Once on one high-load access server with about 5 Gb/s traffic in /var/log/syslog, errors began to appear frequently:
In this article I will briefly describe the difference between MASQUERADE and SNAT. MASQUERADE. Less fast routing than SNAT with mass requests, since for each new connection an IP address on the external network interface (WAN) is determined. Great for home use routers and when changing the IP address on the WAN interface.
The script every second displays the number of incoming and outgoing packets per second on the specified network interface.Place the contents of the script into a file, for example, pps.sh and execute by specifying the name of the network interface:
ipset – a tool consisting of a kernel module, libraries and utility, allowing you to organize a list of networks, IP or MAC addresses, etc., which is very convenient to use for example with IPTables.
Once I noticed on one of the computers that nothing was displayed in the network environment, and after selecting “Enable network discovery” in “Control Panel \ Network and Internet \ Network and Sharing Center \ Advanced Sharing Options”, the choice was still on “Disable network discovery”.
I will give examples of commands for viewing information about a network adapter in Linux. View network interfaces and assigned IP addresses:
I will give an example of a speed limit of up to 3.3 Gb/s on a network interface on Ubuntu Server 16.04:
nload – network interface bandwidth monitoring tool with graphical display in the terminal. Installing nload on Linux Ubuntu/Debian:
I will give an example of creating dummy interfaces in Linux. On the test I use Ubuntu Server 16.04. The first thing you need to load the module “dummy”, you can also add the option “numdummies = 2” to immediately create two dummyX interfaces:
I will give an example of balancing only incoming traffic with two channels using Quagga. On the test, I will use Ubuntu 16.04.4 LTS and Quagga 0.99.24.1, the network interface ens1f0 for the second provider with one neighbors and ens2f0 for the first provider with two neighbors, the local network will be connected to ens2f1. […]