Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1205 > unrolled thread

Is this a bridging scenario?

Started byAl <bigal.nz@gmail.com>
First post2012-03-24 15:55 -0700
Last post2012-04-09 18:19 -0400
Articles 20 on this page of 22 — 4 participants

Back to article view | Back to comp.os.linux.networking


Contents

  Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-03-24 15:55 -0700
    Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-03-24 15:57 -0700
    Re: Is this a bridging scenario? Aragorn <stryder@telenet.be.invalid> - 2012-03-25 09:26 +0200
      Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-03-25 10:56 +0200
        Re: Is this a bridging scenario? Aragorn <stryder@telenet.be.invalid> - 2012-03-25 12:19 +0200
      Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-08 05:00 -0700
        Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 14:20 +0200
          Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-08 06:10 -0700
            Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 16:28 +0200
              Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-08 12:39 -0700
                Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-08 22:32 +0200
                  Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-09 08:28 -0700
                    Re: Is this a bridging scenario? Scott Hemphill <hemphill@hemphills.net> - 2012-04-09 12:41 -0400
                      Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-09 11:52 -0700
                        Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-09 21:09 +0200
                          Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 01:56 -0700
                            Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-10 20:30 +0200
                              Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 16:30 -0700
                                Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 19:23 -0700
                              Re: Is this a bridging scenario? Al <bigal.nz@gmail.com> - 2012-04-10 22:54 -0700
                                Re: Is this a bridging scenario? Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2012-04-11 09:33 +0200
                        Re: Is this a bridging scenario? Scott Hemphill <hemphill@hemphills.net> - 2012-04-09 18:19 -0400

Page 1 of 2  [1] 2  Next page →


#1205 — Is this a bridging scenario?

FromAl <bigal.nz@gmail.com>
Date2012-03-24 15:55 -0700
SubjectIs this a bridging scenario?
Message-ID<b5b53ca6-9141-4105-b701-4b8935268f02@vy8g2000pbc.googlegroups.com>
Hi All,

I have the following:


<IP CAM>-------WIRED------<<PC  <LAN CARD>+<WIFI CARD> >> ------- /
WIRELESS/ --------<ROUTER>---INET

So in otherwords I have a IP Camera wired to a Linux PC which
wirelessly connects to a ADSL modem/router, that is the wired
inetfaces connects the camera to the PC, and the wireless interface
connects the PC to the router.

I want the Camera to be able to connect to the Internet via the modem
router.

Is this what is called a bridge?

What would I need to do to allow the Camera to access the gateway and
thus internet via eth0 and eth1 (the wired and wireless interface) in
the PC which it is connected to?

[toc] | [next] | [standalone]


#1206

FromAl <bigal.nz@gmail.com>
Date2012-03-24 15:57 -0700
Message-ID<98dc3a93-2599-4b1e-b032-f080ab36a53a@x10g2000pbi.googlegroups.com>
In reply to#1205
PS: I still want the modem/router doing all the DHCP.

[toc] | [prev] | [next] | [standalone]


#1208

FromAragorn <stryder@telenet.be.invalid>
Date2012-03-25 09:26 +0200
Message-ID<jkmhbp$em6$1@dont-email.me>
In reply to#1205
On Saturday 24 March 2012 23:55, Al conveyed the following to 
comp.os.linux.networking...

> Hi All,
> 
> I have the following:
> 
> 
> <IP CAM>-------WIRED------<<PC  <LAN CARD>+<WIFI CARD> >> ------- /
> WIRELESS/ --------<ROUTER>---INET
> 
> So in otherwords I have a IP Camera wired to a Linux PC which
> wirelessly connects to a ADSL modem/router, that is the wired
> inetfaces connects the camera to the PC, and the wireless interface
> connects the PC to the router.
> 
> I want the Camera to be able to connect to the Internet via the modem
> router.
> 
> Is this what is called a bridge?

No, what you are describing is routing.  Bridging is when you have a 
single NIC device acting like it is multiple virtual NICs, each with 
their own IP address and/or MAC address.

> What would I need to do to allow the Camera to access the gateway and
> thus internet via eth0 and eth1 (the wired and wireless interface) in
> the PC which it is connected to?

You need to set up the PC as the gateway for the camera.

