Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #1236 > unrolled thread
| Started by | lincy <lincylin@gmail.com> |
|---|---|
| First post | 2012-04-08 05:50 -0700 |
| Last post | 2012-04-08 17:25 -0700 |
| Articles | 20 on this page of 22 — 3 participants |
Back to article view | Back to comp.os.linux.networking
linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-08 05:50 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-04-08 17:16 +0300
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-08 08:26 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-08 08:47 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 18:13 +0200
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-08 09:24 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 18:31 +0200
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-08 09:44 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 19:54 +0200
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-08 17:13 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-09 10:45 +0200
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-09 06:40 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-09 21:01 +0200
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-09 12:56 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-09 23:33 +0200
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-04-10 08:55 +0300
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-09 23:40 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-04-10 14:39 +0300
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-10 08:22 -0700
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Tauno Voipio <tauno.voipio@notused.fi.invalid> - 2012-04-08 21:13 +0300
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 20:48 +0200
Re: linux as multi-port (subnet) router using Ubuntu 11.10 server lincy <lincylin@gmail.com> - 2012-04-08 17:25 -0700
Page 1 of 2 [1] 2 Next page →
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-08 05:50 -0700 |
| Subject | linux as multi-port (subnet) router using Ubuntu 11.10 server |
| Message-ID | <11134348.13.1333889415598.JavaMail.geo-discussion-forums@pbnu1> |
Hi everyone. I have an fast-growing network. Around 120-130 pcs in single class c localnet (192.168.1.0/24). Because service lot large file share (multi-nas for multi-media). Now I am try to split it by department. So, I am using an 4 ports giga lan machine and install ubuntu 11.10 server. Because I just want to split the network but not to do any security in this machine. So, I just setup 4 subnet and enable the ip forward. eth0: 192.168.1.1 netmask 255.255.255.0 eth1: 192.168.2.1 netmask 255.255.255.0 eth2: 192.168.3.1 netmask 255.255.255.0 eth3: 192.168.4.1 netmask 255.255.255.0 And echo 1 > /proc/sys/net/ipv4/ip_forward in /etc/rc.local Now, My problem was. I can't ping cross subnet, ex: ping 192.168.2.x from 192.168.1.x But I can open web page cross subnet. ex: open 192.168.1.x intranet web server from 192.168.2.x or 192.168.3.x I also can't access the windows/share-folder either samba share cross subnet. But same subnet can access. ex: 192.168.1.x's pc can access NAS within 192.168.1.x but not NAS in 192.168.2.x. Does anyone know what's wrong ?
[toc] | [next] | [standalone]
| From | Tauno Voipio <tauno.voipio@notused.fi.invalid> |
|---|---|
| Date | 2012-04-08 17:16 +0300 |
| Message-ID | <jls6jb$50l$1@dont-email.me> |
| In reply to | #1236 |
On 8.4.12 3:50 , lincy wrote:
> Hi everyone.
>
> I have an fast-growing network. Around 120-130 pcs in single class c localnet (192.168.1.0/24). Because service lot large file share (multi-nas for multi-media).
>
> Now I am try to split it by department. So, I am using an 4 ports giga lan machine and install ubuntu 11.10 server. Because I just want to split the network but not to do any security in this machine. So, I just setup 4 subnet and enable the ip forward.
>
> eth0: 192.168.1.1 netmask 255.255.255.0
> eth1: 192.168.2.1 netmask 255.255.255.0
> eth2: 192.168.3.1 netmask 255.255.255.0
> eth3: 192.168.4.1 netmask 255.255.255.0
>
> And echo 1> /proc/sys/net/ipv4/ip_forward in /etc/rc.local
>
> Now, My problem was.
>
> I can't ping cross subnet, ex: ping 192.168.2.x from 192.168.1.x
> But I can open web page cross subnet. ex: open 192.168.1.x intranet web server from 192.168.2.x or 192.168.3.x
> I also can't access the windows/share-folder either samba share cross subnet.
> But same subnet can access. ex: 192.168.1.x's pc can access NAS within 192.168.1.x but not NAS in 192.168.2.x.
>
> Does anyone know what's wrong ?
How is the default gateway in the client machines set?
My guess is:
a) The clients in subnets do not know that the route to another
subnet goes via the Linux machine,
b) There is a HTTP proxy in the Linux machine forwarding the
Web requests.
Another question: Is the way out from the subnets to the big
Internet via the Linux machine, or something else?
If this is a basic network tree, you should have in each machine
the default gateway pointing to the next step toward the Net.
You have now changed the next step from what it was.
