Shape an Internet Link Safely with tc-cake
You will finish with CAKE, the Linux queueing discipline in tc, shaping an interface at a chosen rate and reporting its live statistics. The examples use iproute2 6.1.0-1ubuntu6.4, installed on this machine.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes for a first test. You need the iproute2 package, the interface name, and a bandwidth figure that is slightly below the real bottleneck rate. Reading and inspecting commands are ordinary user operations. Changing a root qdisc needs elevated privileges and can briefly affect traffic.
1. Check the installed command
Confirm the binary and package version before copying a configuration from somewhere else. These commands do not change networking:
$ command -v tc
/usr/sbin/tc
$ tc -V
tc utility, iproute2-6.1.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4
The local tc-cake(8) page describes CAKE as a shaping-capable queue discipline combining active queue management, flow isolation and optional Diffserv tins. All settings are optional, but a useful Internet configuration normally supplies bandwidth.
2. Identify the interface and current qdisc
Replace IFACE with the interface that carries the traffic you want to shape. Do not assume that the first Ethernet-looking name is the WAN interface, especially on a host with bridges, containers or multiple uplinks:
$ ip -br link
$ IFACE='eth0'
$ tc -s qdisc show dev "$IFACE"
Record the output before changing anything. It is your recovery reference. The output may show several qdiscs; the line marked root is the one CAKE will replace in the example below.
Checkpoint
Stop here if IFACE is not the device connected to the bottleneck. A CAKE instance on the wrong interface can appear healthy while doing nothing useful.
3. Choose the rate and link correction
CAKE's bandwidth value sets its shaper. Use a measured rate below the service's sustainable bottleneck, rather than the headline package speed. For a variable cellular link, the manpage also provides autorate-ingress; it estimates capacity from traffic arriving at the qdisc and cannot estimate a link downstream of itself.
Overhead matters because Linux's packet size may not equal the number of bytes metered on the wire. The manpage supplies technology keywords. ethernet accounts for Ethernet framing and is equivalent to overhead 38 mpu 84 noatm. For an ADSL PPPoE connection, the appropriate keyword may instead be pppoe-llcsnap or pppoe-vcmux. For VDSL2 PPPoE, use pppoe-ptm if that matches the provider's framing.
Do not select an overhead keyword by habit. Check the modem or provider settings first. If you do not know the link technology, begin with a verified rate and the default raw accounting, then measure and refine it. The default RTT tuning is internet, equivalent to 100 ms, which is the sensible starting point for ordinary Internet traffic. Do not use lan for an Internet access link.
4. Apply a first CAKE configuration
Warning
This replaces the interface's root qdisc and changes live packet scheduling. Run it during a short test window, preferably with local access available. Save the previous output from step 2 first.
This example shapes egress on an Ethernet bottleneck at 100 Mbit/s. The shell variable is only a convenience; inspect it before running the privileged command:
$ printf 'interface: %s\n' "$IFACE"
interface: eth0
$ sudo tc qdisc replace dev "$IFACE" root cake bandwidth 100Mbit ethernet
The command uses CAKE's documented defaults for Diffserv, flow isolation, RTT and GSO splitting. The explicit ethernet keyword adds the link correction. CAKE's default shaper is unlimited, so omitting bandwidth would not shape the link.
For a downstream Internet link on a router, the qdisc must be attached where the router can control the packets before they leave towards the LAN. Inbound shaping often requires an IFB or another topology-specific arrangement, which is outside this simple root-qdisc example. The ingress option changes CAKE's direction setting; it does not by itself move the qdisc to a different interface.
5. Verify the active settings
Ask tc for statistics immediately after applying the change:
$ sudo tc -s qdisc show dev "$IFACE"
qdisc cake 1: root refcnt 2 bandwidth 100Mbit diffserv3 triple-isolate rtt 100.0ms noatm overhead 38 mpu 84
Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
memory used: 0b of 5000000b
capacity estimate: 100Mbit
Your counters and handle can differ. The useful checks are that the root line says cake, the bandwidth is the value you selected, and the output includes the expected overhead and RTT. The manpage's sample also reports per-tin counters for Bulk, Best Effort and Voice in the default diffserv3 preset.
Generate ordinary traffic, then repeat the same command. overlimits indicates shaper events, while dropped, backlog and the per-tin delay fields describe what the queue has experienced. Zero counters immediately after configuration are normal; they do not prove that the chosen rate or interface is correct.
6. Adjust only one assumption at a time
If the measured link still queues elsewhere, lower the CAKE rate slightly and test again. If throughput is consistently below expectation despite a good rate, investigate the real framing and add the matching overhead keyword. For example, this changes only the rate while retaining Ethernet correction:
$ sudo tc qdisc replace dev "$IFACE" root cake bandwidth 95Mbit ethernet
$ sudo tc -s qdisc show dev "$IFACE"
For mostly local traffic, choose the RTT preset that matches the path: metro is 10 ms and regional is 30 ms. The manpage warns that lan, equivalent to 1 ms, can signal congestion prematurely on ordinary Linux systems. Change RTT only when the traffic pattern justifies it.
Leave diffserv3 and triple-isolate in place unless you have a reason to classify traffic differently. besteffort removes priority tins. dual-srchost is intended to share an egress link fairly between source hosts, while dual-dsthost suits an ingress path; triple-isolate is the general default. These choices affect fairness, not the physical capacity of the link.
7. Remove the test configuration
If the test causes a problem, remove the root qdisc using the documented deletion form:
$ sudo tc qdisc delete root dev "$IFACE"
$ sudo tc -s qdisc show dev "$IFACE"
This is a live change. The kernel will return to the interface's normal default behaviour, but it will not restore an arbitrary qdisc that was present before CAKE. If step 2 showed a deliberate prior configuration, restore that configuration using its own documented command instead. A reboot or network-manager restart is not a substitute for understanding the original setup.
Done means
- You confirmed the installed iproute2 and
tcversions. - You identified the bottleneck interface and recorded its original root qdisc.
- You selected a sustainable rate and verified the link overhead model.
tc -s qdisc showreports CAKE with the intended rate and settings.- You tested under real traffic and interpreted counters as measurements, not proof by themselves.
- You know how to delete CAKE or restore the previous deliberate qdisc configuration.