-- 
= Aragorn =
(registered GNU/Linux user #223157)

[toc] | [prev] | [next] | [standalone]


#1211

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-03-25 10:56 +0200
Message-ID<jkmmjh$rkh$1@saria.nerim.net>
In reply to#1208
Hello,

Aragorn a écrit :
> On Saturday 24 March 2012 23:55, Al conveyed the following to 
> comp.os.linux.networking...
> 
>> <IP CAM>-------WIRED------<<PC  <LAN CARD>+<WIFI CARD> >> ------- /
>> WIRELESS/ --------<ROUTER>---INET
>>
>> So in otherwords I have a IP Camera wired to a Linux PC which
>> wirelessly connects to a ADSL modem/router, that is the wired
>> inetfaces connects the camera to the PC, and the wireless interface
>> connects the PC to the router.
>>
>> I want the Camera to be able to connect to the Internet via the modem
>> router.
>>
>> Is this what is called a bridge?
> 
> No, what you are describing is routing.

It could be bridging too. If the OP requires that the camera gets its IP
configuration from the modem-router's DHCP server, then it will probably
be bridging, because routing requires two separate subnets while
bridging expands the LAN. Note that not all wireless NICs support
bridging. See
<http://www.linuxfoundation.org/collaborate/workgroups/networking/bridge#It_doesn.27t_work_with_my_Wireless_card.21>

> Bridging is when you have a 
> single NIC device acting like it is multiple virtual NICs, each with 
> their own IP address and/or MAC address.

Huh ? Bridging is when interfaces (not only NICs) are used as ports of a
software switch. Usually bridged interfaces do not have an IP address on
their own, it is transferred the bridge interface.

[toc] | [prev] | [next] | [standalone]


#1212

FromAragorn <stryder@telenet.be.invalid>
Date2012-03-25 12:19 +0200
Message-ID<jkmren$sec$1@dont-email.me>
In reply to#1211
On Sunday 25 March 2012 10:56, Pascal Hambourg conveyed the following to 
comp.os.linux.networking...

> Hello,
> 
> Aragorn a écrit :
>> On Saturday 24 March 2012 23:55, Al conveyed the following to
>> comp.os.linux.networking...
>> 
>>> <IP CAM>-------WIRED------<<PC  <LAN CARD>+<WIFI CARD> >> ------- /
>>> WIRELESS/ --------<ROUTER>---INET
>>>
>>> So in otherwords I have a IP Camera wired to a Linux PC which
>>> wirelessly connects to a ADSL modem/router, that is the wired
>>> inetfaces connects the camera to the PC, and the wireless interface
>>> connects the PC to the router.
>>>
>>> I want the Camera to be able to connect to the Internet via the
>>> modem router.
>>>
>>> Is this what is called a bridge?
>> 
>> No, what you are describing is routing.
> 
> It could be bridging too.

Yes, I realized this after I had already sent off my reply.

> If the OP requires that the camera gets its IP configuration from the
> modem-router's DHCP server, then it will probably be bridging, because
> routing requires two separate subnets while bridging expands the LAN.

That is correct.

> Note that not all wireless NICs support bridging. See
> 
<http://www.linuxfoundation.org/collaborate/workgroups/networking/bridge#It_doesn.27t_work_with_my_Wireless_card.21>

I didn't know about that, but then again I'm not very well-versed on 
wireless stuff.  The only thing I myself use it for is for having my 
Android phone connect to the internet via my Linksys WRT54GL router, 
which supports both wired and wireless connections.  My computers are 
all connected via CAT5e UTP cables. ;-)

>> Bridging is when you have a single NIC device acting like it is
>> multiple virtual NICs, each with their own IP address and/or MAC
>> address.
> 
> Huh ? Bridging is when interfaces (not only NICs) are used as ports of
> a software switch.

Yes, poor choice of words on my part - my apologies.  By "NIC" I meant 
"something in which you plug a (physical or virtual) network cable".

> Usually bridged interfaces do not have an IP address on their own, it
> is transferred the bridge interface.

That too is correct.  My brain shortcircuited for a second with regard 
to the IP addresses.  The idea of course is to have a _common_ IP 
address for the whole bridge, whereas with routing, you have two 
different subnets talking to eachother and thus two different IP ranges.

