Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
linux_router:tc [2026-05-13 Wed wk20 21:28] – [Traffic Shaping with CAKE SQM] baumkplinux_router:tc [2026-07-12 Sun wk28 21:14] (current) – [Monitor CAKE statistics] baumkp
Line 4: Line 4:
 Queuing controls how data is sent; receiving data is much more reactive with fewer network-oriented controls. However, since TCP/IP packets are sent using a slow start the system starts sending the packets slow and keeps sending them faster and faster until packets start getting rejected - it is therefore possible to control how much traffic is received on a LAN by dropping packets that arrive at a router before they get forwarded. There are more relevant details, but they do not touch directly on queuing logic. Queuing controls how data is sent; receiving data is much more reactive with fewer network-oriented controls. However, since TCP/IP packets are sent using a slow start the system starts sending the packets slow and keeps sending them faster and faster until packets start getting rejected - it is therefore possible to control how much traffic is received on a LAN by dropping packets that arrive at a router before they get forwarded. There are more relevant details, but they do not touch directly on queuing logic.
  
 +++++Direct TC / qdisc, tldr;|
   *''sudo sysctl -a | grep qdisc'' shows current default settings   *''sudo sysctl -a | grep qdisc'' shows current default settings
   *''sudo sysctl -a | grep net.'' shows all the net. parameters, additional deeper filters net.core, net.ipv4, net.ipv6, net.mptcp, and net.netfilter.  There are a few additionals not shown in deeper filters!   *''sudo sysctl -a | grep net.'' shows all the net. parameters, additional deeper filters net.core, net.ipv4, net.ipv6, net.mptcp, and net.netfilter.  There are a few additionals not shown in deeper filters!
Line 14: Line 15:
 qdisc fq_codel 0: parent :2 limit 10240p flows 1024 quantum 1514 target 5ms interval 100ms memory_limit 32Mb ecn drop_batch 64  qdisc fq_codel 0: parent :2 limit 10240p flows 1024 quantum 1514 target 5ms interval 100ms memory_limit 32Mb ecn drop_batch 64 
 qdisc fq_codel 0: parent :1 limit 10240p flows 1024 quantum 1514 target 5ms interval 100ms memory_limit 32Mb ecn drop_batch 64 </code> qdisc fq_codel 0: parent :1 limit 10240p flows 1024 quantum 1514 target 5ms interval 100ms memory_limit 32Mb ecn drop_batch 64 </code>
 +++++
  
 =====Traffic Shaping with CAKE SQM===== =====Traffic Shaping with CAKE SQM=====
Line 22: Line 23:
 Test your connection at the [[https://www.waveform.com/tools/bufferbloat|Waveform Bufferbloat Test]] before doing anything. If you get a grade of C or worse, you have bufferbloat. Test your connection at the [[https://www.waveform.com/tools/bufferbloat|Waveform Bufferbloat Test]] before doing anything. If you get a grade of C or worse, you have bufferbloat.
  
-CAKE (Common Applications Kept Enhanced) is the modern Linux qdisc that fixes this. It combines Active Queue Management (AQM), Fair Queuing (FQ), and traffic shaping into a single qdisc. CAKE has been in the mainline kernel since 4.19, so no extra kernel modules are required on any modern distro. It replaced the older approach of combining fq_codel with htb shaping - CAKE does everything in one shot with less configuration. +[[https://www.man7.org/linux/man-pages/man8/tc-cake.8.html|CAKE]] (Common Applications Kept Enhanced) is the modern Linux qdisc that fixes this. It combines Active Queue Management (AQM), Fair Queuing (FQ), and traffic shaping into a single qdisc. CAKE has been in the mainline kernel since 4.19, so no extra kernel modules are required on any modern distro. It replaced the older approach of combining fq_codel with htb shaping - CAKE does everything in one shot with less configuration.
-Upload Shaping+
  
