The QoS Firewall is up. I don’t have a copy of my scripts right now. When I was testing it, some how and I don’t know how, pf got turned off. It’s turned on by default on startup using flashdist’s rc script. This took me a while to figure out when it wasn’t working. I still haven’t found any documentation about using altq/pf with a transparent bridge. Half the documentation out there on the net is about altq before it was merged with pf. I’ll try to post my configs later, as I think they’ll help. I swear that I read somewhere that you can only use altq when filtering in on a transparent bridge, but it appears to work either way for me. I don’t think random early detection / RED is working correctly, as the firebox’s bandwidth monitor still shows very spikey traffic. Maybe this isn’t avoidable. I have no idea if using ToS bits or explicit congestion notification / ECN will make any difference with the upstream to iron this out, or if I can justify the time spent on company time.
I configured the third port on the 4801 as a monitor port by adding it to the bridge as a span.(“brconfig bridge0 addspan sis2”, this is all in one line in my rc file “brconfig bridge0 add sis0 add sis1 addspan sis2”.) The manual says it can’t be a bridge member and a span at the same time. I couldn’t get it to be either. This sucks, as it seems like it doesn’t bridge when it’s a span, so your monitoring station will need to have another link if you expect it to perform dns resolution and stuff.
I also can’t find the modern equivalent of altqstat. I have no idea how to monitor the queues. I tried searching, but this is difficult as I earlier noted there’s lots of old docs. I tried asking in #pf on freenode and nobody said a thing all day. I’ve been using etherape on the monitoring station but at the moment trying to add other protocols to the protocol analyzer window doesn’t do anything and I haven’t discovered why.
But it’s working. I had to pull VoIP traffic out of the VPN for now, and remember that RTP is all over the place, but I got it into a queue. I need to really research pf some more. As much as I’ve played with it, I don’t really really get it, and I think it is about time I did.
Eric, Joel and I met at FreedomHEC this morning and saw some more presentations. I’ve never been to an “unconference” before, so it was very laid back, but interesting. I’m sure it will be more busy and popular next year, as this was the first. Unfortunately the wireless internet only worked outside of the room we were in, on the 76th floor (or 75th floor mezzaine or something) and my ubuntu installation lacked any sort of development tools so I had to keep leaving to get them installed. It’s STILL not working right, and I’m a little frustrated with it. And my netgear atheros card is giving me “ath_attach: unable to attach hardware: ‘Hardware self-test failed’ (HAL status 14)” errors. Which mades me think I broke it switching back and forth between it and the orinoco card playing around. That sucks. I need it for a client test on wednesday. I’ll probably have to go buy another and I get the feeling the boss doesn’t like these expenses. Which is weird. Since we run exchange and shit. But we’re Microsoft gold certified partners and all that, so it’s probably really free in the end.
Someone came up to me at freedomhec and asked what I did. I told them I was a trainer at a vocational type school and they said, “like Strategy?”. I was dumbfounded. Advertising works?
I’m test posting this through flickr. I’m sure this is a mistake. But here goes.