-- 
= Aragorn =
(registered GNU/Linux user #223157)

[toc] | [prev] | [next] | [standalone]


#1234

FromAl <bigal.nz@gmail.com>
Date2012-04-08 05:00 -0700
Message-ID<2f8acba3-b55f-42c3-b7ff-c7de7bf22649@qg3g2000pbc.googlegroups.com>
In reply to#1208
On Mar 25, 8:26 pm, Aragorn <stry...@telenet.be.invalid> wrote:
> On Saturday 24 March 2012 23:55, Al conveyed the following to
> comp.os.linux.networking...
>
>
>
>
>
> > Hi All,
>
> > I have the following:
>
> > <IP CAM>-------WIRED------<<PC  <LAN CARD>+<WIFI CARD> >> ------- /
> > WIRELESS/ --------<ROUTER>---INET
>
> > So in otherwords I have a IP Camera wired to a Linux PC which
> > wirelessly connects to a ADSL modem/router, that is the wired
> > inetfaces connects the camera to the PC, and the wireless interface
> > connects the PC to the router.
>
> > I want the Camera to be able to connect to the Internet via the modem
> > router.
>
> > Is this what is called a bridge?
>
> No, what you are describing is routing.  Bridging is when you have a
> single NIC device acting like it is multiple virtual NICs, each with
> their own IP address and/or MAC address.
>
> > What would I need to do to allow the Camera to access the gateway and
> > thus internet via eth0 and eth1 (the wired and wireless interface) in
> > the PC which it is connected to?
>
> You need to set up the PC as the gateway for the camera.
>
> --
> = Aragorn =
> (registered GNU/Linux user #223157)

Hi,

Sorry for the belated reply. Ok I understand that it is routing, and I
will need to set a static IP on the interfaces.

Lets say on the PC we have

wlan0 192.168.1.120
eth0 192.168.2.121 (I think eth0 needs to be a diff subnet right?)

and on the camera which connects to eth0:

cam1 192.168.2.122

I then need a routing "rule" ?
and how would I port forward so I can access the camera directly from
the inet?
how would I port forward so I can access the linux box from the net?

What would the rules look like?

Sorry for all the questions, but some of these topics are new to me.

Thanks

-AL



[toc] | [prev] | [next] | [standalone]


#1235

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-04-08 14:20 +0200
Message-ID<jlrvq6$2muf$1@saria.nerim.net>
In reply to#1234
Al a écrit :
> 
> Sorry for the belated reply. Ok I understand that it is routing, and I
> will need to set a static IP on the interfaces.

As I wrote, it can be either routing or bridging. Let's go for routing.

> Lets say on the PC we have
> 
> wlan0 192.168.1.120
> eth0 192.168.2.121 (I think eth0 needs to be a diff subnet right?)

Correct.

> and on the camera which connects to eth0:
> 
> cam1 192.168.2.122

Fine.

> I then need a routing "rule" ?

No. But in order for the camera to be able to connect to the internet,
you need to set the Linux box (192.168.2.121) as the default gateway on
the camera and set up the Linux box as an IP router (sysctl
net.ipv4.ip_forward=1).
Also you will need to either :
- create a static route on the router to the camera subnet
(192.168.2.0/24) with the Linux box (192.168.1.120) as the gateway.
- or set up masquerading on the Linux box (iptables -t nat -A
POSTROUTING -o wlan0 -j MASQUERADE).

> and how would I port forward so I can access the camera directly from
> the inet?

If the router has a static route to the camera subnet, then it should be
possible to create a port forwarding rule directly to the camera
(192.168.2.122) on it.
Otherwise you need to create a port forwarding rule to the Linux box
(192.168.1.120) on the router and create a similar port forwarding rule
to the camera on the Linux box :
iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.120 -p tcp --dport
80 -j DNAT --to 192.168.2.122
(change with whatever port the camera is using)

> how would I port forward so I can access the linux box from the net?

See above. This is router-dependent.