 +====Upload Shaping====
 Apply CAKE to your WAN interface with your upload bandwidth set to 90-95% of measured speed: Apply CAKE to your WAN interface with your upload bandwidth set to 90-95% of measured speed:
- +  *''%%tc qdisc replace dev wan0 root cake bandwidth 450mbit besteffort wash nat ack-filter-aggressive%%''
-''tc qdisc replace dev wan0 root cake bandwidth 450mbit besteffort wash nat ack-filter-aggressive''+
  
 Key options: Key options:
Line 35: Line 35:
   *ack-filter-aggressive - reduces TCP ACK congestion on asymmetric links (important if your download is much faster than upload)   *ack-filter-aggressive - reduces TCP ACK congestion on asymmetric links (important if your download is much faster than upload)
  
-Download Shaping with IFB+====Download Shaping with IFB====
  
 CAKE can only shape outgoing (egress) traffic. To shape incoming (ingress) traffic - which is where download bufferbloat lives - you redirect incoming packets through an Intermediate Functional Block (IFB) device and apply CAKE there: CAKE can only shape outgoing (egress) traffic. To shape incoming (ingress) traffic - which is where download bufferbloat lives - you redirect incoming packets through an Intermediate Functional Block (IFB) device and apply CAKE there:
- +++++bash script for ingress traffic| 
-# Create and bring up IFB device+<code bash># Create and bring up IFB device
 ip link add ifb-wan0 type ifb ip link add ifb-wan0 type ifb
 ip link set ifb-wan0 up ip link set ifb-wan0 up
Line 49: Line 49:
  
 # Apply CAKE on the IFB device # Apply CAKE on the IFB device
-tc qdisc replace dev ifb-wan0 root cake bandwidth 900mbit besteffort wash+tc qdisc replace dev ifb-wan0 root cake bandwidth 900mbit besteffort wash </code>
  
 Set the IFB bandwidth to 90-95% of your measured download speed. Set the IFB bandwidth to 90-95% of your measured download speed.
-Persist Across Reboots +++++ 
 +====Persist Across Reboots====
 These tc commands do not survive a reboot on their own. Create a systemd service: These tc commands do not survive a reboot on their own. Create a systemd service:
- +++++sudo vim /etc/systemd/system/sqm.service| 
-# /etc/systemd/system/sqm.service+<code bash># /etc/systemd/system/sqm.service
 [Unit] [Unit]
 Description=SQM (CAKE) Traffic Shaping Description=SQM (CAKE) Traffic Shaping
Line 82: Line 82:
  
 [Install] [Install]
-WantedBy=multi-user.target+WantedBy=multi-user.target</code>
  
-Enable it:+Enable it: ''%%sudo systemctl enable --now sqm.service%%'' 
 +++++
  
-systemctl enable --now sqm.service+====Verify It Works====
  
-Verify It Works+After applying CAKE, rerun the [[https://www.waveform.com/tools/bufferbloat|Waveform Bufferbloat Test]]. You should see latency under load drop from 200-500ms down to 5-15ms. Video calls stop freezing mid-sentence and game ping stays flat even during large transfers.
  
-After applying CAKE, rerun the Waveform Bufferbloat Test . You should see latency under load drop from 200-500ms down to 5-15ms. Video calls stop freezing mid-sentence and game ping stays flat even during large transfers. +====Monitor CAKE statistics==== 
- +  *''tc -s qdisc show dev wan0''  (Use IP a to check actual wan interface name, e.g. enp1s0) 
-Monitor CAKE statistics+  *''tc -s qdisc show dev ifb-wan0''
- +
-tc -s qdisc show dev wan0 +
-tc -s qdisc show dev ifb-wan0+
  
