Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #1205 > unrolled thread
| Started by | Al <bigal.nz@gmail.com> |
|---|---|
| First post | 2012-03-24 15:55 -0700 |
| Last post | 2012-04-09 18:19 -0400 |
| Articles | 20 on this page of 22 — 4 participants |
Back to article view | Back to comp.os.linux.networking
Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-03-24 15:55 -0700
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-03-24 15:57 -0700
Re: Is this a bridging scenario? Aragorn <stryder@telenet.be.invalid> - 2012-03-25 09:26 +0200
Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-25 10:56 +0200
Re: Is this a bridging scenario? Aragorn <stryder@telenet.be.invalid> - 2012-03-25 12:19 +0200
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-08 05:00 -0700
Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 14:20 +0200
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-08 06:10 -0700
Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 16:28 +0200
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-08 12:39 -0700
Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 22:32 +0200
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-09 08:28 -0700
Re: Is this a bridging scenario? Scott Hemphill <hemphill@hemphills.net> - 2012-04-09 12:41 -0400
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-09 11:52 -0700
Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-09 21:09 +0200
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 01:56 -0700
Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-10 20:30 +0200
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 16:30 -0700
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 19:23 -0700
Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 22:54 -0700
Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-11 09:33 +0200
Re: Is this a bridging scenario? Scott Hemphill <hemphill@hemphills.net> - 2012-04-09 18:19 -0400
Page 1 of 2 [1] 2 Next page →
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-03-24 15:55 -0700 |
| Subject | Is this a bridging scenario? |
| Message-ID | <b5b53ca6-9141-4105-b701-4b8935268f02@vy8g2000pbc.googlegroups.com> |
Hi All, I have the following: <IP CAM>-------WIRED------<<PC <LAN CARD>+<WIFI CARD> >> ------- / WIRELESS/ --------<ROUTER>---INET So in otherwords I have a IP Camera wired to a Linux PC which wirelessly connects to a ADSL modem/router, that is the wired inetfaces connects the camera to the PC, and the wireless interface connects the PC to the router. I want the Camera to be able to connect to the Internet via the modem router. Is this what is called a bridge? What would I need to do to allow the Camera to access the gateway and thus internet via eth0 and eth1 (the wired and wireless interface) in the PC which it is connected to?
[toc] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-03-24 15:57 -0700 |
| Message-ID | <98dc3a93-2599-4b1e-b032-f080ab36a53a@x10g2000pbi.googlegroups.com> |
| In reply to | #1205 |
PS: I still want the modem/router doing all the DHCP.
[toc] | [prev] | [next] | [standalone]
| From | Aragorn <stryder@telenet.be.invalid> |
|---|---|
| Date | 2012-03-25 09:26 +0200 |
| Message-ID | <jkmhbp$em6$1@dont-email.me> |
| In reply to | #1205 |
On Saturday 24 March 2012 23:55, Al conveyed the following to comp.os.linux.networking... > Hi All, > > I have the following: > > > <IP CAM>-------WIRED------<<PC <LAN CARD>+<WIFI CARD> >> ------- / > WIRELESS/ --------<ROUTER>---INET > > So in otherwords I have a IP Camera wired to a Linux PC which > wirelessly connects to a ADSL modem/router, that is the wired > inetfaces connects the camera to the PC, and the wireless interface > connects the PC to the router. > > I want the Camera to be able to connect to the Internet via the modem > router. > > Is this what is called a bridge? No, what you are describing is routing. Bridging is when you have a single NIC device acting like it is multiple virtual NICs, each with their own IP address and/or MAC address. > What would I need to do to allow the Camera to access the gateway and > thus internet via eth0 and eth1 (the wired and wireless interface) in > the PC which it is connected to? You need to set up the PC as the gateway for the camera. -- = Aragorn = (registered GNU/Linux user #223157)
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-03-25 10:56 +0200 |
| Message-ID | <jkmmjh$rkh$1@saria.nerim.net> |
| In reply to | #1208 |
Hello, Aragorn a écrit : > On Saturday 24 March 2012 23:55, Al conveyed the following to > comp.os.linux.networking... > >> <IP CAM>-------WIRED------<<PC <LAN CARD>+<WIFI CARD> >> ------- / >> WIRELESS/ --------<ROUTER>---INET >> >> So in otherwords I have a IP Camera wired to a Linux PC which >> wirelessly connects to a ADSL modem/router, that is the wired >> inetfaces connects the camera to the PC, and the wireless interface >> connects the PC to the router. >> >> I want the Camera to be able to connect to the Internet via the modem >> router. >> >> Is this what is called a bridge? > > No, what you are describing is routing. It could be bridging too. If the OP requires that the camera gets its IP configuration from the modem-router's DHCP server, then it will probably be bridging, because routing requires two separate subnets while bridging expands the LAN. Note that not all wireless NICs support bridging. See <http://www.linuxfoundation.org/collaborate/workgroups/networking/bridge#It_doesn.27t_work_with_my_Wireless_card.21> > Bridging is when you have a > single NIC device acting like it is multiple virtual NICs, each with > their own IP address and/or MAC address. Huh ? Bridging is when interfaces (not only NICs) are used as ports of a software switch. Usually bridged interfaces do not have an IP address on their own, it is transferred the bridge interface.
