<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.frotmail.nl/index.php?action=history&amp;feed=atom&amp;title=TP2010</id>
	<title>TP2010 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.frotmail.nl/index.php?action=history&amp;feed=atom&amp;title=TP2010"/>
	<link rel="alternate" type="text/html" href="https://wiki.frotmail.nl/index.php?title=TP2010&amp;action=history"/>
	<updated>2026-06-15T08:03:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.3</generator>
	<entry>
		<id>https://wiki.frotmail.nl/index.php?title=TP2010&amp;diff=102&amp;oldid=prev</id>
		<title>Eric: Created page with &quot;=Info= * Proxy: Squid  ** Let op FD&#039;s (file descriptors) ** WCCP *** Squid in transparent mode, iptables redirect poort * Shaping op cisco ** Netflow: [http://forums.cacti.net/about12393.html] ** Shaping basics [http://slaptijack.com/networking/easy-traffic-shaping-in-cisco-ios/] ** [http://wiki.nil.com/Traffic_shaping_in_Cisco_IOS]  ** [http://www.cisco.com/en/US/docs/ios/12_1t/12_1t2/feature/guide/clsbsshp.html#wp1025965 uitleg]  Eerst definities:   class-map match-all...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.frotmail.nl/index.php?title=TP2010&amp;diff=102&amp;oldid=prev"/>
		<updated>2022-04-05T09:44:14Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;=Info= * Proxy: Squid  ** Let op FD&amp;#039;s (file descriptors) ** WCCP *** Squid in transparent mode, iptables redirect poort * Shaping op cisco ** Netflow: [http://forums.cacti.net/about12393.html] ** Shaping basics [http://slaptijack.com/networking/easy-traffic-shaping-in-cisco-ios/] ** [http://wiki.nil.com/Traffic_shaping_in_Cisco_IOS]  ** [http://www.cisco.com/en/US/docs/ios/12_1t/12_1t2/feature/guide/clsbsshp.html#wp1025965 uitleg]  Eerst definities:   class-map match-all...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Info=&lt;br /&gt;
* Proxy: Squid &lt;br /&gt;
** Let op FD&amp;#039;s (file descriptors)&lt;br /&gt;
** WCCP&lt;br /&gt;
*** Squid in transparent mode, iptables redirect poort&lt;br /&gt;
* Shaping op cisco&lt;br /&gt;
** Netflow: [http://forums.cacti.net/about12393.html]&lt;br /&gt;
** Shaping basics [http://slaptijack.com/networking/easy-traffic-shaping-in-cisco-ios/]&lt;br /&gt;
** [http://wiki.nil.com/Traffic_shaping_in_Cisco_IOS]&lt;br /&gt;
&lt;br /&gt;
** [http://www.cisco.com/en/US/docs/ios/12_1t/12_1t2/feature/guide/clsbsshp.html#wp1025965 uitleg]&lt;br /&gt;
 Eerst definities:&lt;br /&gt;
  class-map match-all HTTP&lt;br /&gt;
    match protocol http&lt;br /&gt;
  class-map match-any HighPrio&lt;br /&gt;
    match packet length max 384&lt;br /&gt;
    match protocol icmp&lt;br /&gt;
&lt;br /&gt;
 Dan Policy&lt;br /&gt;
  policy-map blaa&lt;br /&gt;
   class HTTP&lt;br /&gt;
    shape average 10000000&lt;br /&gt;
&lt;br /&gt;
 En dan toepassen&lt;br /&gt;
  interface fa0/0&lt;br /&gt;
   service out blaa&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
           [  INET  ]&lt;br /&gt;
               |&lt;br /&gt;
         ______|_______&lt;br /&gt;
        |  Cisco 2811  |&lt;br /&gt;
        |______________|&lt;br /&gt;
