer on destruction.

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>