找回密码
 注册

QQ登录

只需一步,快速开始

搜索
查看: 2709|回复: 2

[其它] 直接针对detination port mark routing和先mark connection再mark packets的区别是?

[复制链接]
发表于 2010-11-5 20:44:24 | 显示全部楼层 |阅读模式

马上注册,结交更多好友,享用更多功能,让你轻松玩转社区。

您需要 登录 才可以下载或查看,没有账号?注册

×
如题,求高手解答~
routeros
 楼主| 发表于 2010-11-6 12:37:54 | 显示全部楼层
没人知道,还是没人看过呢?
routeros
回复

使用道具 举报

发表于 2010-11-7 11:45:26 | 显示全部楼层
http://forum.mikrotik.com/viewtopic.php?f=8&t=10458

Well, that was the kind of question, which bothered me too. Not sure if related to NAT (masquarading), but generally I think that you mark your connection just because of it. Then MT tracks the connection for you (correct me, if I am wrong, please  

If you can see, your marked packets are just equal to your marked connections, so marking packets does not add anything for you. The thing is, when you look at queue definition, you can add your "packet mark", not "connection mark".

So, my understanding is, that marking connecion is just helper to be able to properly mark packets.

One guy told me, that it would be easier to do shaping without masquarading, and insert one other router in front of your router, doing only masquarading. Can anyone confirm, that NAT is generally complicating our situation here?  

Thanks,
Petr

if you mark a packet with a connection mark, connection tracking will remember the mark whenever the return/consecutive packet(s) in the stream come along. You mark a stream/connection once and connection marking will remember it until the stream/connection is gone from the connections table.

A packet mark is forgotten as soon as the packet exits the router.

The reason there is two different ones is that you might want to apply different policies to packets that belong to the same stream/connection.

udp is connectionless but is considered a connection when udp packets flow through the router and a return packet of that exact host/port combination is returned. same goes for ip but there is no port combination.

Thus you must mark peer2peer connections with a connection mark and then a packet mark based on the connection mark to apply queueing. Otherwise you would just apply queueing to a single packet in the stream/connection (and that wouldnt make for very good peer2peer shaping!)

_________________
Repetition leads to inefficiency.
Inefficiency leads to failure.
Failure is suffering.


我不怎么看的懂,同问
routeros
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

QQ|Archiver|手机版|小黑屋|软路由 ( 渝ICP备15001194号-1|渝公网安备 50011602500124号 )

GMT+8, 2024-12-22 17:25 , Processed in 0.164177 second(s), 4 queries , Gzip On, Redis On.

Powered by Discuz! X3.5 Licensed

© 2001-2024 Discuz! Team.

快速回复 返回顶部 返回列表