[Spce-user] Chain Mediaproxy Iptables
Francisco Romero | VOZELIA
francisco.romero at vozelia.com
Fri Dec 5 05:49:06 EST 2014
Okey. Thank everybody for all.
Regards.
Francisco
----- Original Message -----
From: "Marc Storck" <mstorck at voipgate.com>
To: "<spce-user at lists.sipwise.com>" <spce-user at lists.sipwise.com>
Sent: Friday, December 5, 2014 11:36:53 AM
Subject: Re: [Spce-user] Chain Mediaproxy Iptables
Make that: “that chain is mandatory, regardless of your input policy, if you want to benefit from in-kernel packet forwarding.”
Regards,
Marc
Hi,
as Richard said, that chain is mandatory if you want to benefit from in-kernel packet forwarding, which gives you a large boost in performance.
Daniel
On 12/05/2014 11:25 AM, Francisco Romero | VOZELIA wrote:
<blockquote>
Excuse me. I wanted to say "If you have NOT set up reject policy input".
Francisco.
----- Original Message -----
From: "Daniel Grotti" <dgrotti at sipwise.com>
To: "Francisco Romero | VOZELIA" <francisco.romero at vozelia.com>
Cc: spce-user at lists.sipwise.com
Sent: Friday, December 5, 2014 11:16:48 AM
Subject: Re: [Spce-user] Chain Mediaproxy Iptables
Hi,
what do you mean ?
We don't set up reject policy input.
Daniel
On 12/05/2014 10:58 AM, Francisco Romero | VOZELIA wrote:
<blockquote>
Thank you Daniel.
Handbook contains:
For each media stream, it opens two pairs of UDP ports on the public interface in the range of 30000 and 40000 per default
I think It's necessary If you have set up reject policy input.
Regards.
Francisco
From: "Daniel Grotti" <dgrotti at sipwise.com>
To: spce-user at lists.sipwise.com
Sent: Friday, December 5, 2014 10:32:29 AM
Subject: Re: [Spce-user] Chain Mediaproxy Iptables
Hi,
yes, it's really necessary.
Please read the handbook:
https://www.sipwise.com/doc/mr3.6.1/spce/ar01s02.html#_media_relay
Daniel
On 12/05/2014 10:25 AM, Francisco Romero | VOZELIA wrote:
<blockquote>
Hi list,
I have noticed there is a chain from mediaproxy and a reference in input chain:
Chain INPUT (policy ACCEPT)
target prot opt source destination
mediaproxy all -- 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain mediaproxy (1 references)
target prot opt source destination
It is necessary for something or could I delete it?
Regards.
Francisco
_______________________________________________
Spce-user mailing list Spce-user at lists.sipwise.com https://lists.sipwise.com/listinfo/spce-user
_______________________________________________
Spce-user mailing list
Spce-user at lists.sipwise.com
https://lists.sipwise.com/listinfo/spce-user
</blockquote>
</blockquote>
_______________________________________________
Spce-user mailing list
Spce-user at lists.sipwise.com
https://lists.sipwise.com/listinfo/spce-user
</blockquote>
_______________________________________________
Spce-user mailing list
Spce-user at lists.sipwise.com
https://lists.sipwise.com/listinfo/spce-user
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.sipwise.com/pipermail/spce-user_lists.sipwise.com/attachments/20141205/bea76abc/attachment-0001.html>
More information about the Spce-user
mailing list