--
Tauno Voipio
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-08 08:26 -0700 |
| Message-ID | <13863831.877.1333898763111.JavaMail.geo-discussion-forums@pbjk8> |
| In reply to | #1238 |
Tauno Voipio於 2012年4月8日星期日UTC+8下午10時16分11秒寫道: > On 8.4.12 3:50 , lincy wrote: > > Hi everyone. > > > > I have an fast-growing network. Around 120-130 pcs in single class c localnet (192.168.1.0/24). Because service lot large file share (multi-nas for multi-media). > > > > Now I am try to split it by department. So, I am using an 4 ports giga lan machine and install ubuntu 11.10 server. Because I just want to split the network but not to do any security in this machine. So, I just setup 4 subnet and enable the ip forward. > > > > eth0: 192.168.1.1 netmask 255.255.255.0 > > eth1: 192.168.2.1 netmask 255.255.255.0 > > eth2: 192.168.3.1 netmask 255.255.255.0 > > eth3: 192.168.4.1 netmask 255.255.255.0 > > > > And echo 1> /proc/sys/net/ipv4/ip_forward in /etc/rc.local > > > > Now, My problem was. > > > > I can't ping cross subnet, ex: ping 192.168.2.x from 192.168.1.x > > But I can open web page cross subnet. ex: open 192.168.1.x intranet web server from 192.168.2.x or 192.168.3.x > > I also can't access the windows/share-folder either samba share cross subnet. > > But same subnet can access. ex: 192.168.1.x's pc can access NAS within 192.168.1.x but not NAS in 192.168.2.x. > > > > Does anyone know what's wrong ? > > > How is the default gateway in the client machines set? > > My guess is: > > a) The clients in subnets do not know that the route to another > subnet goes via the Linux machine, I have using dnsmasq too, so each subnet's client can get correctly ip and default gw to this machine. ex: 192.168.1.x > Another question: Is the way out from the subnets to the big > Internet via the Linux machine, or something else? > > If this is a basic network tree, you should have in each machine > the default gateway pointing to the next step toward the Net. > You have now changed the next step from what it was. > > -- > > Tauno Voipio Tauno Voipio於 2012年4月8日星期日UTC+8下午10時16分11秒寫道: > On 8.4.12 3:50 , lincy wrote: > > Hi everyone. > > > > I have an fast-growing network. Around 120-130 pcs in single class c localnet (192.168.1.0/24). Because service lot large file share (multi-nas for multi-media). > > > > Now I am try to split it by department. So, I am using an 4 ports giga lan machine and install ubuntu 11.10 server. Because I just want to split the network but not to do any security in this machine. So, I just setup 4 subnet and enable the ip forward. > > > > eth0: 192.168.1.1 netmask 255.255.255.0 > > eth1: 192.168.2.1 netmask 255.255.255.0 > > eth2: 192.168.3.1 netmask 255.255.255.0 > > eth3: 192.168.4.1 netmask 255.255.255.0 > > > > And echo 1> /proc/sys/net/ipv4/ip_forward in /etc/rc.local > > > > Now, My problem was. > > > > I can't ping cross subnet, ex: ping 192.168.2.x from 192.168.1.x > > But I can open web page cross subnet. ex: open 192.168.1.x intranet web server from 192.168.2.x or 192.168.3.x > > I also can't access the windows/share-folder either samba share cross subnet. > > But same subnet can access. ex: 192.168.1.x's pc can access NAS within 192.168.1.x but not NAS in 192.168.2.x. > > > > Does anyone know what's wrong ? > > > How is the default gateway in the client machines set? > > My guess is: > > a) The clients in subnets do not know that the route to another > subnet goes via the Linux machine, > > b) There is a HTTP proxy in the Linux machine forwarding the > Web requests. > > Another question: Is the way out from the subnets to the big > Internet via the Linux machine, or something else? > > If this is a basic network tree, you should have in each machine > the default gateway pointing to the next step toward the Net. > You have now changed the next step from what it was. > > -- > > Tauno Voipio Tauno Voipio於 2012年4月8日星期日UTC+8下午10時16分11秒寫道: > On 8.4.12 3:50 , lincy wrote: > > Hi everyone. > > > > I have an fast-growing network. Around 120-130 pcs in single class c localnet (192.168.1.0/24). Because service lot large file share (multi-nas for multi-media). > > > > Now I am try to split it by department. So, I am using an 4 ports giga lan machine and install ubuntu 11.10 server. Because I just want to split the network but not to do any security in this machine. So, I just setup 4 subnet and enable the ip forward. > > > > eth0: 192.168.1.1 netmask 255.255.255.0 > > eth1: 192.168.2.1 netmask 255.255.255.0 > > eth2: 192.168.3.1 netmask 255.255.255.0 > > eth3: 192.168.4.1 netmask 255.255.255.0 > > > > And echo 1> /proc/sys/net/ipv4/ip_forward in /etc/rc.local > > > > Now, My problem was. > > > > I can't ping cross subnet, ex: ping 192.168.2.x from 192.168.1.x > > But I can open web page cross subnet. ex: open 192.168.1.x intranet web server from 192.168.2.x or 192.168.3.x > > I also can't access the windows/share-folder either samba share cross subnet. > > But same subnet can access. ex: 192.168.1.x's pc can access NAS within 192.168.1.x but not NAS in 192.168.2.x. > > > > Does anyone know what's wrong ? > > > How is the default gateway in the client machines set? > > My guess is: > > a) The clients in subnets do not know that the route to another > subnet goes via the Linux machine, > > b) There is a HTTP proxy in the Linux machine forwarding the > Web requests. > > Another question: Is the way out from the subnets to the big > Internet via the Linux machine, or something else? > > If this is a basic network tree, you should have in each machine > the default gateway pointing to the next step toward the Net. > You have now changed the next step from what it was. > > -- > > Tauno Voipio Tauno Voipio於 2012年4月8日星期日UTC+8下午10時16分11秒寫道: > On 8.4.12 3:50 , lincy wrote: > > Hi everyone. > > > > I have an fast-growing network. Around 120-130 pcs in single class c localnet (192.168.1.0/24). Because service lot large file share (multi-nas for multi-media). > > > > Now I am try to split it by department. So, I am using an 4 ports giga lan machine and install ubuntu 11.10 server. Because I just want to split the network but not to do any security in this machine. So, I just setup 4 subnet and enable the ip forward. > > > > eth0: 192.168.1.1 netmask 255.255.255.0 > > eth1: 192.168.2.1 netmask 255.255.255.0 > > eth2: 192.168.3.1 netmask 255.255.255.0 > > eth3: 192.168.4.1 netmask 255.255.255.0 > > > > And echo 1> /proc/sys/net/ipv4/ip_forward in /etc/rc.local > > > > Now, My problem was. > > > > I can't ping cross subnet, ex: ping 192.168.2.x from 192.168.1.x > > But I can open web page cross subnet. ex: open 192.168.1.x intranet web server from 192.168.2.x or 192.168.3.x > > I also can't access the windows/share-folder either samba share cross subnet. > > But same subnet can access. ex: 192.168.1.x's pc can access NAS within 192.168.1.x but not NAS in 192.168.2.x. > > > > Does anyone know what's wrong ? > > > How is the default gateway in the client machines set? > > My guess is: > > a) The clients in subnets do not know that the route to another > subnet goes via the Linux machine, > Thanks your reply. First, I have 192.168.1.x subnet. so. Have one firewall in front of Internet. It's 192.168.1.254, So, every machine in 192.168.1.x was default gw point to 192.168.1.254 At the new 4 ports machine. I set the default gw to 192.168.1.254 Then add static route, 192.168.2.x/192.168.3.x/192.168.4.x point to 192.168.1.1 This machine no any rule. Just forward enable. > Another question: Is the way out from the subnets to the big > Internet via the Linux machine, or something else? as above. I think, If I don't set any filter rule. This machine should pass any package. But look like it don't. I don't know why http port can work. But not other ports.
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-08 08:47 -0700 |
| Message-ID | <20292715.691.1333900061222.JavaMail.geo-discussion-forums@pbsy3> |
| In reply to | #1240 |
> Thanks your reply. > First, I have 192.168.1.x subnet. so. Have one firewall in front of Internet. It's 192.168.1.254, So, every machine in 192.168.1.x was default gw point to 192.168.1.254 > > At the new 4 ports machine. I set the default gw to 192.168.1.254 > Then add static route, 192.168.2.x/192.168.3.x/192.168.4.x point to 192.168.1.1 > This machine no any rule. Just forward enable. Sorry, the static route to 192.168.1.1 was setting in firewall machine.
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-08 18:13 +0200 |
| Message-ID | <jlsdeu$2s1d$1@saria.nerim.net> |
| In reply to | #1241 |
Hello, lincy a écrit : >> First, I have 192.168.1.x subnet. so. Have one firewall in front of >> Internet. It's 192.168.1.254, So, every machine in 192.168.1.x was >> default gw point to 192.168.1.254 >> >> At the new 4 ports machine. I set the default gw to 192.168.1.254 >> Then add static route, 192.168.2.x/192.168.3.x/192.168.4.x point to 192.168.1.1 >> This machine no any rule. Just forward enable. > > Sorry, the static route to 192.168.1.1 was setting in firewall machine. So subnet 192.168.1.x is special : packets from a host in this subnet to another subnet has to go through the firewall first and then (hopefully) be forwarded to the Linux router. Let's save it for later. What about communications between subnets other that 192.168.1.x ? Note : packet capture, e.g. with tcpdump, on the Linux router may help.
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-08 09:24 -0700 |
| Message-ID | <18422322.213.1333902286409.JavaMail.geo-discussion-forums@pbag4> |
| In reply to | #1242 |
Pascal Hambourg於 2012年4月9日星期一UTC+8上午12時13分17秒寫道: > Hello, > > lincy a écrit : > >> First, I have 192.168.1.x subnet. so. Have one firewall in front of > >> Internet. It's 192.168.1.254, So, every machine in 192.168.1.x was > >> default gw point to 192.168.1.254 > >> > >> At the new 4 ports machine. I set the default gw to 192.168.1.254 > >> Then add static route, 192.168.2.x/192.168.3.x/192.168.4.x point to 192.168.1.1 > >> This machine no any rule. Just forward enable. > > > > Sorry, the static route to 192.168.1.1 was setting in firewall machine. > > So subnet 192.168.1.x is special : packets from a host in this subnet to > another subnet has to go through the firewall first and then > (hopefully) be forwarded to the Linux router. > > Let's save it for later. What about communications between subnets other > that 192.168.1.x ? > > Note : packet capture, e.g. with tcpdump, on the Linux router may help. 192.168.2.x/192.168.3.x/192.168.4.x can't ping each other. ex: 192.168.2.x can't ping 192.168.3.x but 192.168.2.a can ping 192.168.2.b, 192.168.3.a can ping 192.168.3.b For web access. 192.168.2.x can access 192.168.3.x web (ex: NAS's web-UI) For SMB/Windows access. 192.168.2.x can't access 192.168.3.x share (ex:NAS's windows share) But SMB access with same subnet was ok.
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-08 18:31 +0200 |
| Message-ID | <jlsehl$2sf8$1@saria.nerim.net> |
| In reply to | #1243 |
lincy a écrit : > > 192.168.2.x/192.168.3.x/192.168.4.x can't ping each other. > ex: 192.168.2.x can't ping 192.168.3.x > but 192.168.2.a can ping 192.168.2.b, 192.168.3.a can ping 192.168.3.b Did you check that /proc/sys/net/ipv4/ip_forward is actually set to 1 ? What is the output of "route -n" or "ip route" on the Linux router and on a host in each subnet ? What is the exact result (output) of the ping commands ? What is the output of iptables-save on the Linux router ?