[toc] | [prev] | [next] | [standalone]
| From | Aragorn <stryder@telenet.be.invalid> |
|---|---|
| Date | 2012-03-25 12:19 +0200 |
| Message-ID | <jkmren$sec$1@dont-email.me> |
| In reply to | #1211 |
On Sunday 25 March 2012 10:56, Pascal Hambourg conveyed the following to comp.os.linux.networking... > Hello, > > Aragorn a écrit : >> On Saturday 24 March 2012 23:55, Al conveyed the following to >> comp.os.linux.networking... >> >>> <IP CAM>-------WIRED------<<PC <LAN CARD>+<WIFI CARD> >> ------- / >>> WIRELESS/ --------<ROUTER>---INET >>> >>> So in otherwords I have a IP Camera wired to a Linux PC which >>> wirelessly connects to a ADSL modem/router, that is the wired >>> inetfaces connects the camera to the PC, and the wireless interface >>> connects the PC to the router. >>> >>> I want the Camera to be able to connect to the Internet via the >>> modem router. >>> >>> Is this what is called a bridge? >> >> No, what you are describing is routing. > > It could be bridging too. Yes, I realized this after I had already sent off my reply. > If the OP requires that the camera gets its IP configuration from the > modem-router's DHCP server, then it will probably be bridging, because > routing requires two separate subnets while bridging expands the LAN. That is correct. > Note that not all wireless NICs support bridging. See > <http://www.linuxfoundation.org/collaborate/workgroups/networking/bridge#It_doesn.27t_work_with_my_Wireless_card.21> I didn't know about that, but then again I'm not very well-versed on wireless stuff. The only thing I myself use it for is for having my Android phone connect to the internet via my Linksys WRT54GL router, which supports both wired and wireless connections. My computers are all connected via CAT5e UTP cables. ;-) >> Bridging is when you have a single NIC device acting like it is >> multiple virtual NICs, each with their own IP address and/or MAC >> address. > > Huh ? Bridging is when interfaces (not only NICs) are used as ports of > a software switch. Yes, poor choice of words on my part - my apologies. By "NIC" I meant "something in which you plug a (physical or virtual) network cable". > Usually bridged interfaces do not have an IP address on their own, it > is transferred the bridge interface. That too is correct. My brain shortcircuited for a second with regard to the IP addresses. The idea of course is to have a _common_ IP address for the whole bridge, whereas with routing, you have two different subnets talking to eachother and thus two different IP ranges. -- = Aragorn = (registered GNU/Linux user #223157)
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-08 05:00 -0700 |
| Message-ID | <2f8acba3-b55f-42c3-b7ff-c7de7bf22649@qg3g2000pbc.googlegroups.com> |
| In reply to | #1208 |
On Mar 25, 8:26 pm, Aragorn <stry...@telenet.be.invalid> wrote: > On Saturday 24 March 2012 23:55, Al conveyed the following to > comp.os.linux.networking... > > > > > > > Hi All, > > > I have the following: > > > <IP CAM>-------WIRED------<<PC <LAN CARD>+<WIFI CARD> >> ------- / > > WIRELESS/ --------<ROUTER>---INET > > > So in otherwords I have a IP Camera wired to a Linux PC which > > wirelessly connects to a ADSL modem/router, that is the wired > > inetfaces connects the camera to the PC, and the wireless interface > > connects the PC to the router. > > > I want the Camera to be able to connect to the Internet via the modem > > router. > > > Is this what is called a bridge? > > No, what you are describing is routing. Bridging is when you have a > single NIC device acting like it is multiple virtual NICs, each with > their own IP address and/or MAC address. > > > What would I need to do to allow the Camera to access the gateway and > > thus internet via eth0 and eth1 (the wired and wireless interface) in > > the PC which it is connected to? > > You need to set up the PC as the gateway for the camera. > > -- > = Aragorn = > (registered GNU/Linux user #223157) Hi, Sorry for the belated reply. Ok I understand that it is routing, and I will need to set a static IP on the interfaces. Lets say on the PC we have wlan0 192.168.1.120 eth0 192.168.2.121 (I think eth0 needs to be a diff subnet right?) and on the camera which connects to eth0: cam1 192.168.2.122 I then need a routing "rule" ? and how would I port forward so I can access the camera directly from the inet? how would I port forward so I can access the linux box from the net? What would the rules look like? Sorry for all the questions, but some of these topics are new to me. Thanks -AL
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-08 14:20 +0200 |
| Message-ID | <jlrvq6$2muf$1@saria.nerim.net> |
| In reply to | #1234 |
