Home / Alt manpages / tc-red(8)

  • tc-red(8)
  • Admin command
  • linux

Tune a Linux RED Queue with tc red

You will configure a Random Early Detection (RED) queuing discipline with tc, inspect the resulting thresholds and counters, and remove the test qdisc without guessing what it changed. RED starts marking or dropping packets before a queue reaches its hard limit, which can reduce the burst of synchronised TCP retransmissions caused by a simple tail drop.

Before you start

This guide matches the installed tc-red(8) documentation from iproute2 6.1.0 and the tc binary on the test system. Option availability and output can differ with another iproute2 release, so check the local help on the machine you are changing.

Allow about 10 minutes for a read-only inspection and a little longer for a controlled test. You need:

  • root privileges, or CAP_NET_ADMIN, for qdisc changes;
  • the interface name and a maintenance window if it carries production traffic;
  • an existing classful parent if you use the parent-based example below.

Checkpoint: the following commands only inspect the system and do not change traffic handling.

tc -V
tc qdisc add red help
tc qdisc show dev <INTERFACE>
tc class show dev <INTERFACE>

Replace <INTERFACE> with a real device such as enp0s31f6. The help command is deliberately written as an add request with help; tc prints the RED grammar and does not create a qdisc. In iproute2 6.1.0 the advertised form is limit BYTES [min BYTES] [max BYTES] avpkt BYTES, followed by optional burst, adaptive, probability, bandwidth, ECN and qevent settings.

Understand the four queue values

RED uses an exponentially weighted moving average, not just the instantaneous queue length. The average remains below min during short bursts more readily when the configuration has a suitable burst value. Once the average passes min, the probability of action rises linearly until the average reaches max. The actual queue may still grow, so limit is the hard byte ceiling.

The manpage defaults are easy to overlook:

  • min defaults to one third of max;
  • max defaults to one quarter of limit and should be at least twice min;
  • probability defaults to 0.02, meaning a maximum 2% early-mark or early-drop probability;
  • avpkt is a packet-size estimate in bytes and is used with burst to calculate the average's time constant;
  • bandwidth helps calculate the average after idle time. It does not shape the interface.

For a first test, make all four queue-related values explicit. The values below are the example from the local manpage: a 400,000-byte hard limit, thresholds at 30,000 and 90,000 bytes, and a 1,000-byte average packet estimate.

Choose how RED handles congestion

Without ecn, RED deals with an eligible packet by dropping it when its probability says to act. With ecn, an ECN-capable packet is marked instead, up to the hard limit. Non-ECN traffic can still be early-dropped. This is usually the less disruptive choice when the hosts and the rest of the path support ECN, but it is not a guarantee that every packet will be marked.

harddrop forces a drop when the average is above max, even in ECN mode. nodrop keeps traffic that would otherwise be marked but is not ECN-capable. That can let the queue grow, so do not add it casually. adaptive makes the probability dynamic, aiming for an average queue around half-way between min and max; the local manpage records it as available from Linux 3.3.

Checkpoint: decide whether you want ECN, and record the current qdisc output before changing anything. If the interface already has a root qdisc, do not replace it just to try RED.

Attach RED below an existing class

This is the safer operational shape because it leaves the root qdisc and other classes in place. The parent must already exist. The read-only tc class show command above should show the class you intend to use, such as 1:1.

Warning

The next command changes packet queuing and requires elevation. Use a test interface or a known maintenance window. Substitute the interface and parent only after checking them.

sudo tc qdisc add dev <INTERFACE> parent 1:1 handle 10: red \
    limit 400000 min 30000 max 90000 avpkt 1000 \
    burst 55 ecn adaptive bandwidth 10Mbit

The handle 10: identifies this qdisc. It is not a bandwidth setting. burst 55 controls how quickly the real queue influences the moving average; it is not a packet limit. The bandwidth value is used for idle-time calculations and must describe the relevant interface rate.

Verify the attachment and collect statistics:

sudo tc qdisc show dev <INTERFACE>
sudo tc -s qdisc show dev <INTERFACE>

Expected output includes a RED qdisc beneath the chosen parent, with the configured handle and options. The statistics form adds packet and byte counters. Counters may be zero on an idle interface; that is not evidence that the qdisc failed to attach.

Test without replacing the root qdisc

Generate or observe traffic that actually traverses the class containing RED, then run the statistics command again. Do not flood a production link merely to make counters move. RED is a queue management policy, not a traffic generator or a shaper, so it cannot create congestion for you and it cannot enforce 10Mbit on the interface.

When ECN is enabled, early action may appear as marks rather than drops for ECN-capable traffic. Non-ECN packets can be dropped before the hard limit. At the hard limit, packets are dropped regardless of whether ECN is enabled. If counters do not change, first check the parent, direction of traffic and whether the class is receiving packets.

Remove the test qdisc

Removal is another elevated, service-affecting operation. Confirm that handle 10: is the RED qdisc you added, then delete that exact qdisc:

sudo tc qdisc show dev <INTERFACE>
sudo tc qdisc del dev <INTERFACE> parent 1:1 handle 10:
tc qdisc show dev <INTERFACE>

After deletion, the parent returns to its normal child or default behaviour. Do not use a guessed tc qdisc replace ... root command as an undo step: the previous root qdisc, handle and parameters are system-specific. If you changed a root qdisc instead, restore the exact configuration recorded before the change.

Common mistakes

  • No such file or directory, or an invalid parent: the parent class does not exist on that interface. Inspect tc class show and use its exact class ID.
  • RED never marks: the moving average may never have crossed min, or traffic may not pass through the selected class. Check counters and thresholds before changing probability.
  • Too many drops during a burst: review burst, avpkt, min and max together. Raising limit alone changes the hard ceiling, not the average calculation.
  • ECN is not visible: only ECN-capable packets are marked. Non-ECN packets can be early-dropped unless nodrop is set.
  • Traffic rate did not change: that is expected. RED manages queue pressure; it does not shape bandwidth.

Done means

  • tc qdisc add red help confirms the local option grammar.
  • The parent class and existing qdisc were recorded before the change.
  • The RED qdisc is visible with tc qdisc show and its counters were checked with -s.
  • ECN, hard-drop behaviour, thresholds and bandwidth assumptions are documented for this interface.
  • The exact test qdisc can be removed with its known parent and handle.