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-08 09:44 -0700 |
| Message-ID | <26518308.9.1333903498341.JavaMail.geo-discussion-forums@pbtd9> |
| In reply to | #1244 |
Pascal Hambourg於 2012年4月9日星期一UTC+8上午12時31分47秒寫道: > lincy a écrit : > > > > 192.168.2.x/192.168.3.x/192.168.4.x can't ping each other. > > ex: 192.168.2.x can't ping 192.168.3.x > > but 192.168.2.a can ping 192.168.2.b, 192.168.3.a can ping 192.168.3.b > > Did you check that /proc/sys/net/ipv4/ip_forward is actually set to 1 ? > What is the output of "route -n" or "ip route" on the Linux router and > on a host in each subnet ? > What is the exact result (output) of the ping commands ? > What is the output of iptables-save on the Linux router ? 1. yes, It's 1 2. 4 ports router. Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 0.0.0.0 192.168.1.254 0.0.0.0 UG 100 0 0 eth0 192.168.2.0 * 255.255.255.0 U 0 0 0 eth1 192.168.3.0 * 255.255.255.0 U 0 0 0 eth2 192.168.4.0 * 255.255.255.0 U 0 0 0 eth3 192.168.1.0 * 255.255.255.0 U 0 0 0 eth0 client machine. (windows) IP address : 192.168.2.181 netmask : 255.255.255.0 gateway : 192.168.2.1 DHCP server : 192.168.2.1 DNS Server : 192.168.2.1 WINS Server : 192.168.1.1 NetBIOS over tcpip : yes 3. ping 192.168.3.51 Timeout... Timeout... .... 4. # Generated by iptables-save v1.4.10 on Mon Apr 9 00:41:02 2012 *filter :INPUT ACCEPT [686:74793] :FORWARD ACCEPT [129:25283] :OUTPUT ACCEPT [607:68740] COMMIT # Completed on Mon Apr 9 00:41:02 2012 # Generated by iptables-save v1.4.10 on Mon Apr 9 00:41:02 2012 *nat :PREROUTING ACCEPT [55:5548] :INPUT ACCEPT [41:4300] :OUTPUT ACCEPT [73:7833] :POSTROUTING ACCEPT [86:8975] COMMIT # Completed on Mon Apr 9 00:41:02 2012 # Generated by iptables-save v1.4.10 on Mon Apr 9 00:41:02 2012 *mangle :PREROUTING ACCEPT [816:100182] :INPUT ACCEPT [686:74793] :FORWARD ACCEPT [129:25283] :OUTPUT ACCEPT [607:68740] :POSTROUTING ACCEPT [1002:127527] COMMIT # Completed on Mon Apr 9 00:41:02 2012
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-08 19:54 +0200 |
| Message-ID | <jlsjd0$2u7i$1@saria.nerim.net> |
| In reply to | #1245 |
lincy a écrit : >> Did you check that /proc/sys/net/ipv4/ip_forward is actually set to 1 ? >> What is the output of "route -n" or "ip route" on the Linux router and >> on a host in each subnet ? >> What is the exact result (output) of the ping commands ? >> What is the output of iptables-save on the Linux router ? > > 1. yes, It's 1 > > 2. 4 ports router. > Kernel IP routing table > Destination Gateway Genmask Flags Metric Ref Use Iface > 0.0.0.0 192.168.1.254 0.0.0.0 UG 100 0 0 eth0 > 192.168.2.0 * 255.255.255.0 U 0 0 0 eth1 > 192.168.3.0 * 255.255.255.0 U 0 0 0 eth2 > 192.168.4.0 * 255.255.255.0 U 0 0 0 eth3 > 192.168.1.0 * 255.255.255.0 U 0 0 0 eth0 > > client machine. (windows) > IP address : 192.168.2.181 > netmask : 255.255.255.0 > gateway : 192.168.2.1 What about the host on the other subnet, 192.168.3.51 ? > 3. > ping 192.168.3.51 > Timeout... > Timeout... I would run tcpdump on the router to see what is going on...
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-08 17:13 -0700 |
| Message-ID | <13689836.1943.1333930427032.JavaMail.geo-discussion-forums@pbvs10> |
| In reply to | #1246 |
Pascal Hambourg於 2012年4月9日星期一UTC+8上午1時54分39秒寫道: > lincy a écrit : > >> Did you check that /proc/sys/net/ipv4/ip_forward is actually set to 1 ? > >> What is the output of "route -n" or "ip route" on the Linux router and > >> on a host in each subnet ? > >> What is the exact result (output) of the ping commands ? > >> What is the output of iptables-save on the Linux router ? > > > > 1. yes, It's 1 > > > > 2. 4 ports router. > > Kernel IP routing table > > Destination Gateway Genmask Flags Metric Ref Use Iface > > 0.0.0.0 192.168.1.254 0.0.0.0 UG 100 0 0 eth0 > > 192.168.2.0 * 255.255.255.0 U 0 0 0 eth1 > > 192.168.3.0 * 255.255.255.0 U 0 0 0 eth2 > > 192.168.4.0 * 255.255.255.0 U 0 0 0 eth3 > > 192.168.1.0 * 255.255.255.0 U 0 0 0 eth0 > > > > client machine. (windows) > > IP address : 192.168.2.181 > > netmask : 255.255.255.0 > > gateway : 192.168.2.1 > > What about the host on the other subnet, 192.168.3.51 ? IP address : 192.168.3.51 netmask : 255.255.255.0 gateway : 192.168.3.1 > > > 3. > > ping 192.168.3.51 > > Timeout... > > Timeout... > > I would run tcpdump on the router to see what is going on... I have using tcpdump to listen eth1 (192.168.2.0) and eth2 (192.168.3.0), I have saw the 192.168.3.51 have echo icmp request. But this package only reach 192.168.3.1, not going to 192.168.2.1, so, 192.168.2.181 report time out.
