Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #262696 > unrolled thread

How do I connect my new wifi router (Mi Router 4C)?

Started byMartin <martin94@cryptolab.net>
First post2023-10-25 06:20 +0200
Last post2023-10-26 01:30 +0200
Articles 20 on this page of 27 — 7 participants

Back to article view | Back to linux.debian.user


Contents

  How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 06:20 +0200
    Re: How do I connect my new wifi router (Mi Router 4C)? Geert Stappers <stappers@stappers.nl> - 2023-10-25 07:00 +0200
      Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 07:50 +0200
    Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 07:30 +0200
      Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 08:50 +0200
        Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 08:50 +0200
          Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:40 +0200
            Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 14:20 +0200
              Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 22:20 +0200
    Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-10-25 10:10 +0200
      Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 10:20 +0200
        Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:30 +0200
          Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 14:40 +0200
            Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 21:30 +0200
              Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 05:00 +0200
                Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-26 12:10 +0200
                  Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 17:10 +0200
                    Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-04 20:10 +0100
                      Re: How do I connect my new wifi router (Mi Router 4C)? Tixy <tixy@yxit.co.uk> - 2023-11-05 07:50 +0100
                        Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-05 17:00 +0100
                          Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-08 14:50 +0100
                            Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-09 11:30 +0100
                            Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-09 15:50 +0100
                        Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
                      Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-05 09:30 +0100
                        Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
      Re: How do I connect my new wifi router (Mi Router 4C)? David Wright <deblis@lionunicorn.co.uk> - 2023-10-26 01:30 +0200

Page 1 of 2  [1] 2  Next page →


#262696 — How do I connect my new wifi router (Mi Router 4C)?

FromMartin <martin94@cryptolab.net>
Date2023-10-25 06:20 +0200
SubjectHow do I connect my new wifi router (Mi Router 4C)?
Message-ID<HsDx7-Fzy-3@gated-at.bofh.it>
Hello,

With wifi antena I receive a (rather weak) signal that connect my
computer to internet. I have to use windsurfer antena booster
(http://members.multiweb.nl/schaaijw/windsurfer_wifi_en.pdf)
to get usable signal. So my computer have internet signal from
wifi antena - yay great thing :)

Now I also want to connect to internet with my mobile phone!
So I got a wifi router (Mi Router 4C made by Xiaomi)
(web site https://www.mi.com/global/product/mi-router-4c/
documentation https://manuals.plus/_mi/mi-router-4c-manual)

As it turn out I am not so bright to make this whole setup working :(
I pluged in new router to power and connected ethernet cable from my
computer to router WAN connection. (I belive this is how it should be
connected togheder)

>From now I had some partial successes and whole lot of problems.
I will describe what I tried later, but I would like to ask you now
How do I proceed from now on to set up router?


I tried lot of setup and none worked. Here I will describe one that
i hope should work - but does not :(

While I was seting up router as described in
https://manuals.plus/_mi/mi-router-4c-manual
in Step 2 (point 3) it said I do not have internet.
So I choose to manualy set up 'Static address' for
router as folows (my computer has IP address 192.168.231.3):

     IP address: 192.168.231.5
    Subnet mask: 255.255.255.0
Default gateway: 192.168.231.3
            DNS: 192.168.231.3

After all this setup I could issue those commands on my desktop:

(this is my desktop IP address - just to show it works)
boza@redmoon:~/work
$ ping 192.168.231.3
PING 192.168.231.3 (192.168.231.3) 56(84) bytes of data.
64 bytes from 192.168.231.3: icmp_seq=1 ttl=64 time=0.074 ms
64 bytes from 192.168.231.3: icmp_seq=2 ttl=64 time=0.058 ms
64 bytes from 192.168.231.3: icmp_seq=3 ttl=64 time=0.058 ms
64 bytes from 192.168.231.3: icmp_seq=4 ttl=64 time=0.048 ms
64 bytes from 192.168.231.3: icmp_seq=5 ttl=64 time=0.058 ms
64 bytes from 192.168.231.3: icmp_seq=6 ttl=64 time=0.048 ms
64 bytes from 192.168.231.3: icmp_seq=7 ttl=64 time=0.058 ms
^C
 --- 192.168.231.3 ping statistics ---
7 packets transmitted, 7 received, 0% packet loss, time 6123ms
rtt min/avg/max/mdev = 0.048/0.057/0.074/0.008 ms

