Page MenuHomeVyOS Platform

Provide a CLI solution for Ingress Shaping when there is SNAT
Open, Requires assessmentPublicFEATURE REQUEST

Description

When both SNAT and an outbound traffic-policy have been configured, translations will happen before traffic policy comes into action. So, if a traffic-policy has been configured to classify traffic according to addresses, that will not work, as traffic-policy will see translated addresses. So very likely all the traffic will end up in its default class.

Fortunately that can be solved by VyOS CLI, as explained here.

Without SNAT, VyOS CLI also allows you to configure "ingress shaping" through an IFB. Here is the explanation.

The missing part is a CLI solution for an inbound traffic-policy when there is SNAT. I have not found the way to configure it through CLI.

Maybe is it possible through conntrack-sync?

As it is perfectly possible to successfully have Ingress Shaping with SNAT as explained here, it would be nice to fill that CLI gap in order to have a complete QoS solution for the most common scenarios.

Details

Difficulty level
Unknown (require assessment)
Version
1.2.x ; 1.3 ; qos ; tc
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)

Event Timeline

s.lorente created this task.Thu, Oct 8, 9:25 PM
s.lorente renamed this task from Provide a CLI solution for Ingress Shaping when there is SNAT. to Provide a CLI solution for Ingress Shaping when there is SNAT.Thu, Oct 8, 9:53 PM
s.lorente updated the task description. (Show Details)
s.lorente updated the task description. (Show Details)Thu, Oct 8, 10:06 PM
s.lorente added a project: VyOS 1.3 Equuleus.
s.lorente changed Version from - to 1.2.x ; 1.3 ; qos ; tc.
pasik added a subscriber: pasik.Fri, Oct 9, 6:25 AM
s.lorente updated the task description. (Show Details)Tue, Oct 13, 10:45 AM
s.lorente updated the task description. (Show Details)Tue, Oct 13, 10:48 AM
s.lorente updated the task description. (Show Details)Tue, Oct 13, 10:51 AM