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-09 10:45 +0200 |
| Message-ID | <jlu7ip$g2l$1@saria.nerim.net> |
| In reply to | #1251 |
lincy a écrit : > > I have using tcpdump to listen eth1 (192.168.2.0) and eth2 (192.168.3.0), > I have saw the 192.168.3.51 have echo icmp request. But this package > only reach 192.168.3.1, not going to 192.168.2.1, so, 192.168.2.181 > report time out. Can you be more precise, or better, provide the output of tcpdump on both interfaces ?
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-09 06:40 -0700 |
| Message-ID | <23753461.82.1333978858232.JavaMail.geo-discussion-forums@pbvy6> |
| In reply to | #1253 |
Pascal Hambourg於 2012年4月9日星期一UTC+8下午4時45分12秒寫道: > lincy a écrit : > > > > I have using tcpdump to listen eth1 (192.168.2.0) and eth2 (192.168.3.0), > > I have saw the 192.168.3.51 have echo icmp request. But this package > > only reach 192.168.3.1, not going to 192.168.2.1, so, 192.168.2.181 > > report time out. > > Can you be more precise, or better, provide the output of tcpdump on > both interfaces ? Sorry, I was wrong. I was issue some iptable rule. To try and error. Then saw this result. But after clear all rule. It's little difference Here is the tcpdump with no any iptable rule. dump for eth1 (192.168.2.0) 21:00:36.593857 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56228, length 40 21:00:36.681668 IP 192.168.2.181.138 > 192.168.2.255.138: UDP, length 213 21:00:41.594273 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56229, length 40 21:00:46.592657 ARP, Request who-has 192.168.2.1 (00:60:e0:4e:f9:e1) tell 192.168.2.181, length 46 21:00:46.592676 ARP, Reply 192.168.2.1 is-at 00:60:e0:4e:f9:e1, length 28 21:00:46.593667 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56230, length 40 21:00:47.417978 IP 192.168.2.181.60120 > 192.168.1.11.161: UDP, length 78 21:00:51.593160 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56231, length 40 21:00:56.593645 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56232, length 40 21:00:58.391788 IP 192.168.2.181.60120 > 192.168.1.11.161: UDP, length 78 21:01:01.593176 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56233, length 40 21:01:06.593578 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56234, length 40 21:01:08.392724 IP 192.168.2.181.60120 > 192.168.1.11.161: UDP, length 78 21:01:11.594091 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56235, length 40 21:01:13.093096 ARP, Request who-has 192.168.2.1 (00:60:e0:4e:f9:e1) tell 192.168.2.181, length 46 21:01:13.093112 ARP, Reply 192.168.2.1 is-at 00:60:e0:4e:f9:e1, length 28 21:01:16.593682 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56236, length 40 21:01:19.315536 ARP, Request who-has 192.168.2.1 tell 192.168.2.181, length 46 21:01:19.315552 ARP, Reply 192.168.2.1 is-at 00:60:e0:4e:f9:e1, length 28 21:01:19.596954 IP 192.168.2.181.50952 > 239.255.255.250.1900: UDP, length 133 21:01:21.594124 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56237, length 40 21:01:22.597326 IP 192.168.2.181.50952 > 239.255.255.250.1900: UDP, length 133 dump for eth2: 21:00:36.457244 ARP, Request who-has 192.168.3.51 tell 192.168.51.1, length 28 21:00:36.457510 ARP, Reply 192.168.3.51 is-at 70:5a:b6:40:02:d5, length 46 21:00:36.593887 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56228, length 40 21:00:41.594300 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56229, length 40 21:00:46.593692 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56230, length 40 21:00:51.593187 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56231, length 40 21:00:56.593677 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56232, length 40 21:01:01.593200 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56233, length 40 21:01:06.593605 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56234, length 40 21:01:11.594113 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56235, length 40 21:01:16.593717 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56236, length 40 21:01:21.594152 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56237, length 40 Ok, here is what I try... iptables -t nat -A POSTROUTING -s 192.168.2.0/24 -d 192.168.3.0/24 -j SNAT --to 192.168.3.1 iptables -t nat -A POSTROUTING -s 192.168.3.0/24 -d 192.168.2.0/24 -j SNAT --to 192.168.2.1 now can ping from 192.168.2.x to 192.168.3.x, vice versa. The strange thing is 192.168.3.x to 192.168.2.x SMB function ok, but 192.168.2.x to 192.168.3.x was not..... Still trying ....