(this is new router IP address)
boza@redmoon:~/work
$ ping 192.168.231.5
PING 192.168.231.5 (192.168.231.5) 56(84) bytes of data.
64 bytes from 192.168.231.5: icmp_seq=1 ttl=64 time=0.445 ms
64 bytes from 192.168.231.5: icmp_seq=2 ttl=64 time=0.381 ms
64 bytes from 192.168.231.5: icmp_seq=3 ttl=64 time=0.384 ms
64 bytes from 192.168.231.5: icmp_seq=4 ttl=64 time=0.360 ms
64 bytes from 192.168.231.5: icmp_seq=5 ttl=64 time=0.376 ms
64 bytes from 192.168.231.5: icmp_seq=6 ttl=64 time=0.403 ms
^C
 --- 192.168.231.5 ping statistics ---
6 packets transmitted, 6 received, 0% packet loss, time 5107ms
rtt min/avg/max/mdev = 0.360/0.391/0.445/0.027 ms


So ping work as expected but when i look on my mobile phone and
connect wirelesly to router and on phone I look with browser at
address 192.168.31.1 (this is addres router is using when i look
from phone) it show me that I can connet from mobile phone to router
(with green line on the picture it shows) but I can not connect
to internet (it shows red line from router to internet)

I hope someone will be able to give me some hint how to solve
this issue and be able to connect to internet from router - and
connected phone.

Martin

[toc] | [next] | [standalone]


#262698

FromGeert Stappers <stappers@stappers.nl>
Date2023-10-25 07:00 +0200
Message-ID<HsE9P-FTn-5@gated-at.bofh.it>
In reply to#262696
On Wed, Oct 25, 2023 at 06:15:00AM +0200, Martin wrote:
> Hello,
> 
    snip
> 
> I tried lot of setup and none worked.

And also missed https://lists.debian.org/debian-user/2023/10/msg00684.html
and https://lists.debian.org/debian-user/2023/10/msg00685.html
and https://lists.debian.org/debian-user/2023/10/msg00688.html
and https://lists.debian.org/debian-user/2023/10/msg00690.html
 


It is not how it works



Groeten
Geert Stappers
-- 
Silence is hard to parse

[toc] | [prev] | [next] | [standalone]


#262702

FromMartin <martin94@cryptolab.net>
Date2023-10-25 07:50 +0200
Message-ID<HsEWd-Go0-1@gated-at.bofh.it>
In reply to#262698
On Wed, Oct 25, 2023 at 06:52:09AM +0200, Geert Stappers wrote:
> On Wed, Oct 25, 2023 at 06:15:00AM +0200, Martin wrote:
> > I tried lot of setup and none worked.
> 
> And also missed https://lists.debian.org/debian-user/2023/10/msg00684.html
> and https://lists.debian.org/debian-user/2023/10/msg00685.html
> and https://lists.debian.org/debian-user/2023/10/msg00688.html
> and https://lists.debian.org/debian-user/2023/10/msg00690.html

Now I am very, very embarased.

When I first posted this message i got the error message back that it
cculd not be delivered. So I send more same message but did not receive
any response from mailing list. This is when I started looking at
browser on the link
https://lists.debian.org/debian-user/2023/10/threads.html but could not
find my message there (note that it shows only first page of 2 pages of
emails) I did not realize that this list have 2 pages, I always looked
only on the first page. And so I tried to use my different email
addresses that I had and post same message again few times. I also did
not receive any message back from mailing list that i send (some of
addresses were not subscribed to mailing list). Finaly I made a post
from this address and got the message back as posted in mailing list.
I guess it all boils down that I did not realized that 
https://lists.debian.org/debian-user/2023/10/threads.html page
have 2 pages, I was always looking at first page :(

Now I will hide under the rock and be ashamed.

But I really do need some advice about the problem I described in
(lot of the) messages I posted.

