LARTC - load balancing / routing by bandwidth

Posted on 2009-02-09
Last Modified: 2012-05-06
I'm trying to find out if it's possible to route based on current bandwidth consumption. I have a linux router connected to three networks:
- internal lan (eth1)
- 4mb/512kb cable connection (eth2)
- 3mb/3mb dual T1 connection (eth3).

Currently all unmarked traffic gets NAT'd and goes out eth2 (cable). I can mark traffic with iptables and force it to get NAT'd and go out eth3 (T1s). I also have a public /27 that gets routed directly out eth3 (T1s).

I just started messing around with TC to shape the outgoing bandwidth on eth2 (cable) since it has such little outgoing bandwidth. I'd like to be able to force all (NAT'd) traffic out eth2 (cable) until that link is maxed out and then let addition connections go out eth3 (T1s).

I'm aware I can load balance with iproute2 based on a weight, but I'd rather let the cable connection get consumed first and leave the T1s open for our server traffic.

Does anyone know if this is possible?

I've read the incredibly confusing howto docs on and in the section on ingress policing they talk about overlimits, which is in the right neighborhood:

I guess my real question is, is it possible to mark traffic using the TC commmand like I can with iproute2? Or can I send packets that come in on one interface to a TC qdisc on another interface?
Question by:jar3817
    LVL 27

    Accepted Solution

    > is it possible to mark traffic using the TC commmand like I can with iproute2?

    You can classify it and direct to any  queue on the _given_ interface, but you can't change interface _with TC_.
    >  Or can I send packets that come in on one interface to a TC qdisc on another interface?

    Again, not with TC.

    TC works after the routing decision (when outgoing interface has been already chosen), so if you like to pass some extra traffic to another interface, try to do it with iptables. Currently there is no module in IPtables, that would measure current byte  transfer rate per interface (however there is one, that measures transfer rate per connection), but you can measure it with some external tool (say once a minute) and then use iptables 'condition' module.
    iptables -t nat -A PREROUTING -m conntrack --ctstate NEW  -m condition --condition eth2_overloaded -j YOUR_ETH3_NAT_CHAIN

    then in external program, that will monitor your transfer rate: touch /proc/net/ipt_condition/eth2_overloaded

    to make it work, you should also install 'condition' module, that is not setup by default, read here: about installation.

    LVL 27

    Expert Comment

    I found a module, that might help you:
     also non-standard, I'm not sure even that it is still supported, but you may try :-)
    LVL 26

    Author Closing Comment

    Not really what I was looking for, but good enough, thanks!
    LVL 27

    Expert Comment

    Thank you for points.

    Really this problem is not easy. You are trying to apply some rule to every one packet where the packet itself doesn't play any role for the decision. Also there are no internal kernel structures for the rule 'condition', so some external process is required.
    LVL 26

    Author Comment

    Yeah, it's kind of a weird situation. This is an old machine that is in use 24/7 so maybe I'll look harder into when it's time to update this machine.

    Thanks for the input!

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Looking for New Ways to Advertise?

    Engage with tech pros in our community with native advertising, as a Vendor Expert, and more.

    The purpose of this article is to demonstrate how we can use conditional statements using Python.
    Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
    Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    10 Experts available now in Live!

    Get 1:1 Help Now