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-09 21:01 +0200 |
| Message-ID | <jlvbm4$u16$1@saria.nerim.net> |
| In reply to | #1254 |
lincy a écrit : > Sorry, I was wrong. I was issue some iptable rule. It cannot possibly be an issue with some iptables rule, as iptables-save showed no rule at all. > dump for eth2: > 21:00:36.457244 ARP, Request who-has 192.168.3.51 tell 192.168.51.1, length 28 Huh ? "tell 192.168.51.1" ? What is the address configured on eth2 ? > 21:00:36.457510 ARP, Reply 192.168.3.51 is-at 70:5a:b6:40:02:d5, length 46 > 21:00:36.593887 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56228, length 40 [...] So the echo request is forwarded, but no reply ever comes back. I can see only two explanations : - host 192.168.3.51 default route is misconfigured or missing - or it has a firewall which drops requests from other subnets. > Ok, here is what I try... > > iptables -t nat -A POSTROUTING -s 192.168.2.0/24 -d 192.168.3.0/24 -j SNAT --to 192.168.3.1 > iptables -t nat -A POSTROUTING -s 192.168.3.0/24 -d 192.168.2.0/24 -j SNAT --to 192.168.2.1 Ah, SNAT aka masquerading. It is called "masquerading" because it masquerades the source address, but I like to say that it is actually used to masquerade the real - routing of filtering - problem. > now can ping from 192.168.2.x to 192.168.3.x, vice versa.
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-09 12:56 -0700 |
| Message-ID | <16433470.0.1334001361795.JavaMail.geo-discussion-forums@pbcio9> |
| In reply to | #1258 |
Pascal Hambourg於 2012年4月10日星期二UTC+8上午3時01分22秒寫道: > lincy a écrit : > > Sorry, I was wrong. I was issue some iptable rule. > > It cannot possibly be an issue with some iptables rule, as iptables-save > showed no rule at all. > I meaning I am try&error to type iptable rule from command line to test it. I don't save the rule or edit the script file. I am reboot machine and capture fresh package with no any rule. > > dump for eth2: > > 21:00:36.457244 ARP, Request who-has 192.168.3.51 tell 192.168.51.1, length 28 > > Huh ? "tell 192.168.51.1" ? What is the address configured on eth2 ? > It's typing error. sorry. should be 192.168.3.1 > > 21:00:36.457510 ARP, Reply 192.168.3.51 is-at 70:5a:b6:40:02:d5, length 46 > > 21:00:36.593887 IP 192.168.2.181 > 192.168.3.51: ICMP echo request, id 3, seq 56228, length 40 > [...] > So the echo request is forwarded, but no reply ever comes back. > I can see only two explanations : > - host 192.168.3.51 default route is misconfigured or missing > - or it has a firewall which drops requests from other subnets. > The default route of 192.168.3.51 was 192.168.3.1 I am guess the kernel drop something too. But I don't know why. Because the iptable rule are empty. > > Ok, here is what I try... > > > > iptables -t nat -A POSTROUTING -s 192.168.2.0/24 -d 192.168.3.0/24 -j SNAT --to 192.168.3.1 > > iptables -t nat -A POSTROUTING -s 192.168.3.0/24 -d 192.168.2.0/24 -j SNAT --to 192.168.2.1 > > Ah, SNAT aka masquerading. It is called "masquerading" because it > masquerades the source address, but I like to say that it is actually > used to masquerade the real - routing of filtering - problem. > yes, I just try to see masq work or not. But the service won't work. Just can ping. Weird.... This 4ports linux box was hard to setup more then internet firewall box. >_< Firewall rule to reject all then accept what you want was easy understand. This machine no any rule, all chain was accept. I can't understand where to drop/reject/block package. so this box don't work as I expected. > > now can ping from 192.168.2.x to 192.168.3.x, vice versa.
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> |
|---|---|
| Date | 2012-04-09 23:33 +0200 |
| Message-ID | <jlvkk1$1182$1@saria.nerim.net> |
| In reply to | #1260 |
lincy a écrit : > Pascal Hambourg wrote : >> It cannot possibly be an issue with some iptables rule, as iptables-save >> showed no rule at all. > > I meaning I am try&error to type iptable rule from command line to test it. You should not need any iptables rules if everything else is setup correctly. >> So the echo request is forwarded, but no reply ever comes back. >> I can see only two explanations : >> - host 192.168.3.51 default route is misconfigured or missing >> - or it has a firewall which drops requests from other subnets. > > The default route of 192.168.3.51 was 192.168.3.1 Looks good. > I am guess the kernel drop something too. But I don't know why. > Because the iptable rule are empty. It cannot be iptables nor the IP stack. Incoming packets are captured by tcpdump before iptables and the IP stack can see them. The only part of the kernel which could drop the packets before tcpdump can see them is the ethernet driver. > This 4ports linux box was hard to setup more then internet firewall > box. >_< There is nothing difficult to setup : just IP settings on each interface and enable IP forwarding. > Firewall rule to reject all then accept what you want was easy understand. You do not need any filtering rules. Just leave everything open. > This machine no any rule, all chain was accept. I can't understand > where to drop/reject/block package. so this box don't work as I expected. My guess is the problem lies in the firewall or IP setup on the hosts, not on the router box.