Martin

[toc] | [prev] | [next] | [standalone]


#262699

From"Marco M." <mm@dorfdsl.de>
Date2023-10-25 07:30 +0200
Message-ID<HsECR-GiD-1@gated-at.bofh.it>
In reply to#262696
Am 25.10.2023 um 06:15:00 Uhr schrieb Martin:

> As it turn out I am not so bright to make this whole setup working :(
> I pluged in new router to power and connected ethernet cable from my
> computer to router WAN connection. (I belive this is how it should be
> connected togheder)

Please specify the EXACT model names and the exact wiring of your
devices.

Please also tell us if you use NetworkManager or /etc/network for
configuration.

[toc] | [prev] | [next] | [standalone]


#262704

FromMartin <martin94@cryptolab.net>
Date2023-10-25 08:50 +0200
Message-ID<HsFSi-GXp-7@gated-at.bofh.it>
In reply to#262699
On Wed, Oct 25, 2023 at 07:24:10AM +0200, Marco M. wrote:
> 
> Please specify the EXACT model names and the exact wiring of your
> devices.

There is no other name than 'Mi Router 4C' made by Xiaomi.
2 links that I provided are for exact model I have.
(here they are again:
https://www.mi.com/global/product/mi-router-4c/
https://manuals.plus/_mi/mi-router-4c-manual)


The wiring is as folow:
a) power cable goes from wall to the far right socket
   (when looking from front of modem)
b) ethernet cable is connected from my desktop to far left scoket of router.
   (there are also 2 middle ethernet cable sockets which i do not use
   my guess is they are for connecting other devices -like desktop- to
   subnetwork that wifi router uses which is 192.168.31.X - my phone is
   geting adress from this subnetwork when connected to wifi router)

> Please also tell us if you use NetworkManager or /etc/network for
> configuration.

I am using /etc/network and here is whole /etc/network/interfaces file:

auto lo
iface lo inet loopback

auto enp3s0
iface enp3s0 inet static
      address 192.168.231.3
      netmask 255.255.255.0

# auto wlxe8de27a5ab1c
iface wlxe8de27a5ab1c inet dhcp
     wpa-ssid Thomson
     wpa-psk mybigsecret

Martin

[toc] | [prev] | [next] | [standalone]


#262705

From"Marco M." <mm@dorfdsl.de>
Date2023-10-25 08:50 +0200
Message-ID<HsFSi-GXp-9@gated-at.bofh.it>
In reply to#262704
Am 25.10.2023 um 08:45:26 Uhr schrieb Martin:

> I am using /etc/network and here is whole /etc/network/interfaces
> file:
> 
> auto lo
> iface lo inet loopback
> 
> auto enp3s0
> iface enp3s0 inet static
>       address 192.168.231.3
>       netmask 255.255.255.0

Why don't you use DHCP like your phone does?

Show 
ip a

[toc] | [prev] | [next] | [standalone]


#262715

FromMartin <martin94@cryptolab.net>
Date2023-10-25 13:40 +0200
Message-ID<HsKoW-K88-5@gated-at.bofh.it>
In reply to#262705
On Wed, Oct 25, 2023 at 08:47:03AM +0200, Marco M. wrote:
> 
> Why don't you use DHCP like your phone does?

Because I used this computer before I had WiFi and phone.

> Show 
> ip a

I posted output of that command to Max Nikulin email.

(Do not want to to post same info twice again as first email)

Martin

[toc] | [prev] | [next] | [standalone]


#262716

From"Marco M." <mm@dorfdsl.de>
Date2023-10-25 14:20 +0200
Message-ID<HsL1D-KGh-1@gated-at.bofh.it>
In reply to#262715
Am 25.10.2023 um 13:33:48 Uhr schrieb Martin:

> On Wed, Oct 25, 2023 at 08:47:03AM +0200, Marco M. wrote:
> > 
> > Why don't you use DHCP like your phone does?  
> 
> Because I used this computer before I had WiFi and phone.

Why it is a problem to change it?
Do you really want to deal with manually addressing machines?