[toc] | [prev] | [next] | [standalone]


#1237

FromAl <bigal.nz@gmail.com>
Date2012-04-08 06:10 -0700
Message-ID<e5b024d8-e2c6-4d7d-8969-70a983604ccd@x5g2000pbl.googlegroups.com>
In reply to#1235
On Apr 9, 12:20 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
wrote:
> Al a écrit :
>
>
>
> > Sorry for the belated reply. Ok I understand that it is routing, and I
> > will need to set a static IP on the interfaces.
>
> As I wrote, it can be either routing or bridging. Let's go for routing.
>
> > Lets say on the PC we have
>
> > wlan0 192.168.1.120
> > eth0 192.168.2.121 (I think eth0 needs to be a diff subnet right?)
>
> Correct.
>
> > and on the camera which connects to eth0:
>
> > cam1 192.168.2.122
>
> Fine.
>
> > I then need a routing "rule" ?
>
> No. But in order for the camera to be able to connect to the internet,
> you need to set the Linux box (192.168.2.121) as the default gateway on
> the camera and set up the Linux box as an IP router (sysctl
> net.ipv4.ip_forward=1).
> Also you will need to either :
> - create a static route on the router to the camera subnet
> (192.168.2.0/24) with the Linux box (192.168.1.120) as the gateway.
> - or set up masquerading on the Linux box (iptables -t nat -A
> POSTROUTING -o wlan0 -j MASQUERADE).
>
> > and how would I port forward so I can access the camera directly from
> > the inet?
>
> If the router has a static route to the camera subnet, then it should be
> possible to create a port forwarding rule directly to the camera
> (192.168.2.122) on it.
> Otherwise you need to create a port forwarding rule to the Linux box
> (192.168.1.120) on the router and create a similar port forwarding rule
> to the camera on the Linux box :
> iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.120 -p tcp --dport
> 80 -j DNAT --to 192.168.2.122
> (change with whatever port the camera is using)
>
> > how would I port forward so I can access the linux box from the net?
>
> See above. This is router-dependent.

How does this look:

http://i.imgur.com/1wqFf.jpg

But do I still need to add something else for the camera to make
outbound connections for SIP and email notifications etc?

Cheers

-Al

[toc] | [prev] | [next] | [standalone]


#1239

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-04-08 16:28 +0200
Message-ID<jls7ac$2pq5$1@saria.nerim.net>
In reply to#1237
Al a écrit :
> 
> How does this look:
> 
> http://i.imgur.com/1wqFf.jpg

The -o option cannot be used in a PREROUTING chain, because the output
interface is not known yet : it is selected at the routing decision.

Why do you need the rule in the FORWARD chain ?
If you need it because packets are dropped by default, then you'll
probably need extra rules to accept reply packets in the other direction
and packets belonging to other types of communication (you mentionned
SIP and mail below).

"forward WAN port 12345 to LAN 12345" is not detailed enough.
You must indicate to which address.

> But do I still need to add something else for the camera to make
> outbound connections for SIP and email notifications etc?

SIP is a special protocol, a bit like FTP. If the Linux box does
stateful filtering or masquerading, you may need to load the conntrack
(for stateful filtering) or NAT (for masquerading) helper modules for
that protocol, nf_conntrack_sip and nf_nat_ftp.

[toc] | [prev] | [next] | [standalone]


#1249

FromAl <bigal.nz@gmail.com>
Date2012-04-08 12:39 -0700
Message-ID<4989b111-42a3-4ff4-994c-814c858c7689@qg3g2000pbc.googlegroups.com>
In reply to#1239
On Apr 9, 2:28 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
wrote:
> Al a écrit :
>
>
>
> > How does this look:
>
> >http://i.imgur.com/1wqFf.jpg
>
> The -o option cannot be used in a PREROUTING chain, because the output
> interface is not known yet : it is selected at the routing decision.
>
> Why do you need the rule in the FORWARD chain ?
> If you need it because packets are dropped by default, then you'll
> probably need extra rules to accept reply packets in the other direction
> and packets belonging to other types of communication (you mentionned
> SIP and mail below).
>
> "forward WAN port 12345 to LAN 12345" is not detailed enough.
> You must indicate to which address.
>
> > But do I still need to add something else for the camera to make
> > outbound connections for SIP and email notifications etc?
>
> SIP is a special protocol, a bit like FTP. If the Linux box does
> stateful filtering or masquerading, you may need to load the conntrack
> (for stateful filtering) or NAT (for masquerading) helper modules for
> that protocol, nf_conntrack_sip and nf_nat_ftp.

