Chris Egolf wrote:
> > I take it that you can't use one fwmark which handles both of your current
> > groups?
> >
> I'm trying to handle requests differently depending on the network they
> come from. If it's coming from the internal network, I want to handle
> persistence per client, but if they're coming from the outside, I want to
> apply a netmask w/ persistence to deal w/ the proxy farm issue.
If the two groups of packets are coming from two different MAC addresses
then you (should be able to - I haven't done it) use the -sh scheduler
and have one fwmark group. The docs are a little thin on the matter, I'm
afraid and I haven't heard of anyone using it besides the author (and
Wensong presumably who would have checked it out).
Joe
--
Joseph Mack PhD, Senior Systems Engineer, Lockheed Martin
contractor to the National Environmental Supercomputer Center,
mailto:mack.joseph@xxxxxxx ph# 919-541-0007, RTP, NC, USA
|