Al a écrit : > > Sorry for the belated reply. Ok I understand that it is routing, and I > will need to set a static IP on the interfaces. As I wrote, it can be either routing or bridging. Let's go for routing. > Lets say on the PC we have > > wlan0 192.168.1.120 > eth0 192.168.2.121 (I think eth0 needs to be a diff subnet right?) Correct. > and on the camera which connects to eth0: > > cam1 192.168.2.122 Fine. > I then need a routing "rule" ? No. But in order for the camera to be able to connect to the internet, you need to set the Linux box (192.168.2.121) as the default gateway on the camera and set up the Linux box as an IP router (sysctl net.ipv4.ip_forward=1). Also you will need to either : - create a static route on the router to the camera subnet (192.168.2.0/24) with the Linux box (192.168.1.120) as the gateway. - or set up masquerading on the Linux box (iptables -t nat -A POSTROUTING -o wlan0 -j MASQUERADE). > and how would I port forward so I can access the camera directly from > the inet? If the router has a static route to the camera subnet, then it should be possible to create a port forwarding rule directly to the camera (192.168.2.122) on it. Otherwise you need to create a port forwarding rule to the Linux box (192.168.1.120) on the router and create a similar port forwarding rule to the camera on the Linux box : iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.120 -p tcp --dport 80 -j DNAT --to 192.168.2.122 (change with whatever port the camera is using) > how would I port forward so I can access the linux box from the net? See above. This is router-dependent.
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-08 06:10 -0700 |
| Message-ID | <e5b024d8-e2c6-4d7d-8969-70a983604ccd@x5g2000pbl.googlegroups.com> |
| In reply to | #1235 |
On Apr 9, 12:20 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org> wrote: > Al a écrit : > > > > > Sorry for the belated reply. Ok I understand that it is routing, and I > > will need to set a static IP on the interfaces. > > As I wrote, it can be either routing or bridging. Let's go for routing. > > > Lets say on the PC we have > > > wlan0 192.168.1.120 > > eth0 192.168.2.121 (I think eth0 needs to be a diff subnet right?) > > Correct. > > > and on the camera which connects to eth0: > > > cam1 192.168.2.122 > > Fine. > > > I then need a routing "rule" ? > > No. But in order for the camera to be able to connect to the internet, > you need to set the Linux box (192.168.2.121) as the default gateway on > the camera and set up the Linux box as an IP router (sysctl > net.ipv4.ip_forward=1). > Also you will need to either : > - create a static route on the router to the camera subnet > (192.168.2.0/24) with the Linux box (192.168.1.120) as the gateway. > - or set up masquerading on the Linux box (iptables -t nat -A > POSTROUTING -o wlan0 -j MASQUERADE). > > > and how would I port forward so I can access the camera directly from > > the inet? > > If the router has a static route to the camera subnet, then it should be > possible to create a port forwarding rule directly to the camera > (192.168.2.122) on it. > Otherwise you need to create a port forwarding rule to the Linux box > (192.168.1.120) on the router and create a similar port forwarding rule > to the camera on the Linux box : > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.120 -p tcp --dport > 80 -j DNAT --to 192.168.2.122 > (change with whatever port the camera is using) > > > how would I port forward so I can access the linux box from the net? > > See above. This is router-dependent. How does this look: http://i.imgur.com/1wqFf.jpg But do I still need to add something else for the camera to make outbound connections for SIP and email notifications etc? Cheers -Al
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-08 16:28 +0200 |
| Message-ID | <jls7ac$2pq5$1@saria.nerim.net> |
| In reply to | #1237 |
Al a écrit : > > How does this look: > > http://i.imgur.com/1wqFf.jpg The -o option cannot be used in a PREROUTING chain, because the output interface is not known yet : it is selected at the routing decision. Why do you need the rule in the FORWARD chain ? If you need it because packets are dropped by default, then you'll probably need extra rules to accept reply packets in the other direction and packets belonging to other types of communication (you mentionned SIP and mail below). "forward WAN port 12345 to LAN 12345" is not detailed enough. You must indicate to which address. > But do I still need to add something else for the camera to make > outbound connections for SIP and email notifications etc? SIP is a special protocol, a bit like FTP. If the Linux box does stateful filtering or masquerading, you may need to load the conntrack (for stateful filtering) or NAT (for masquerading) helper modules for that protocol, nf_conntrack_sip and nf_nat_ftp.