So what do you think the rules should look like?

Sorry I am not expert enough yet to try my hand at writing the rules.

Cheers

-AL

[toc] | [prev] | [next] | [standalone]


#1250

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-04-08 22:32 +0200
Message-ID<jlssko$39$1@saria.nerim.net>
In reply to#1249
Al a écrit :
> 
> So what do you think the rules should look like?

For a start, only the ones I mentionned in my previous reply.

[toc] | [prev] | [next] | [standalone]


#1255

FromAl <bigal.nz@gmail.com>
Date2012-04-09 08:28 -0700
Message-ID<ae19d8e4-3a63-4590-bd08-67f643df1b8c@w6g2000pbp.googlegroups.com>
In reply to#1250
On Apr 9, 8:32 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
wrote:
> Al a écrit :
>
>
>
> > So what do you think the rules should look like?
>
> For a start, only the ones I mentionned in my previous reply.

Something is still screwy.

I have eth0 on;

auto lo
iface lo inet loopback

auto eth0
iface eth0 inet static
address 192.168.70.121
netmask 255.0.0.0
network 192.168.70.0
broadcast 192.168.70.255
#gateway 192.168.2.254

#auto wlan0
#iface wlan0 inet static
#address 192.168.1.120
#netmask 255.255.255.0
#network 192.168.1.0
#broadcast 192.168.1.255
#gateway 192.168.1.254

And the camera should have a static of 192.168.70.140 - but for some
reason when I ssh into the linux box from the net via wlan0 I cant
ping the camera.

Any thoughts?

Cheers

-Al

[toc] | [prev] | [next] | [standalone]


#1256

FromScott Hemphill <hemphill@hemphills.net>
Date2012-04-09 12:41 -0400
Message-ID<m3lim4j1rz.fsf@hemphills.net>
In reply to#1255
Al <bigal.nz@gmail.com> writes:

> On Apr 9, 8:32 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
> wrote:
>> Al a écrit :
>>
>>
>>
>> > So what do you think the rules should look like?
>>
>> For a start, only the ones I mentionned in my previous reply.
>
> Something is still screwy.
>
> I have eth0 on;
>
> auto lo
> iface lo inet loopback
>
> auto eth0
> iface eth0 inet static
> address 192.168.70.121
> netmask 255.0.0.0
> network 192.168.70.0
> broadcast 192.168.70.255
> #gateway 192.168.2.254
>
> #auto wlan0
> #iface wlan0 inet static
> #address 192.168.1.120
> #netmask 255.255.255.0
> #network 192.168.1.0
> #broadcast 192.168.1.255
> #gateway 192.168.1.254
>
> And the camera should have a static of 192.168.70.140 - but for some
> reason when I ssh into the linux box from the net via wlan0 I cant
> ping the camera.
>
> Any thoughts?

Your netmask is wrong.  It should be:

netmask 255.255.255.0

Scott
-- 
Scott Hemphill	hemphill@alumni.caltech.edu
"This isn't flying.  This is falling, with style."  -- Buzz Lightyear

[toc] | [prev] | [next] | [standalone]


#1257

FromAl <bigal.nz@gmail.com>
Date2012-04-09 11:52 -0700
Message-ID<41cda2ac-704c-407d-9716-fdd9ddba0011@s10g2000pbc.googlegroups.com>
In reply to#1256
On Apr 10, 4:41 am, Scott Hemphill <hemph...@hemphills.net> wrote:
> Al <bigal...@gmail.com> writes:
> > On Apr 9, 8:32 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
> > wrote:
> >> Al a écrit :
>
> >> > So what do you think the rules should look like?
>
> >> For a start, only the ones I mentionned in my previous reply.
>
> > Something is still screwy.
>
> > I have eth0 on;
>
> > auto lo
> > iface lo inet loopback
>
> > auto eth0
> > iface eth0 inet static
> > address 192.168.70.121
> > netmask 255.0.0.0
> > network 192.168.70.0
> > broadcast 192.168.70.255
> > #gateway 192.168.2.254
>
> > #auto wlan0
> > #iface wlan0 inet static
> > #address 192.168.1.120
> > #netmask 255.255.255.0
> > #network 192.168.1.0
> > #broadcast 192.168.1.255
> > #gateway 192.168.1.254
>
> > And the camera should have a static of 192.168.70.140 - but for some
> > reason when I ssh into the linux box from the net via wlan0 I cant
> > ping the camera.
>
> > Any thoughts?
>
> Your netmask is wrong.  It should be:
>
> netmask 255.255.255.0
>
> Scott
> --
> Scott Hemphill  hemph...@alumni.caltech.edu
> "This isn't flying.  This is falling, with style."  -- Buzz Lightyear

I made that mask rather liberal in attempt to get into the camera.
255.255.255.0 doesnt work either.