               |&lt;br /&gt;
        _______|_______&lt;br /&gt;
       |  Cisco 3750   |&lt;br /&gt;
       |_______________|&lt;br /&gt;
          |  |  |  |&lt;br /&gt;
          |  |  |  |&lt;br /&gt;
      ____|__|__|__|_____             ___&lt;br /&gt;
    _|                   |_          /_ /|&lt;br /&gt;
   |          LAN          |--------|  | |  &amp;lt;-- Squid&lt;br /&gt;
   |_                     _|        |  | |&lt;br /&gt;
     |___________________|          |__|/&lt;br /&gt;
          |                     ___&lt;br /&gt;
          |____________________|___| &amp;lt;-- Client&lt;br /&gt;
                              /___/&lt;br /&gt;
&lt;br /&gt;
=Testconfig (v1)=&lt;br /&gt;
 class-map match-all HTTP&lt;br /&gt;
  match protocol http&lt;br /&gt;
 class-map match-all Prio&lt;br /&gt;
 class-map match-any SSH&lt;br /&gt;
  match protocol ssh&lt;br /&gt;
 class-map match-all High&lt;br /&gt;
  match class-map SSH&lt;br /&gt;
 class-map match-any HTTPS&lt;br /&gt;
  match access-group name HTTPS&lt;br /&gt;
 class-map match-any Normal&lt;br /&gt;
  match class-map HTTP&lt;br /&gt;
  match class-map HTTPS&lt;br /&gt;
 class-map match-any Prios&lt;br /&gt;
  match class-map Normal&lt;br /&gt;
  match class-map High&lt;br /&gt;
 class-map match-all Downstream&lt;br /&gt;
  match class-map Prios&lt;br /&gt;
 class-map match-all Web&lt;br /&gt;
  match class-map HTTP&lt;br /&gt;
  match class-map HTTPS&lt;br /&gt;
 class-map match-all Low&lt;br /&gt;
 !&lt;br /&gt;
 !&lt;br /&gt;
 policy-map Prio&lt;br /&gt;
 policy-map High&lt;br /&gt;
  class SSH&lt;br /&gt;
 policy-map Normal&lt;br /&gt;
  class HTTP&lt;br /&gt;
   police rate percent 70&lt;br /&gt;
     violate-action drop&lt;br /&gt;
  class HTTPS&lt;br /&gt;
 policy-map Prios&lt;br /&gt;
  class Normal&lt;br /&gt;
   bandwidth percent 70&lt;br /&gt;
   service-policy Normal&lt;br /&gt;
  class High&lt;br /&gt;
   bandwidth percent 30&lt;br /&gt;
   service-policy High&lt;br /&gt;
 policy-map Downstream&lt;br /&gt;
  class Downstream&lt;br /&gt;
   shape average 1000000&lt;br /&gt;
   service-policy Prios&lt;br /&gt;
  class class-default&lt;br /&gt;
   shape average 100000&lt;br /&gt;
 policy-map Low&lt;br /&gt;
 !&lt;br /&gt;
 interface FastEthernet0&lt;br /&gt;
  ip address 192.168.38.249 255.255.255.0&lt;br /&gt;
  ip broadcast-address 0.0.0.0&lt;br /&gt;
  ip nat outside&lt;br /&gt;
  ip virtual-reassembly&lt;br /&gt;
  duplex auto&lt;br /&gt;
  speed auto&lt;br /&gt;
 !&lt;br /&gt;
 interface Vlan1&lt;br /&gt;
  ip address 10.9.0.1 255.255.255.0&lt;br /&gt;
  ip broadcast-address 0.0.0.0&lt;br /&gt;
  ip nat inside&lt;br /&gt;
  ip virtual-reassembly&lt;br /&gt;
  service-policy output Downstream&lt;br /&gt;
 !&lt;br /&gt;
 ip route 0.0.0.0 0.0.0.0 192.168.38.1&lt;br /&gt;
 !&lt;br /&gt;
 ip access-list extended HTTP&lt;br /&gt;
  permit tcp any any eq www&lt;br /&gt;
 ip access-list extended HTTPS&lt;br /&gt;
  permit tcp any any eq 443&lt;br /&gt;
 ip access-list extended Mail&lt;br /&gt;
  permit tcp any any eq pop3&lt;br /&gt;
  permit tcp any any eq 143&lt;br /&gt;