[toc] | [prev] | [next] | [standalone]
| From | Tauno Voipio <tauno.voipio@notused.fi.invalid> |
|---|---|
| Date | 2012-04-10 08:55 +0300 |
| Message-ID | <jm0hvq$a3f$1@dont-email.me> |
| In reply to | #1261 |
On 10.4.12 12:33 , Pascal Hambourg wrote: > lincy a écrit : >> Pascal Hambourg wrote : >>> It cannot possibly be an issue with some iptables rule, as iptables-save >>> showed no rule at all. >> >> I meaning I am try&error to type iptable rule from command line to test it. > > You should not need any iptables rules if everything else is setup > correctly. > >>> So the echo request is forwarded, but no reply ever comes back. >>> I can see only two explanations : >>> - host 192.168.3.51 default route is misconfigured or missing >>> - or it has a firewall which drops requests from other subnets. >> >> The default route of 192.168.3.51 was 192.168.3.1 > > Looks good. > >> I am guess the kernel drop something too. But I don't know why. >> Because the iptable rule are empty. > > It cannot be iptables nor the IP stack. Incoming packets are captured by > tcpdump before iptables and the IP stack can see them. The only part of > the kernel which could drop the packets before tcpdump can see them is > the ethernet driver. > >> This 4ports linux box was hard to setup more then internet firewall >> box.>_< > > There is nothing difficult to setup : just IP settings on each interface > and enable IP forwarding. > >> Firewall rule to reject all then accept what you want was easy understand. > > You do not need any filtering rules. Just leave everything open. > >> This machine no any rule, all chain was accept. I can't understand >> where to drop/reject/block package. so this box don't work as I expected. > > My guess is the problem lies in the firewall or IP setup on the hosts, > not on the router box. There is a strong smell of Windows 'firewalling' off networks that are not own. Is there such a 'security feature' in Windows that it will respond to pings from local network only? Which version/flavour or Windows? -- Tauno Voipio
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-09 23:40 -0700 |
| Message-ID | <21041448.21.1334040002494.JavaMail.geo-discussion-forums@pbso10> |
| In reply to | #1263 |
Tauno Voipio於 2012年4月10日星期二UTC+8下午1時55分06秒寫道: > On 10.4.12 12:33 , Pascal Hambourg wrote: > > lincy a écrit : > >> Pascal Hambourg wrote : > >>> It cannot possibly be an issue with some iptables rule, as iptables-save > >>> showed no rule at all. > >> > >> I meaning I am try&error to type iptable rule from command line to test it. > > > > You should not need any iptables rules if everything else is setup > > correctly. > > > >>> So the echo request is forwarded, but no reply ever comes back. > >>> I can see only two explanations : > >>> - host 192.168.3.51 default route is misconfigured or missing > >>> - or it has a firewall which drops requests from other subnets. > >> > >> The default route of 192.168.3.51 was 192.168.3.1 > > > > Looks good. > > > >> I am guess the kernel drop something too. But I don't know why. > >> Because the iptable rule are empty. > > > > It cannot be iptables nor the IP stack. Incoming packets are captured by > > tcpdump before iptables and the IP stack can see them. The only part of > > the kernel which could drop the packets before tcpdump can see them is > > the ethernet driver. > > > >> This 4ports linux box was hard to setup more then internet firewall > >> box.>_< > > > > There is nothing difficult to setup : just IP settings on each interface > > and enable IP forwarding. > > > >> Firewall rule to reject all then accept what you want was easy understand. > > > > You do not need any filtering rules. Just leave everything open. > > > >> This machine no any rule, all chain was accept. I can't understand > >> where to drop/reject/block package. so this box don't work as I expected. > > > > My guess is the problem lies in the firewall or IP setup on the hosts, > > not on the router box. > > There is a strong smell of Windows 'firewalling' off networks > that are not own. Is there such a 'security feature' in Windows > that it will respond to pings from local network only? > > Which version/flavour or Windows? > Windows 7
[toc] | [prev] | [next] | [standalone]
| From | Tauno Voipio <tauno.voipio@notused.fi.invalid> |
|---|---|
| Date | 2012-04-10 14:39 +0300 |
| Message-ID | <jm164r$e1k$1@dont-email.me> |
| In reply to | #1264 |
On 10.4.12 9:40 , lincy wrote: > Tauno Voipio於 2012年4月10日星期二UTC+8下午1時55分06秒寫道: >> On 10.4.12 12:33 , Pascal Hambourg wrote: >>> lincy a écrit : >>>> Pascal Hambourg wrote : >>>>> It cannot possibly be an issue with some iptables rule, as iptables-save >>>>> showed no rule at all. >>>> >>>> I meaning I am try&error to type iptable rule from command line to test it. >>> >>> You should not need any iptables rules if everything else is setup >>> correctly. >>> >>>>> So the echo request is forwarded, but no reply ever comes back. >>>>> I can see only two explanations : >>>>> - host 192.168.3.51 default route is misconfigured or missing >>>>> - or it has a firewall which drops requests from other subnets. >>>> >>>> The default route of 192.168.3.51 was 192.168.3.1 >>> >>> Looks good. >>> >>>> I am guess the kernel drop something too. But I don't know why. >>>> Because the iptable rule are empty. >>> >>> It cannot be iptables nor the IP stack. Incoming packets are captured by >>> tcpdump before iptables and the IP stack can see them. The only part of >>> the kernel which could drop the packets before tcpdump can see them is >>> the ethernet driver. >>> >>>> This 4ports linux box was hard to setup more then internet firewall >>>> box.>_< >>> >>> There is nothing difficult to setup : just IP settings on each interface >>> and enable IP forwarding. >>> >>>> Firewall rule to reject all then accept what you want was easy understand. >>> >>> You do not need any filtering rules. Just leave everything open. >>> >>>> This machine no any rule, all chain was accept. I can't understand >>>> where to drop/reject/block package. so this box don't work as I expected. >>> >>> My guess is the problem lies in the firewall or IP setup on the hosts, >>> not on the router box. >> >> There is a strong smell of Windows 'firewalling' off networks >> that are not own. Is there such a 'security feature' in Windows >> that it will respond to pings from local network only? >> >> Which version/flavour or Windows? >> > > Windows 7 I refuse to touch anything newer than XP. Someone else? -- Tauno Voipio
[toc] | [prev] | [next] | [standalone]
| From | lincy <lincylin@gmail.com> |
|---|---|
| Date | 2012-04-10 08:22 -0700 |
| Message-ID | <14408064.764.1334071324460.JavaMail.geo-discussion-forums@pbcio9> |
| In reply to | #1267 |
> >> There is a strong smell of Windows 'firewalling' off networks > >> that are not own. Is there such a 'security feature' in Windows > >> that it will respond to pings from local network only? > >> > >> Which version/flavour or Windows? > > Windows 7 > I refuse to touch anything newer than XP. Someone else? ha ... My office have xp/windows7/mac machine and windows 2003 server... so, I still have to solve those problem. Anyway. I have using Ubuntu Desktop live CD to boot 2 linux machine in 192.168.2.x and 192.168.3.x. It's really weird.... With no any rule in 4ports box. Linux client machine in 192.168.2.130 can ping 192.168.3.51 (both get ip by dhcp). but... some time will get this message 192.168.3.130: From 192.168.3.1 icmp_seq=xxxx Destination Host Unreachable... 64 byes from 192.168.2.130: icmp_req=xxxx ttl=63 time=xxxms (from 0.5 to 500ms) I don't know why...... I will try to get more machine to test.