> > Show 
> > ip a  
> 
> I posted output of that command to Max Nikulin email.
> 
> (Do not want to to post same info twice again as first email)

This is a mailing list, please keep the discussion here on the list and
do not send emails directly to subscribers. Nobody else can read them.

[toc] | [prev] | [next] | [standalone]


#262727

FromMartin <martin94@cryptolab.net>
Date2023-10-25 22:20 +0200
Message-ID<HsSw9-PvT-1@gated-at.bofh.it>
In reply to#262716
On Wed, Oct 25, 2023 at 02:15:36PM +0200, Marco M. wrote:
> Am 25.10.2023 um 13:33:48 Uhr schrieb Martin:
> 
> > On Wed, Oct 25, 2023 at 08:47:03AM +0200, Marco M. wrote:
> > > 
> > > Why don't you use DHCP like your phone does?  
> > 
> > Because I used this computer before I had WiFi and phone.
> 
> Why it is a problem to change it?
> Do you really want to deal with manually addressing machines?

I only have one computer, and now this new router. Because I only have
one computer I did not feel need to use DHCP to automaticaly assing me
an IP address.

Martin

[toc] | [prev] | [next] | [standalone]


#262708

FromAnssi Saari <anssi.saari@debian-user.mail.kapsi.fi>
Date2023-10-25 10:10 +0200
Message-ID<HsH7H-IcH-3@gated-at.bofh.it>
In reply to#262696
Martin <martin94@cryptolab.net> writes:

> Hello,
>
> With wifi antena I receive a (rather weak) signal that connect my
> computer to internet. I have to use windsurfer antena booster
> (http://members.multiweb.nl/schaaijw/windsurfer_wifi_en.pdf)
> to get usable signal. So my computer have internet signal from
> wifi antena - yay great thing :)
>
> Now I also want to connect to internet with my mobile phone!

You mean you want to use some unspecified wifi signal with your phone
also? Share the connection to your phone and computer? The link to this
"windsurfer" doesn't work so it's a little hard to help if you can't
describe what you have.

> As it turn out I am not so bright to make this whole setup working :(
> I pluged in new router to power and connected ethernet cable from my
> computer to router WAN connection. (I belive this is how it should be
> connected togheder)

The WAN connection is for the internet, not your computer. It says as
much in the Xiaomi manual.

> While I was seting up router as described in
> https://manuals.plus/_mi/mi-router-4c-manual
> in Step 2 (point 3) it said I do not have internet.
> So I choose to manualy set up 'Static address' for
> router as folows (my computer has IP address 192.168.231.3):
>
>      IP address: 192.168.231.5
>     Subnet mask: 255.255.255.0
> Default gateway: 192.168.231.3
>             DNS: 192.168.231.3
>
> After all this setup I could issue those commands on my desktop:
>
> (this is my desktop IP address - just to show it works)

So you created a LAN between your computer and the router.

> I hope someone will be able to give me some hint how to solve
> this issue and be able to connect to internet from router - and
> connected phone.

You have some kind of mysterious internet connection from
something. That needs to connect to the router's WAN port.

[toc] | [prev] | [next] | [standalone]


#262709

FromMax Nikulin <manikulin@gmail.com>
Date2023-10-25 10:20 +0200
Message-ID<HsHhn-Igc-7@gated-at.bofh.it>
In reply to#262708
On 25/10/2023 15:04, Anssi Saari wrote:
> You have some kind of mysterious internet connection from something. 
> That needs to connect to the router's WAN port.

My guess is the following:

- Source of weak WiFi
- WiFi booster
- WiFi adapter in computer
- ethernet port in computer
- ethernet port of Mi router
- WiFi provided by Mi router
- WiFi adapter inside the phone

So packet forwarding should be enabled on the computer. However I 
suspect an issue with IP addresses. Martin, please, provide output of

     ip address list

[toc] | [prev] | [next] | [standalone]