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-08 12:39 -0700 |
| Message-ID | <4989b111-42a3-4ff4-994c-814c858c7689@qg3g2000pbc.googlegroups.com> |
| In reply to | #1239 |
On Apr 9, 2:28 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org> wrote: > Al a écrit : > > > > > How does this look: > > >http://i.imgur.com/1wqFf.jpg > > The -o option cannot be used in a PREROUTING chain, because the output > interface is not known yet : it is selected at the routing decision. > > Why do you need the rule in the FORWARD chain ? > If you need it because packets are dropped by default, then you'll > probably need extra rules to accept reply packets in the other direction > and packets belonging to other types of communication (you mentionned > SIP and mail below). > > "forward WAN port 12345 to LAN 12345" is not detailed enough. > You must indicate to which address. > > > But do I still need to add something else for the camera to make > > outbound connections for SIP and email notifications etc? > > SIP is a special protocol, a bit like FTP. If the Linux box does > stateful filtering or masquerading, you may need to load the conntrack > (for stateful filtering) or NAT (for masquerading) helper modules for > that protocol, nf_conntrack_sip and nf_nat_ftp. So what do you think the rules should look like? Sorry I am not expert enough yet to try my hand at writing the rules. Cheers -AL
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-08 22:32 +0200 |
| Message-ID | <jlssko$39$1@saria.nerim.net> |
| In reply to | #1249 |
Al a écrit : > > So what do you think the rules should look like? For a start, only the ones I mentionned in my previous reply.
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-09 08:28 -0700 |
| Message-ID | <ae19d8e4-3a63-4590-bd08-67f643df1b8c@w6g2000pbp.googlegroups.com> |
| In reply to | #1250 |
On Apr 9, 8:32 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org> wrote: > Al a écrit : > > > > > So what do you think the rules should look like? > > For a start, only the ones I mentionned in my previous reply. Something is still screwy. I have eth0 on; auto lo iface lo inet loopback auto eth0 iface eth0 inet static address 192.168.70.121 netmask 255.0.0.0 network 192.168.70.0 broadcast 192.168.70.255 #gateway 192.168.2.254 #auto wlan0 #iface wlan0 inet static #address 192.168.1.120 #netmask 255.255.255.0 #network 192.168.1.0 #broadcast 192.168.1.255 #gateway 192.168.1.254 And the camera should have a static of 192.168.70.140 - but for some reason when I ssh into the linux box from the net via wlan0 I cant ping the camera. Any thoughts? Cheers -Al
[toc] | [prev] | [next] | [standalone]
| From | Scott Hemphill <hemphill@hemphills.net> |
|---|---|
| Date | 2012-04-09 12:41 -0400 |
| Message-ID | <m3lim4j1rz.fsf@hemphills.net> |
| In reply to | #1255 |
Al <bigal.nz@gmail.com> writes: > On Apr 9, 8:32 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org> > wrote: >> Al a écrit : >> >> >> >> > So what do you think the rules should look like? >> >> For a start, only the ones I mentionned in my previous reply. > > Something is still screwy. > > I have eth0 on; > > auto lo > iface lo inet loopback > > auto eth0 > iface eth0 inet static > address 192.168.70.121 > netmask 255.0.0.0 > network 192.168.70.0 > broadcast 192.168.70.255 > #gateway 192.168.2.254 > > #auto wlan0 > #iface wlan0 inet static > #address 192.168.1.120 > #netmask 255.255.255.0 > #network 192.168.1.0 > #broadcast 192.168.1.255 > #gateway 192.168.1.254 > > And the camera should have a static of 192.168.70.140 - but for some > reason when I ssh into the linux box from the net via wlan0 I cant > ping the camera. > > Any thoughts? Your netmask is wrong. It should be: netmask 255.255.255.0 Scott -- Scott Hemphill hemphill@alumni.caltech.edu "This isn't flying. This is falling, with style." -- Buzz Lightyear
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-09 11:52 -0700 |
| Message-ID | <41cda2ac-704c-407d-9716-fdd9ddba0011@s10g2000pbc.googlegroups.com> |
| In reply to | #1256 |