[toc] | [prev] | [next] | [standalone]


#1259

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-04-09 21:09 +0200
Message-ID<jlvc4f$u73$1@saria.nerim.net>
In reply to#1257
Al a écrit :
>>> auto eth0
>>> iface eth0 inet static
>>> address 192.168.70.121
>>> netmask 255.0.0.0
>>> network 192.168.70.0
>>> broadcast 192.168.70.255
[...]
>>> And the camera should have a static of 192.168.70.140

"Should" ? Does it actually ? How is it supposed to be configured ? Did
you check it, e.g. with arping ?

>> Your netmask is wrong.  It should be:
>>
>> netmask 255.255.255.0
> 
> I made that mask rather liberal in attempt to get into the camera.

255.0.0.0 is much too liberal. The private range in that block is only
192.168.0.0/16 (mask 255.255.0.0). The rest of 192.0.0.0/8 is public or
reserved space.

[toc] | [prev] | [next] | [standalone]


#1265

FromAl <bigal.nz@gmail.com>
Date2012-04-10 01:56 -0700
Message-ID<f2b02ff3-451d-4079-b537-8af9cd9c2dc0@w17g2000yqe.googlegroups.com>
In reply to#1259
Ok,

Not sure what was wrong, but finally, when I ssh into the linux box
via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via
eth0 (192.168.70.121)

By default access to the camera is via port 80, so now its IP table
time so I can access the camera from the inet (the router in use here
doesnt support static routes, so I open port 5555 on the router and
forward it to wlan0 (192.168.1.71) and need a similar rule in the
linux box. From what you wrote above the rules should be:

iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport
80 -j DNAT --to 192.168.70.140

Where 80 is the port the camera listens on. What I dont understand is
how this rule still allows me to access the linux box, cause I have
setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for
ssh. The rule above appears that any inbound traffic to wlan0 gets
forwarded to port 80 of the camera?

Cheers

-Al


[toc] | [prev] | [next] | [standalone]


#1276

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2012-04-10 20:30 +0200
Message-ID<jm1u90$1rkd$1@saria.nerim.net>
In reply to#1265
Al a écrit :
> 
> Not sure what was wrong, but finally, when I ssh into the linux box
> via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via
> eth0 (192.168.70.121)
> 
> By default access to the camera is via port 80, so now its IP table
> time so I can access the camera from the inet (the router in use here
> doesnt support static routes, so I open port 5555 on the router and
> forward it to wlan0 (192.168.1.71) and need a similar rule in the
> linux box. From what you wrote above the rules should be:
> 
> iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport
> 80 -j DNAT --to 192.168.70.140
> 
> Where 80 is the port the camera listens on. What I dont understand is
> how this rule still allows me to access the linux box, cause I have
> setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for
> ssh. The rule above appears that any inbound traffic to wlan0 gets
> forwarded to port 80 of the camera?

With the rule above, TCP connections to 192.168.1.71 port 80 are
redirected to 192.168.70.140 (same port).
1) SSH connections on port 22 are not affected.
2) If the router redirects port 5555 to 192.168.1.71 without changing
the destination port, this is useless. The rule must redirect port 5555
to port 80 :

iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport
5555 -j DNAT --to 192.168.70.140:80

[toc] | [prev] | [next] | [standalone]