#262714

FromMartin <martin94@cryptolab.net>
Date2023-10-25 13:30 +0200
Message-ID<HsKff-K4Q-5@gated-at.bofh.it>
In reply to#262709
On Wed, Oct 25, 2023 at 03:17:09PM +0700, Max Nikulin wrote:
> On 25/10/2023 15:04, Anssi Saari wrote:
> > You have some kind of mysterious internet connection from something.
> > That needs to connect to the router's WAN port.
> 
> My guess is the following:
> 
> - Source of weak WiFi
> - WiFi booster
> - WiFi adapter in computer
> - ethernet port in computer
> - ethernet port of Mi router
> - WiFi provided by Mi router
> - WiFi adapter inside the phone
> 
> So packet forwarding should be enabled on the computer. However I suspect an
> issue with IP addresses. Martin, please, provide output of
> 
>     ip address list

You are absolutely correct with your guess - although it take me
some time to understand what you are talking about - which is all my
fault.

here is result of 'ip address list' and also 'ip route' command:

$ ip address list
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute
       valid_lft forever preferred_lft forever
2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether e0:d5:5e:73:c9:d3 brd ff:ff:ff:ff:ff:ff
    inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
       valid_lft forever preferred_lft forever
    inet6 fe80::e2d5:5eff:fe73:c9d3/64 scope link proto kernel_ll
       valid_lft forever preferred_lft forever
3: wlxe8de27a5ab1c: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether e8:de:27:a5:ab:1c brd ff:ff:ff:ff:ff:ff
    inet 192.168.0.16/24 brd 192.168.0.255 scope global dynamic wlxe8de27a5ab1c
       valid_lft 535000sec preferred_lft 535000sec
    inet6 fe80::eade:27ff:fea5:ab1c/64 scope link proto kernel_ll
       valid_lft forever preferred_lft forever
4: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
    link/ether 02:42:42:5b:a7:3b brd ff:ff:ff:ff:ff:ff
    inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
       valid_lft forever preferred_lft forever
5: br-7bfdce95ff27: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
    link/ether 02:42:52:ec:22:75 brd ff:ff:ff:ff:ff:ff
    inet 172.18.0.1/16 brd 172.18.255.255 scope global br-7bfdce95ff27
       valid_lft forever preferred_lft forever
6: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
    link/none
    inet 10.1.1.1/24 scope global tun0
       valid_lft forever preferred_lft forever
    inet6 fe80::f84d:e9fc:4ea5:f7fa/64 scope link stable-privacy proto kernel_ll
       valid_lft forever preferred_lft forever

$ ip route
default via 192.168.0.1 dev wlxe8de27a5ab1c
10.1.1.0/24 dev tun0 proto kernel scope link src 10.1.1.1
172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdown
172.18.0.0/16 dev br-7bfdce95ff27 proto kernel scope link src 172.18.0.1 linkdown
192.168.0.0/24 dev wlxe8de27a5ab1c proto kernel scope link src 192.168.0.16
192.168.231.0/24 dev enp3s0 proto kernel scope link src 192.168.231.3

[toc] | [prev] | [next] | [standalone]


#262719

FromMax Nikulin <manikulin@gmail.com>
Date2023-10-25 14:40 +0200
Message-ID<HsLkZ-KRP-1@gated-at.bofh.it>
In reply to#262714
On 25/10/2023 18:24, Martin wrote:
> On Wed, Oct 25, 2023 at 03:17:09PM +0700, Max Nikulin wrote:
>>
>> So packet forwarding should be enabled on the computer.

sysctl net.ipv4.ip_forward

almost certainly enabled since you have the docker0 network interface

>> However I suspect an issue with IP addresses.
I was wrong.

> 2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
>      link/ether e0:d5:5e:73:c9:d3 brd ff:ff:ff:ff:ff:ff
>      inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
[...]
> 3: wlxe8de27a5ab1c: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
>      link/ether e8:de:27:a5:ab:1c brd ff:ff:ff:ff:ff:ff
>      inet 192.168.0.16/24 brd 192.168.0.255 scope global dynamic wlxe8de27a5ab1c

looks consistent from router settings you posted earlier

>      IP address: 192.168.231.5
>     Subnet mask: 255.255.255.0
> Default gateway: 192.168.231.3
>             DNS: 192.168.231.3

I hope, you have a DNS server running on this machine

     dig debian.org @192.168.231.3

or

     host debian.org 192.168.231.3

Check that you do not have blocking rules in firewall and that 
masquerading is enabled for your downstream link enp3s0

     nft list ruleset

should have something like

table ip sharedconnection {
   chain postrouting {
     type nat hook postrouting priority srcnat; policy accept;
     ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
   }
}

A tool for further debugging is tcpdump or wireshark.