On Apr 10, 4:41 am, Scott Hemphill <hemph...@hemphills.net> wrote: > Al <bigal...@gmail.com> writes: > > On Apr 9, 8:32 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org> > > wrote: > >> Al a écrit : > > >> > So what do you think the rules should look like? > > >> For a start, only the ones I mentionned in my previous reply. > > > Something is still screwy. > > > I have eth0 on; > > > auto lo > > iface lo inet loopback > > > auto eth0 > > iface eth0 inet static > > address 192.168.70.121 > > netmask 255.0.0.0 > > network 192.168.70.0 > > broadcast 192.168.70.255 > > #gateway 192.168.2.254 > > > #auto wlan0 > > #iface wlan0 inet static > > #address 192.168.1.120 > > #netmask 255.255.255.0 > > #network 192.168.1.0 > > #broadcast 192.168.1.255 > > #gateway 192.168.1.254 > > > And the camera should have a static of 192.168.70.140 - but for some > > reason when I ssh into the linux box from the net via wlan0 I cant > > ping the camera. > > > Any thoughts? > > Your netmask is wrong. It should be: > > netmask 255.255.255.0 > > Scott > -- > Scott Hemphill hemph...@alumni.caltech.edu > "This isn't flying. This is falling, with style." -- Buzz Lightyear I made that mask rather liberal in attempt to get into the camera. 255.255.255.0 doesnt work either.
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-09 21:09 +0200 |
| Message-ID | <jlvc4f$u73$1@saria.nerim.net> |
| In reply to | #1257 |
Al a écrit : >>> auto eth0 >>> iface eth0 inet static >>> address 192.168.70.121 >>> netmask 255.0.0.0 >>> network 192.168.70.0 >>> broadcast 192.168.70.255 [...] >>> And the camera should have a static of 192.168.70.140 "Should" ? Does it actually ? How is it supposed to be configured ? Did you check it, e.g. with arping ? >> Your netmask is wrong. It should be: >> >> netmask 255.255.255.0 > > I made that mask rather liberal in attempt to get into the camera. 255.0.0.0 is much too liberal. The private range in that block is only 192.168.0.0/16 (mask 255.255.0.0). The rest of 192.0.0.0/8 is public or reserved space.
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-10 01:56 -0700 |
| Message-ID | <f2b02ff3-451d-4079-b537-8af9cd9c2dc0@w17g2000yqe.googlegroups.com> |
| In reply to | #1259 |
Ok, Not sure what was wrong, but finally, when I ssh into the linux box via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via eth0 (192.168.70.121) By default access to the camera is via port 80, so now its IP table time so I can access the camera from the inet (the router in use here doesnt support static routes, so I open port 5555 on the router and forward it to wlan0 (192.168.1.71) and need a similar rule in the linux box. From what you wrote above the rules should be: iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport 80 -j DNAT --to 192.168.70.140 Where 80 is the port the camera listens on. What I dont understand is how this rule still allows me to access the linux box, cause I have setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for ssh. The rule above appears that any inbound traffic to wlan0 gets forwarded to port 80 of the camera? Cheers -Al
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-10 20:30 +0200 |
| Message-ID | <jm1u90$1rkd$1@saria.nerim.net> |
| In reply to | #1265 |
Al a écrit : > > Not sure what was wrong, but finally, when I ssh into the linux box > via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via > eth0 (192.168.70.121) > > By default access to the camera is via port 80, so now its IP table > time so I can access the camera from the inet (the router in use here > doesnt support static routes, so I open port 5555 on the router and > forward it to wlan0 (192.168.1.71) and need a similar rule in the > linux box. From what you wrote above the rules should be: > > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport > 80 -j DNAT --to 192.168.70.140 > > Where 80 is the port the camera listens on. What I dont understand is > how this rule still allows me to access the linux box, cause I have > setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for > ssh. The rule above appears that any inbound traffic to wlan0 gets > forwarded to port 80 of the camera? With the rule above, TCP connections to 192.168.1.71 port 80 are redirected to 192.168.70.140 (same port). 1) SSH connections on port 22 are not affected. 2) If the router redirects port 5555 to 192.168.1.71 without changing the destination port, this is useless. The rule must redirect port 5555 to port 80 : iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport 5555 -j DNAT --to 192.168.70.140:80
