Traffic Control & Bandwidth Shaping
Hardware queue discipline (HTB) and isolated VLESS proxy pool limits
Applies only to VLESS clients. Per-user caps are enforced by nftables rate rules β download in dl_shape (prerouting), aggregate upload in ul_shape (output, both routes) β with tc HTB classes on enp0s31f6 / wg-surfshark-* as burst smoothers beneath them.
WireGuard Easy (wg0), SSH, Caddy, Web UIs, and host services get unconstrained 1000 Mbps line-rate speed.
Total bandwidth envelope shared across all active VLESS proxy accounts.
Bandwidth allocated to non-VLESS host traffic, wg-easy VPN, and SSH management.
Hard caps live in nftables (dl_shape download / ul_shape aggregate upload); these tc classes smooth bursts via queueing. enp0s31f6 = Route A (direct) uploads, wg-surfshark-* = Route B (tunneled) uploads.
| Class ID | Interface | Committed Rate | Ceiling | Bytes Transferred | Packets | Dropped Packets | Overlimits |
|---|---|---|---|---|---|---|---|
| Loading kernel traffic control classes⦠| |||||||