  permit tcp any any eq 993&lt;br /&gt;
  permit tcp any any eq 995&lt;br /&gt;
  permit tcp any any eq smtp&lt;br /&gt;
 !&lt;br /&gt;
=testconfig (v5)=&lt;br /&gt;
Wanneer verkeer is binnen gekomen heeft het geen nut meer om te shapen. De queue van de provider zit dan al vol. De clue zit hem dus in het upstream shapen (upload naar je ISP) zodat je de eigen queue kan beheren. (WAN-out-shape)&lt;br /&gt;
&lt;br /&gt;
Downstream kunnen we wel policen om zo de TCP sessies te remmen. (WAN-in-police)&lt;br /&gt;
=Services=&lt;br /&gt;
==ACL==&lt;br /&gt;
 Opmerkingen:&lt;br /&gt;
 FTP, ipsec, pptp en l2tp: op nbar laten staan?&lt;br /&gt;
&lt;br /&gt;
 BIJWERKEN&lt;br /&gt;
&lt;br /&gt;
==Gaming==&lt;br /&gt;
===WoW===&lt;br /&gt;
 TCP: 3724, 6112, 6881-6999&lt;br /&gt;
 Game: TCP 1119 &amp;amp; 3724&lt;br /&gt;
 Voice: UDP 3724&lt;br /&gt;
 Downloader (updates): TCP 6112 &amp;amp; 6881-6999&lt;br /&gt;
===Steam===&lt;br /&gt;
 Steam Client&lt;br /&gt;
    * UDP 27000 to 27015 inclusive (Game client traffic)&lt;br /&gt;
    * UDP 27015 to 27030 inclusive (Typically Matchmaking and HLTV)&lt;br /&gt;
    * TCP 27014 to 27050 inclusive (Steam downloads)&lt;br /&gt;
    * UDP 4380&lt;br /&gt;
 Dedicated or Listen Servers&lt;br /&gt;
    * TCP 27015 (SRCDS Rcon port)&lt;br /&gt;
 Steamworks P2P Networking and Steam Voice Chat&lt;br /&gt;
    * UDP 3478 (Outbound)&lt;br /&gt;
    * UDP 4379 (Outbound)&lt;br /&gt;
    * UDP 4380 (Outbound)&lt;br /&gt;
 Additional Ports for Call of Duty: Modern Warfare 2 Multiplayer&lt;br /&gt;
    * UDP 1500 (outbound)&lt;br /&gt;
    * UDP 3005 (outbound)&lt;br /&gt;
    * UDP 3101 (outbound)&lt;br /&gt;
    * UDP 28960&lt;br /&gt;
==IM==&lt;br /&gt;
===MSN===&lt;br /&gt;
 Sign in to the Messenger service      TCP 80, 443, 1863&lt;br /&gt;
 Network Detection                     TCP 7001&lt;br /&gt;
                                       UDP 9, 7001&lt;br /&gt;
 Audio                                 TCP 80, 443, 1863&lt;br /&gt;
                                       TCP/UDP 30000 - 65535&lt;br /&gt;
 Audio (Legacy)                        UDP 5004 â€“ 65535&lt;br /&gt;
 Webcam and Video Conversations        TCP 80&lt;br /&gt;
                                       TCP/UDP 5000 - 65535&lt;br /&gt;
 File Transfer                         TCP 443, 1863&lt;br /&gt;
                                       TCP/UDP 1025 - 65535&lt;br /&gt;
 File Transfer (Legacy)                TCP 6891 - 6900&lt;br /&gt;
 Sharing Folders                       TCP 1863&lt;br /&gt;
                                       TCP/UDP 1025 â€“ 65535&lt;br /&gt;
 Whiteboard and Application Sharing    TCP 1503&lt;br /&gt;
 Remote Assistance                     TCP 3389&lt;br /&gt;
                                       TCP/UDP 49152 â€“ 65535&lt;br /&gt;
 Windows Live Call                     TCP 443, 5061&lt;br /&gt;
                                       UDP 5004 - 65525&lt;br /&gt;
 Games                                 TCP 80, 443, 1863&lt;br /&gt;
                                       TCP/UDP 1025 - 65535&lt;br /&gt;
&lt;br /&gt;
