looking to hire some traffic management help

I’m looking for some paid help from a MT user EXPERIENCED and SKILLED in sophisticated traffic management in ISP ethernet environments. (I will post again stating so when the need is fulfilled)

I’d like an email jp@saucer.midcoast.com summarizing your experience with this task and what’d you’d charge to:

  1. clarify any questions you’d have about this setup described below:
  2. ssh in to the existing running MT router, backup the config to a local file, and setup the rules that nicely satisfy the setup requirements.
  3. let me test it to make sure it works as expected and doesn’t break anything.
  4. perform any final minor tuning if needed.

I’m not incapable of this myself, I just don’t have to time to experiment and would like to hire a setup which I can reuse/tweek/modify on my own.
Paypal would be the easiest way for us to pay, but visa/MC is fine too if you have an established business.

setup:
We are an ISP using lots of Alvarion radios. The traffic shaping features in the Alvarion radios are handy but not sophisticated enough for what we want to do for optimizing performance, so we wish to install a MT box at each pop to manage IP traffic. We don’t have an IP range for each AU/AP, but rather an IP range per site or town. A customer can get one of various AU/AP associations depending on which one has a better signal in their sector.

MT multi-ethernet box acting as a bridge or router, ethernet link goes to
Alvarion AU or AP.

  • We wish to limit the connection to the AU/AP to a particular speed - perhaps 1.5mbps, though it may need fine tuning, so as not to overload the air capactity and cause performance problems. Perhaps 1mbps down and 500kbps up would also work.

  • We wish to limit all p2p traffic to a certain rate - lets say 30kbps up and 200kbps down aggregate for all users of the AU/AP.

  • We wish to make sure VOIP traffic stays prioritized and reserve some bandwidth for that. I’m guessing 300kbps would be the most voip traffic for an AU/AP at a given moment, but usually it would be quite low. SIP is the signalling but the calls actually go over UDP RTP traffic on various ports. I think the ATAs generally prioritise the packets using diffserv and I think the Alvarions support the same. Alvarion supports 802.1p and ToS according to rfc791. Should we mark and reserve bandwidth for this in MT? Aside from the 802.1p and ToS from the Alvarions, I can also provide destination IP addresses for the gateways which the ATA connects to if there is no way to mark the UDP traffic except by IP if necessary.

  • rate limit SMTP port 25 connections to those that aren’t in an IP range we specify. Perhaps 40kbps.

  • block ports 135,137,445, etc.. I already know how to do this.

  • traffic which is not low priority (p2p,nonlocal smtp) and not high priority
    (voip) should get whatever bandwidth remains available for that AU/AP.

  • be able to set a MIR for individual customer IP numbers as needed. We’ll be using this with wired ethernet systems and trango systems as well, which support much higher data rates and we need MIRs to sell tiers of service based on speed, or to adjust MIRs to preserve overall bandwidth in the event of customer computers being exploited or other such abuse.

Would a seperate MT box be required for each AU/AP or is there a way to a queue for each AU/AP and subqueues for each of the services. Maybe a second queue for customers I wish to mark and limit. I’m really experienced with IP and radios and linux, but sort of a novice with IP traffic management system design. I’ve only done real simple stuff, like limit a certain type of traffic of limit a certain IP address. If this works, I will of course be copying the config for other sites in our network that need the same extra traffic control features.

Thanks,
Jason Philbrook
Midcoast Internet Solutions
http://www.midcoast.com/

When we got training from Butch Evans it covered a lot of this material and I’m “certified”, but I don’t have time to engineer everything and test it before deploying it.

I would gladly split the costs with you if you find someone to do this.

You could try to contact Butch through butche (at) wisp-training.com if that email still works…

If all else fails we could hash through it one day…

Oh, we could also ask around on the Mikrotik Part-15 email list.