Hello,
I have a main router CCR1036 (ROS 6.49.18), with a 1Gbit line on sfpp1-gw WAN, local ip range 192.168.168.0/24. I have a second router CCR2004 for a separate part of the network, with it’s WAN on 192.168.168.113 and LAN on bridge1, using 192.168.71.0/24. It has simple queues on bridge1 for 100M/100M and works like a charm, all speedtests etc get something like 98/98M and the traffic is pretty normal. No Fasttrack on any of the routers.
Now, there is a guy in the network behind both routers with 192.168.71.55, downloading something from amazon. He is fullfilling the 100M limit on CCR2004, I can handle that, but my WAN sfpp1-gw is jumping to insane numbers - like ~700 Mbit Rx for sfpp1 and Tx for bridge, and I can see this on CCR2004’s WAN port too.
If I mangle the traffic for 192.168.168.113 on the main router and create a queue tree for it, the speed stays 700Mbit on WAN, but finally drops to 100M for 192.168.168.113, internet is bad for other computers on 192.168.71.0/24 and it seems the router is giving way more traffic to 192.168.71.55.
What is really weird - if I mangle the traffic for the amazon ip on the main router to 50M, to leave the remaining traffic for others, it finally works well, the queue is red and shows 50M, but I still see 700M Rx on my sfpp1-gw WAN - which is eating my traffic, and the ip can (and does) change, so it is not a solution to limit the public ip outside.
I know I can limit the local 192.168.71.55 ip on second router (although these change too nowadays), but - why the hell is this happening and how to get rid of this? If I had only 500M on WAN, it would totally kill my traffic.. is it some crap download service like aspera? Look at the pic - the amazon public ip is limited to 50M, total traffic on local interfaces is something below 200M (bridge2 is sfpp2+eth2) and sfpp1-gw WAN still jumps to 662 Mbit Rx and I can see it coming from the amazon ip.
So - to summarize it - I have a user with 192.168.71.55, downloading 50/50M, using a queue for his ip on router2(LAN 192.168.71.0/24). Using router 2’s WAN (192.168.168.113), the traffic passes to/from main router (LAN 192.168.168.0/24), I can see download 50M for 192.168.168.113, I can see queue limiting the amazon ip to 50M (red - working), but I see 662Mbit traffic from that ip to my main router’s WAN. Is the amazon server pushing the data hard itself to my wan, ignoring dropped packages by the queue and the speed of the downloading computer? How to get rid of that?
thanks