===Skype===&lt;br /&gt;
 Niet mogelijk vast te stellen?&lt;br /&gt;
&lt;br /&gt;
===IRC===&lt;br /&gt;
 TCP 6667&lt;br /&gt;
&lt;br /&gt;
===ICQ===&lt;br /&gt;
 TCP 5190&lt;br /&gt;
&lt;br /&gt;
==Blocked==&lt;br /&gt;
===Torrent===&lt;br /&gt;
 Op basis van headers?&lt;br /&gt;
 Is het nodig om dit te blokkeren als we inbound connecties niet door laten?&lt;br /&gt;
&lt;br /&gt;
===NNTP===&lt;br /&gt;
 TCP 119&lt;br /&gt;
&lt;br /&gt;
=Analyse=&lt;br /&gt;
==DNS==&lt;br /&gt;
  IPTraf&lt;br /&gt;
 â”Œ Packet Distribution by Size â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”&lt;br /&gt;
 â”‚                                                                              â”‚&lt;br /&gt;
 â”‚ Packet size brackets for interface eth0                                      â”‚&lt;br /&gt;
 â”‚                                                                              â”‚&lt;br /&gt;
 â”‚                                                                              â”‚&lt;br /&gt;
 â”‚ Packet Size (bytes)      Count     Packet Size (bytes)     Count             â”‚&lt;br /&gt;
 â”‚     1 to   75:            6118      751 to  825:               0             â”‚&lt;br /&gt;
 â”‚    76 to  150:            6710      826 to  900:               0             â”‚&lt;br /&gt;
 â”‚   151 to  225:             900      901 to  975:               0             â”‚&lt;br /&gt;
 â”‚   226 to  300:             329      976 to 1050:               0             â”‚&lt;br /&gt;
 â”‚   301 to  375:             130     1051 to 1125:               1             â”‚&lt;br /&gt;
 â”‚   376 to  450:             154     1126 to 1200:               0             â”‚&lt;br /&gt;
 â”‚   451 to  525:             101     1201 to 1275:               0             â”‚&lt;br /&gt;
 â”‚   526 to  600:              42     1276 to 1350:               0             â”‚&lt;br /&gt;
 â”‚   601 to  675:               4     1351 to 1425:               0             â”‚&lt;br /&gt;
 â”‚   676 to  750:               0     1426 to 1500+:              2             â”‚&lt;br /&gt;
 â”‚                                                                              â”‚&lt;br /&gt;
 â”‚                                                                              â”‚&lt;br /&gt;
 â”‚ Interface MTU is 1500 bytes, not counting the data-link header               â”‚&lt;br /&gt;
 â”‚ Maximum packet size is the MTU plus the data-link header length              â”‚&lt;br /&gt;
 â”‚ Packet size computations include data-link headers, if any                   â”‚&lt;br /&gt;
 â”” Elapsed time:   0:05 â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”˜&lt;br /&gt;
==SSH==&lt;br /&gt;
  Proto/Port â”€â”€â”€â”€â”€â”€â”€â”€â”€ Pkts â”€â”€â”€ Bytes â”€â”€ PktsTo â”€ BytesTo  PktsFrom BytesFrom â”€&lt;br /&gt;
  TCP/22                621     87044       311     16220       310     70824  &lt;br /&gt;
&lt;br /&gt;
 Sent: 621 p -&amp;gt; 87044 bytes = 140 bytes pp&lt;br /&gt;
 Received: 310 p -&amp;gt; 70824 bytes = 228 bytes pp&lt;/div&gt;</summary>
		<author><name>Eric</name></author>
	</entry>
</feed>