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-10 16:30 -0700 |
| Message-ID | <35599c21-223f-4015-8ff4-45d256388bd6@a5g2000vbl.googlegroups.com> |
| In reply to | #1276 |
On Apr 11, 6:30 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org> wrote: > Al a écrit : > > > > > > > > > Not sure what was wrong, but finally, when I ssh into the linux box > > via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via > > eth0 (192.168.70.121) > > > By default access to the camera is via port 80, so now its IP table > > time so I can access the camera from the inet (the router in use here > > doesnt support static routes, so I open port 5555 on the router and > > forward it to wlan0 (192.168.1.71) and need a similar rule in the > > linux box. From what you wrote above the rules should be: > > > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport > > 80 -j DNAT --to 192.168.70.140 > > > Where 80 is the port the camera listens on. What I dont understand is > > how this rule still allows me to access the linux box, cause I have > > setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for > > ssh. The rule above appears that any inbound traffic to wlan0 gets > > forwarded to port 80 of the camera? > > With the rule above, TCP connections to 192.168.1.71 port 80 are > redirected to 192.168.70.140 (same port). > 1) SSH connections on port 22 are not affected. > 2) If the router redirects port 5555 to 192.168.1.71 without changing > the destination port, this is useless. The rule must redirect port 5555 > to port 80 : > > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport > 5555 -j DNAT --to 192.168.70.140:80 Ok, well its not working. Where do I start, how to see if traffic is even getting to port 80 of wlan0? Cheers -Al
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-10 19:23 -0700 |
| Message-ID | <e15911ac-4bda-478a-a2f1-158e78ff9882@js1g2000pbc.googlegroups.com> |
| In reply to | #1280 |
On Apr 11, 11:30 am, Al <bigal...@gmail.com> wrote: > On Apr 11, 6:30 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org> > wrote: > > > > > > > Al a écrit : > > > > Not sure what was wrong, but finally, when I ssh into the linux box > > > via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via > > > eth0 (192.168.70.121) > > > > By default access to the camera is via port 80, so now its IP table > > > time so I can access the camera from the inet (the router in use here > > > doesnt support static routes, so I open port 5555 on the router and > > > forward it to wlan0 (192.168.1.71) and need a similar rule in the > > > linux box. From what you wrote above the rules should be: > > > > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport > > > 80 -j DNAT --to 192.168.70.140 > > > > Where 80 is the port the camera listens on. What I dont understand is > > > how this rule still allows me to access the linux box, cause I have > > > setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for > > > ssh. The rule above appears that any inbound traffic to wlan0 gets > > > forwarded to port 80 of the camera? > > > With the rule above, TCP connections to 192.168.1.71 port 80 are > > redirected to 192.168.70.140 (same port). > > 1) SSH connections on port 22 are not affected. > > 2) If the router redirects port 5555 to 192.168.1.71 without changing > > the destination port, this is useless. The rule must redirect port 5555 > > to port 80 : > > > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport > > 5555 -j DNAT --to 192.168.70.140:80 > > Ok, well its not working. Where do I start, how to see if traffic is > even getting to port 80 of wlan0? > > Cheers > > -Al Someone suggested I might need to do something with conntracks?
[toc] | [prev] | [next] | [standalone]
| From | Al <bigal.nz@gmail.com> |
|---|---|
| Date | 2012-04-10 22:54 -0700 |
| Message-ID | <fc43a8f0-0e18-4e9c-b272-53174f4d4382@h10g2000pbi.googlegroups.com> |
| In reply to | #1276 |
Tcptrackoutput: Client Server State Idle Speed 118.92.xx.55:58674 192.168.1.71:80 RESET 1s 0 b/s 118.92.xx.55:58673 192.168.1.71:80 RESET 1s 0 b/s 118.92.xx.55:58676 192.168.1.71:80 RESET 1s 0 b/s SHows the connections hitting wlan0, but if I change to eth0 I see nothing. Something is wrong with the rule.
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | comp.os.linux.networking
csiph-web