[toc] | [prev] | [next] | [standalone]
| From | Tauno Voipio <tauno.voipio@notused.fi.invalid> |
|---|---|
| Date | 2012-04-08 21:13 +0300 |
| Message-ID | <jlskg4$heh$1@dont-email.me> |
| In reply to | #1245 |
On 8.4.12 7:44 , lincy wrote: > Pascal Hambourg於 2012年4月9日星期一UTC+8上午12時31分47秒寫道: >> lincy a écrit : >>> >>> 192.168.2.x/192.168.3.x/192.168.4.x can't ping each other. >>> ex: 192.168.2.x can't ping 192.168.3.x >>> but 192.168.2.a can ping 192.168.2.b, 192.168.3.a can ping 192.168.3.b >> >> Did you check that /proc/sys/net/ipv4/ip_forward is actually set to 1 ? >> What is the output of "route -n" or "ip route" on the Linux router and >> on a host in each subnet ? >> What is the exact result (output) of the ping commands ? >> What is the output of iptables-save on the Linux router ? > > 1. yes, It's 1 > > 2. 4 ports router. > Kernel IP routing table > Destination Gateway Genmask Flags Metric Ref Use Iface > 0.0.0.0 192.168.1.254 0.0.0.0 UG 100 0 0 eth0 > 192.168.2.0 * 255.255.255.0 U 0 0 0 eth1 > 192.168.3.0 * 255.255.255.0 U 0 0 0 eth2 > 192.168.4.0 * 255.255.255.0 U 0 0 0 eth3 > 192.168.1.0 * 255.255.255.0 U 0 0 0 eth0 > > client machine. (windows) > IP address : 192.168.2.181 > netmask : 255.255.255.0 > gateway : 192.168.2.1 > DHCP server : 192.168.2.1 > DNS Server : 192.168.2.1 > WINS Server : 192.168.1.1 > NetBIOS over tcpip : yes > > 3. > ping 192.168.3.51 > Timeout... > Timeout... > .... > > > > 4. > # Generated by iptables-save v1.4.10 on Mon Apr 9 00:41:02 2012 > *filter > :INPUT ACCEPT [686:74793] > :FORWARD ACCEPT [129:25283] > :OUTPUT ACCEPT [607:68740] > COMMIT > # Completed on Mon Apr 9 00:41:02 2012 > # Generated by iptables-save v1.4.10 on Mon Apr 9 00:41:02 2012 > *nat > :PREROUTING ACCEPT [55:5548] > :INPUT ACCEPT [41:4300] > :OUTPUT ACCEPT [73:7833] > :POSTROUTING ACCEPT [86:8975] > COMMIT > # Completed on Mon Apr 9 00:41:02 2012 > # Generated by iptables-save v1.4.10 on Mon Apr 9 00:41:02 2012 > *mangle > :PREROUTING ACCEPT [816:100182] > :INPUT ACCEPT [686:74793] > :FORWARD ACCEPT [129:25283] > :OUTPUT ACCEPT [607:68740] > :POSTROUTING ACCEPT [1002:127527] > COMMIT > # Completed on Mon Apr 9 00:41:02 2012 > Point 2. There is a DHCP server mentioned. Do you run DHCP in the network? If you do, the proper location for the server is the Linux machine. In other cases, you'll need a DHCP relay in the Linux machine. The setup means that machines in 192.168.2.x network must have 192.168.2.1 as the default gateway, and similarly for networks 192.168.3.x and 192.168.4.x. The gateway must always be in the same local network as the client. For clients in the 192.168.1.x network it is different: the default gateway must be 192.168.1.254. IIRC, the WINS name server should be also in the local network. Point 3. Weird - if there is not a 'security' module in Windows blocking the show. Can you test with a Linux laptop in the subnet? As Pascal said, tcpdump or - still better - Wireshark is your friend here. Point 4. A better listing is available from iptables: iptables -n -v -L -- Tauno Voipio PS. Thanks, Pascal.
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | comp.os.linux.networking
csiph-web