#1280

FromAl <bigal.nz@gmail.com>
Date2012-04-10 16:30 -0700
Message-ID<35599c21-223f-4015-8ff4-45d256388bd6@a5g2000vbl.googlegroups.com>
In reply to#1276
On Apr 11, 6:30 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
wrote:
> Al a écrit :
>
>
>
>
>
>
>
> > Not sure what was wrong, but finally, when I ssh into the linux box
> > via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via
> > eth0 (192.168.70.121)
>
> > By default access to the camera is via port 80, so now its IP table
> > time so I can access the camera from the inet (the router in use here
> > doesnt support static routes, so I open port 5555 on the router and
> > forward it to wlan0 (192.168.1.71) and need a similar rule in the
> > linux box. From what you wrote above the rules should be:
>
> > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport
> > 80 -j DNAT --to 192.168.70.140
>
> > Where 80 is the port the camera listens on. What I dont understand is
> > how this rule still allows me to access the linux box, cause I have
> > setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for
> > ssh. The rule above appears that any inbound traffic to wlan0 gets
> > forwarded to port 80 of the camera?
>
> With the rule above, TCP connections to 192.168.1.71 port 80 are
> redirected to 192.168.70.140 (same port).
> 1) SSH connections on port 22 are not affected.
> 2) If the router redirects port 5555 to 192.168.1.71 without changing
> the destination port, this is useless. The rule must redirect port 5555
> to port 80 :
>
> iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport
> 5555 -j DNAT --to 192.168.70.140:80

Ok, well its not working. Where do I start, how to see if traffic is
even getting to port 80 of wlan0?

Cheers

-Al

[toc] | [prev] | [next] | [standalone]


#1281

FromAl <bigal.nz@gmail.com>
Date2012-04-10 19:23 -0700
Message-ID<e15911ac-4bda-478a-a2f1-158e78ff9882@js1g2000pbc.googlegroups.com>
In reply to#1280
On Apr 11, 11:30 am, Al <bigal...@gmail.com> wrote:
> On Apr 11, 6:30 am, Pascal Hambourg <boite-a-s...@plouf.fr.eu.org>
> wrote:
>
>
>
>
>
> > Al a écrit :
>
> > > Not sure what was wrong, but finally, when I ssh into the linux box
> > > via wlan0 (192.168.1.71) I can ping the camera (192.168.70.140) via
> > > eth0 (192.168.70.121)
>
> > > By default access to the camera is via port 80, so now its IP table
> > > time so I can access the camera from the inet (the router in use here
> > > doesnt support static routes, so I open port 5555 on the router and
> > > forward it to wlan0 (192.168.1.71) and need a similar rule in the
> > > linux box. From what you wrote above the rules should be:
>
> > > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport
> > > 80 -j DNAT --to 192.168.70.140
>
> > > Where 80 is the port the camera listens on. What I dont understand is
> > > how this rule still allows me to access the linux box, cause I have
> > > setup the router to forward 8888 to port 22 on wlan0 192.168.1.71 for
> > > ssh. The rule above appears that any inbound traffic to wlan0 gets
> > > forwarded to port 80 of the camera?
>
> > With the rule above, TCP connections to 192.168.1.71 port 80 are
> > redirected to 192.168.70.140 (same port).
> > 1) SSH connections on port 22 are not affected.
> > 2) If the router redirects port 5555 to 192.168.1.71 without changing
> > the destination port, this is useless. The rule must redirect port 5555
> > to port 80 :
>
> > iptables -t nat -A PREROUTING -i wlan0 -d 192.168.1.71 -p tcp --dport
> > 5555 -j DNAT --to 192.168.70.140:80
>
> Ok, well its not working. Where do I start, how to see if traffic is
> even getting to port 80 of wlan0?
>
> Cheers
>
> -Al

Someone suggested I might need to do something with conntracks?

[toc] | [prev] | [next] | [standalone]


#1282

FromAl <bigal.nz@gmail.com>
Date2012-04-10 22:54 -0700
Message-ID<fc43a8f0-0e18-4e9c-b272-53174f4d4382@h10g2000pbi.googlegroups.com>
In reply to#1276
Tcptrackoutput:


Client Server State Idle Speed

118.92.xx.55:58674 192.168.1.71:80 RESET 1s 0 b/s
118.92.xx.55:58673 192.168.1.71:80 RESET 1s 0 b/s
118.92.xx.55:58676 192.168.1.71:80 RESET 1s 0 b/s

SHows the connections hitting wlan0, but if I change to eth0 I see
nothing. Something is wrong with the rule.

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.os.linux.networking


csiph-web