Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #206934 > unrolled thread

Debian bridge with one VLAN iface - after upgrade from Deb 8 to 9 tc filters are bypassed for VLAN traffic?

Started by<kaskada@email.cz>
First post2019-04-04 01:20 +0200
Last post2019-04-04 14:20 +0200
Articles 3 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  Debian bridge with one VLAN iface - after upgrade from Deb 8 to 9 tc filters are bypassed for VLAN traffic? <kaskada@email.cz> - 2019-04-04 01:20 +0200
    Re: Debian bridge with one VLAN iface - after upgrade from Deb 8 to 9 tc filters are bypassed for VLAN traffic? deloptes <deloptes@gmail.com> - 2019-04-04 01:40 +0200
      Re: Debian bridge with one VLAN iface - after upgrade from Deb 8 to 9 tc filters are bypassed for VLAN traffic? <kaskada@email.cz> - 2019-04-04 14:20 +0200

#206934 — Debian bridge with one VLAN iface - after upgrade from Deb 8 to 9 tc filters are bypassed for VLAN traffic?

From<kaskada@email.cz>
Date2019-04-04 01:20 +0200
SubjectDebian bridge with one VLAN iface - after upgrade from Deb 8 to 9 tc filters are bypassed for VLAN traffic?
Message-ID<xIXkJ-29d-7@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hello community,





This is problem related to Debian 9, bridge, VLAN interface and HTB tc 
filters for traffic shaping...




For years I`m using Debian with bridged ethernet interfaces as a L2 
transparent traffic shaper. Shaper is based on HTB with tc hash filters. In 
the bridge there is also one VLAN interface where VLAN TAGeed traffic from 
customers is terminated. I`ve tried to google, change some bridge 
parameters, but no success.







Bridge setup:


brctl show bridge1

bridge name     bridge id               STP enabled     interfaces

bridge1         8000.0002a525xxyy       no              eth0

                                                                            
  eth1

                                                                            
  eth1.500








- eth1 (and of course eth1.500) is towards customers. Customers are sending 
some traffic TAGed with 500 and some traffic without VLAN TAG

- eth0 is uplink towards public internet




The problem and question:

This setup worked smoothly for years until I upgraded Debian 8 do Debian 9 
(which I didn`t like to do but I had to, lets say). And now, in Debian 9 
only customer traffic which is not TAGged can reach tc filters and than is 
properly send to appropriate tc class and shaped. BUT traffic with TAG 500 
bypasses tc filters which means it goes just to tc default class (which is 
not good) - yes TAGget traffic is not terminated, just is not passing tc 
filters




I guess I have to turn on some 0/1"switch" somewhere in the Debian 9... But 
please, do you know which switch?




If you would like to have more specific infos, please let me know, I`ll send
it ASAP.




Thank you in advance. At least for that you read it all :)

Pep.





[toc] | [next] | [standalone]


#206935

Fromdeloptes <deloptes@gmail.com>
Date2019-04-04 01:40 +0200
Message-ID<xIXE6-2fr-1@gated-at.bofh.it>
In reply to#206934
kaskada@email.cz wrote:

> This setup worked smoothly for years until I upgraded Debian 8 do Debian 9
> (which I didn`t like to do but I had to, lets say). And now, in Debian 9
> only customer traffic which is not TAGged can reach tc filters and than is
> properly send to appropriate tc class and shaped. BUT traffic with TAG 500
> bypasses tc filters which means it goes just to tc default class (which is
> not good) - yes TAGget traffic is not terminated, just is not passing tc
> filters
> 

Very confusing statement - is tagged traffic terminated or not? If you
configure VLAN on the interface you terminate.

> 
> 
> 
> I guess I have to turn on some 0/1"switch" somewhere in the Debian 9...
> But please, do you know which switch?

In stretch the naming of the interfaces changed and systemd also. I would
firstly eliminate both for the sake of simplicity.
Then go through

https://wiki.debian.org/TrafficControl
https://manpages.debian.org/stretch/iproute2/tc.8.en.html

Unfortunately I do not have the honor to use vlans on bridged interfaces
with debian and TC - means you have some firewall/router.

regards

[toc] | [prev] | [next] | [standalone]


#206949

From<kaskada@email.cz>
Date2019-04-04 14:20 +0200
Message-ID<xJ9vz-1e9-3@gated-at.bofh.it>
In reply to#206935

[Multipart message — attachments visible in raw view] — view raw

Hello,



thank you.






---------- Původní e-mail ----------
Od: deloptes <deloptes@gmail.com>
Komu: debian-user@lists.debian.org
Datum: 4. 4. 2019 1:32:08
Předmět: Re: Debian bridge with one VLAN iface - after upgrade from Deb 8 to
9 tc filters are bypassed for VLAN traffic? 
"kaskada@email.cz wrote: 

> This setup worked smoothly for years until I upgraded Debian 8 do Debian 9

> (which I didn`t like to do but I had to, lets say). And now, in Debian 9 
> only customer traffic which is not TAGged can reach tc filters and than is

> properly send to appropriate tc class and shaped. BUT traffic with TAG 500

> bypasses tc filters which means it goes just to tc default class (which is

> not good) - yes TAGget traffic is not terminated, just is not passing tc 
> filters 
> 

Very confusing statement - is tagged traffic terminated or not? If you 
configure VLAN on the interface you terminate. ""
 "
I`m sorry, I used wrong words. Yes, VLAN is terminated on that eth1.500 
interface. I meant that traffic in VLAN is not "DROPped" when passing the 
bridge/whole Debian server. It is just unTAGged and not going to tc filters.
 




None of interfaces including eth1.500 VLAN iface have IP/mask settings on 
them. All interfaces are just bridged together. The ony IP settings is set 
on the bridge just for management purposes, not for routing/terminating  
customers traffic. It is just pure bridge with traffic shaper. In fact it is
very simple configuration.



"
> 
> 
> 
> I guess I have to turn on some 0/1"switch" somewhere in the Debian 9... 
> But please, do you know which switch? 

In stretch the naming of the interfaces changed and systemd also. I would 
firstly eliminate both for the sake of simplicity. 
"



I`ve upgraded Debian using:

apt-get update

apt-get upgrade

apt-get dist-upgrade

and so on... procedure. So names of interfaces remained the same, all other 
parts of the "shaping system" which need to know interface names works fine.

Could systemd really be connected to this issue?

 
"Then go through 

https://wiki.debian.org/TrafficControl 
https://manpages.debian.org/stretch/iproute2/tc.8.en.html 
"



Yes, I`ll check it. There must by some change in some part of the system 
between Debian 8 and 9. 

 
"
Unfortunately I do not have the honor to use vlans on bridged interfaces 
with debian and TC - means you have some firewall/router. 

regards 

"
Best regards Pep. 
"
 
"

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web