⚑ VLESS-Isolated WAN Shaping Architecture
Hardware Isolated
VLESS Proxy Pool (Class 1:1) Fwmark Marked

Applies only to VLESS clients. Per-user caps are enforced by nftables rate rules β€” download in dl_shape (prerouting), aggregate upload in ul_shape (output, both routes) β€” with tc HTB classes on enp0s31f6 / wg-surfshark-* as burst smoothers beneath them.

Server & wg0 Bypass (Class 1:9999) Full 1 Gbps Bypass

WireGuard Easy (wg0), SSH, Caddy, Web UIs, and host services get unconstrained 1000 Mbps line-rate speed.

Proxy Pool Limits (Class 1:1) VLESS Aggregate

Total bandwidth envelope shared across all active VLESS proxy accounts.

Committed download rate for proxy
Max burstable download limit
Committed upload rate (WG tunnels + WAN)
Max burstable upload limit (WG tunnels + WAN)
System & wg0 Bypass (Class 1:9999) Host Direct

Bandwidth allocated to non-VLESS host traffic, wg-easy VPN, and SSH management.

Default 1000 Mbps line rate
Default 1000 Mbps full link
Live TC Classes (per-user HTB smoothers) 0 active classes
Auto-refreshes every 10s

Hard caps live in nftables (dl_shape download / ul_shape aggregate upload); these tc classes smooth bursts via queueing. enp0s31f6 = Route A (direct) uploads, wg-surfshark-* = Route B (tunneled) uploads.

Class ID Interface Committed Rate Ceiling Bytes Transferred Packets Dropped Packets Overlimits
Loading kernel traffic control classes…