tc(traffic control)는 iproute2 에 든 리눅스 커널 큐잉 제어 도구다. 인터페이스마다 qdisc(queueing discipline)를 달고, 그 아래 class 로 대역을 나누고, filter 로 패킷을 class 에 배정한다. 여기서는 HTB(Hierarchical Token Bucket) qdisc 로 특정 IP 의 업로드·다운로드 대역을 제한한다[1].
| HTB 파라미터 | 의미 |
|---|---|
rate |
이 class 와 그 자식들에게 보장하는 대역 |
ceil |
부모에 여유가 있을 때 빌려 쓸 수 있는 상한. 생략하면 rate 와 같다 |
burst |
ceil 속도로 한 번에 내보낼 수 있는 바이트 |
default N |
어느 필터에도 맞지 않는 트래픽을 보낼 class 번호 |
단위는 kbit · mbit(비트/초), kbps · mbps(바이트/초)로 구분한다. 회선 대역은 보통 비트 단위이므로 mbit 을 쓴다.
tc 는 송신(egress) 큐만 직접 제어한다. 아래 스크립트의 "다운로드 제한" 은 이 서버가 $IP 로 보내는 패킷을 제한하는 것이며, 서버가 게이트웨이 위치에 있을 때만 그 뒤 호스트의 다운로드 제한이 된다. 수신 방향을 제한하려면 ifb 장치로 ingress 를 되돌려야 한다.
iproute2 (tc 명령). 커널에 sch_htb 모듈 (현행 배포판 기본 포함)ip -br link)아래 스크립트를 tc.bash 로 저장하고 IF · DNLD · UPLD · IP 를 환경에 맞게 고친 뒤 실행한다.
#!/bin/bash
#
# tc uses the following units when passed as a parameter.
# kbps: Kilobytes per second
# mbps: Megabytes per second
# kbit: Kilobits per second
# mbit: Megabits per second
# bps: Bytes per second
# Amounts of data can be specified in:
# kb or k: Kilobytes
# mb or m: Megabytes
# mbit: Megabits
# kbit: Kilobits
# To get the byte figure from bits, divide the number by 8 bit
#
#
# Name of the traffic control command.
TC=/sbin/tc
# The network interface we're planning on limiting bandwidth.
IF=eth0 # QOS 설정할 인터페이스
# Download limit (in mega bits)
DNLD=1mbit # DOWNLOAD Limit
# Upload limit (in mega bits)
UPLD=1mbit # UPLOAD Limit
# IP address of the machine we are controlling
IP=216.3.128.12 # 대상 IP
# Filter options for limiting the intended interface.
U32="$TC filter add dev $IF protocol ip parent 1:0 prio 1 u32"
start() {
# We'll use Hierarchical Token Bucket (HTB) to shape bandwidth.
# For detailed configuration options, please consult Linux man
# page.
$TC qdisc add dev $IF root handle 1: htb default 30
$TC class add dev $IF parent 1: classid 1:1 htb rate $DNLD
$TC class add dev $IF parent 1: classid 1:2 htb rate $UPLD
$U32 match ip dst $IP/32 flowid 1:1
$U32 match ip src $IP/32 flowid 1:2
# The first line creates the root qdisc, and the next two lines
# create two child qdisc that are to be used to shape download
# and upload bandwidth.
#
# The 4th and 5th line creates the filter to match the interface.
# The 'dst' IP address is used to limit download speed, and the
# 'src' IP address is used to limit upload speed.
}
stop() {
# Stop the bandwidth shaping.
$TC qdisc del dev $IF root
}
restart() {
# Self-explanatory.
stop
sleep 1
start
}
show() {
# Display status of traffic control status.
$TC -s qdisc ls dev $IF
}
case "$1" in
start)
echo -n "Starting bandwidth shaping: "
start
echo "done"
;;
stop)
echo -n "Stopping bandwidth shaping: "
stop
echo "done"
;;
restart)
echo -n "Restarting bandwidth shaping: "
restart
echo "done"
;;
show)
echo "Bandwidth shaping status for $IF:"
show
echo ""
;;
*)
pwd=$(pwd)
echo "Usage: tc.bash {start|stop|restart|show}"
;;
esac
exit 0
chmod +x tc.bash
sudo ./tc.bash start
sudo ./tc.bash show
default 30 은 필터에 걸리지 않은 트래픽을 class 1:30 으로 보내라는 뜻인데 스크립트는 그 class 를 만들지 않는다. HTB 는 없는 class 를 가리키면 해당 트래픽을 제한 없이 루트 qdisc 로 바로 내보내므로, 대상 IP 외의 트래픽은 영향을 받지 않는다. 나머지 트래픽에도 상한을 두려면 1:30 class 를 만들어 준다.
# class 별 송신 바이트와 드롭
tc -s class show dev eth0
# 필터
tc filter show dev eth0
# 대상 호스트에서 iperf3 로 실제 대역 측정
iperf3 -c <이 서버 IP>
재부팅하면 설정이 사라진다. 유지하려면 스크립트를 systemd 유닛(ExecStart=/usr/local/sbin/tc.bash start, ExecStop=... stop)으로 등록한다.
tc-htb(8) — HTB rate · ceil · burst · default 의미 — 2026-09-20 확인. https://man7.org/linux/man-pages/man8/tc-htb.8.html ↩︎