 This shows drops, ECN marks, and per-tin flow counts. If you see high drop rates, your bandwidth setting may be too close to the actual line speed. Lower it by another 5%. This shows drops, ECN marks, and per-tin flow counts. If you see high drop rates, your bandwidth setting may be too close to the actual line speed. Lower it by another 5%.
 +
 ====Links==== ====Links====
   *CAKE SQM   *CAKE SQM
     *[[https://botmonster.com/posts/build-linux-router-nftables-traffic-shaping/|Debian Router with nftables: CAKE SQM Reaches 15ms Latency]]     *[[https://botmonster.com/posts/build-linux-router-nftables-traffic-shaping/|Debian Router with nftables: CAKE SQM Reaches 15ms Latency]]
     *[[https://www.bufferbloat.net/projects/codel/wiki/Cake/|Cake - Common Applications Kept Enhanced]]     *[[https://www.bufferbloat.net/projects/codel/wiki/Cake/|Cake - Common Applications Kept Enhanced]]
 +    *[[https://www.bufferbloat.net/projects/codel/wiki/Cake/|Cake - Common Applications Kept Enhanced]]
 +    *[[https://www.bufferbloat.net/projects/codel/wiki/CakeRecipes/|Cake Recipes]]
 +    *[[https://www.bufferbloat.net/projects/codel/wiki/CakeTechnical/|Cake Technical Information]]
 +    *[[https://www.man7.org/linux/man-pages/man8/tc-cake.8.html|tc-cake]]
 +    *[[https://netdevconf.info/0x19/docs/netdev-0x19-paper16-talk-paper.pdf|mq-cake: Scaling software rate limiting across CPU cores]]
   *tc-fq_codel   *tc-fq_codel
     *[[https://www.man7.org/linux/man-pages/man8/tc-fq_codel.8.html|tc-fq_codel(8) — Linux manual page]]     *[[https://www.man7.org/linux/man-pages/man8/tc-fq_codel.8.html|tc-fq_codel(8) — Linux manual page]]
Line 119: Line 123:
   *Funtoo [[https://www.funtoo.org/Traffic_Control|Traffic Control]], good basic description.   *Funtoo [[https://www.funtoo.org/Traffic_Control|Traffic Control]], good basic description.
   *[[https://www.man7.org/linux/man-pages/man8/tc.8.html|man7.org - tc(8) — Linux manual page]]   *[[https://www.man7.org/linux/man-pages/man8/tc.8.html|man7.org - tc(8) — Linux manual page]]
 +  *[[https://www.man7.org/linux/man-pages/man8/tc-cake.8.html|tc-cake(8) — Linux manual page]]
 +  *[[https://www.man7.org/linux/man-pages/man8/tc-bpf.8.html|BPF programmable classifier and actions for ingress/egress
 +       queueing disciplines]]  
   *[[https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/linux-traffic-control_configuring-and-managing-networking#linux-traffic-control_configuring-and-managing-networking|Red Hat Documentation - Chapter 31. Linux traffic control]]   *[[https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/linux-traffic-control_configuring-and-managing-networking#linux-traffic-control_configuring-and-managing-networking|Red Hat Documentation - Chapter 31. Linux traffic control]]
 +  *ethtools
 +    *[[https://linuxvox.com/blog/linux-ethtool/|Unveiling the Power of Linux ethtool]]
 +    *[[https://www.baeldung.com/linux/using-ethtool|Using ethtool in Linux]]
 +    *[[https://linuxconcept.com/commands/ethtool|linux concept ethtool]]
 +    *[[https://sandilands.info/sgordon/segmentation-offloading-with-wireshark-and-ethtool|Segmentation and Checksum Offloading: Turning Off with ethtool]]
 +    *[[https://sokratisg.net/2012/04/01/udp-tcp-checksum-errors-from-tcpdump-nic-hardware-offloading/|UDP / TCP Checksum errors from tcpdump & NIC Hardware Offloading]]
 +    *[[https://docs.gz.ro/tuning-network-cards-on-linux.html| Linux Networking: How to disable/enable offload features, RX/TX checksum, scatter, gather and beyond]]
 +    *[[https://oneuptime.com/blog/post/2026-03-20-enable-gro-tso-linux-network/view| How to Enable Generic Receive Offload (GRO) and TCP Segmentation Offload (TSO)]]
  
 ---- ----
  
 <-  linux_router:dns_dhcp|Prev page ^ linux_router:start|Start page ^ linux_router:misc|Next page -> <-  linux_router:dns_dhcp|Prev page ^ linux_router:start|Start page ^ linux_router:misc|Next page ->