Where? I’m only seen lines (-) on high column. I’m curently downloading a pfSense video on youtube and the only column having traffic is default class.
Also, I have rules for web proxy stating that my IP should be marked for high class traffic shaping:
I think that there may be some corner cases where traffic is not marked or marks are not set on connections. I’d start ruling out squid, temporarily disabling the web proxy.
I’ll try to reproduce the problem on Monday.
BTW this is currently the content inside /etc/shorewall/mangle
# ================= DO NOT MODIFY THIS FILE =================
#
# Manual changes will be lost when this file is regenerated.
#
# Please read the developer's guide, which is available
# at NethServer official site: https://www.nethserver.org
#
#
#
# Shorewall version 4 - Mangle File
#
# For information about entries in this file, type "man shorewall-mangle"
#
# See http://shorewall.net/traffic_shaping.htm for additional information.
# For usage in selecting among multiple ISPs, see
# http://shorewall.net/MultiISP.html
#
# See http://shorewall.net/PacketMarking.html for a detailed description of
# the Netfilter/Shorewall packet marking mechanism.
####################################################################################################################################################
#ACTION SOURCE DEST PROTO DEST SOURCE USER TEST LENGTH TOS CONNBYTES HELPER PROBABILITY DSCP
# PORT(S) PORT(S)
#
# 20ndpi
# All nDPI traffic is marked in forward chain
#
#
# 40priorities
# All priority rules are marked inside the post chain.
# If FW is the source, rules are moved to output chain.
#
#
# 60providers
#
#
# 90ndpi
# Restore all markers
#
SAVE $FW
Just did the upgrade, it work quite well so far. Though I’m not having much on /etc/shorewall/mangle but rule from 80qos_fw template which is:
# 80qos_fw
# save priority packet marks for traffic from the firewall itself
SAVE $FW - - - - - !0x00/0xff
According to Shorewall this rule will:
Move Squid marked packets to the connection mark which such packets are part of.
So far squid marks packets for the first two rules defined in traffic shaping, which is something that should be improved, but that is something for another post.