[toc] | [prev] | [next] | [standalone]


#262725

FromMartin <martin94@cryptolab.net>
Date2023-10-25 21:30 +0200
Message-ID<HsRJL-OYs-3@gated-at.bofh.it>
In reply to#262719
On Wed, Oct 25, 2023 at 07:33:52PM +0700, Max Nikulin wrote:
> On 25/10/2023 18:24, Martin wrote:
> > On Wed, Oct 25, 2023 at 03:17:09PM +0700, Max Nikulin wrote:
> > > 
> > > So packet forwarding should be enabled on the computer.
> 
> sysctl net.ipv4.ip_forward
> 
> almost certainly enabled since you have the docker0 network interface

You are right, it is enabled:

$ sudo sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 1

> I hope, you have a DNS server running on this machine
> 
>     host debian.org 192.168.231.3

I did not had dig installed but host worked, alas it showed me that I do
not have installed DNS server. So I installed dnsmasq package and
wonders happened (without me editing any config files - just installing
dnsmasq) - on my mobile phone when I connected to 192.168.31.1 address
(default router address when I look from phone) It showed now green line
from router to internet.

But unfortunatelly phone does not connect to internet yet. I guess I will
need to issue some 'sudo route' command to add path from my router to
outside world (actually I do not have idea if this is the problem).

> Check that you do not have blocking rules in firewall

I do not use firewall anymore, since I stoped using wired home phone
(dialup modem) to connect to internet with ppp protocol. Since I am now
connected to internet via my weak antena which is connected to router(A)
and then to internet I know that distant router(A) is protected enough
(after all it uses only local address that i can see 192.168.0.1).

> and that masquerading
> is enabled for your downstream link enp3s0
> 
>     nft list ruleset
> 
> should have something like
> 
> table ip sharedconnection {
>   chain postrouting {
>     type nat hook postrouting priority srcnat; policy accept;
>     ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
>   }
> }

I did not add any masquerading rules by myself and output of command
'nft list ruleset' is showed below. It does not have anything like you
showed in section 'table ip sharedconnection'. I remember using iptables
command to make firewall and masquerading my computer while I was using
dialup modem internet connection. I do not set up use any iptable rules
manualy anymore.

So this is probably what I need to figure out how to use masquerading
and other firewall rules to enable my new router to connect to outside
internet. (I must admit that I forgot what rules should I use to enable
this setup - so I need your help)

Here is output of 'nft list ruleset' 'iptables -S' and 'iptables -L' command:
(I am not sure they provide different info, but here they are)

Thanks a lot
Martin


$ sudo nft list ruleset
# Warning: table ip nat is managed by iptables-nft, do not touch!
table ip nat {
        chain DOCKER {
                iifname "docker0" counter packets 0 bytes 0 return
                iifname "br-7bfdce95ff27" counter packets 0 bytes 0 return
        }

        chain POSTROUTING {
                type nat hook postrouting priority srcnat; policy accept;
                oifname "wlxe8de27a5ab1c" ip saddr 10.1.1.0/24  counter packets 192 bytes 11818 masquerade
                oifname != "docker0" ip saddr 172.17.0.0/16 counter packets 0 bytes 0 masquerade
                oifname != "br-7bfdce95ff27" ip saddr 172.18.0.0/16 counter packets 0 bytes 0 masquerade
        }

        chain PREROUTING {
                type nat hook prerouting priority dstnat; policy accept;
                fib daddr type local counter packets 7727 bytes 479748 jump DOCKER
        }

        chain OUTPUT {
                type nat hook output priority dstnat; policy accept;
                ip daddr != 127.0.0.0/8 fib daddr type local counter packets 3 bytes 196 jump DOCKER
        }
}
# Warning: table ip filter is managed by iptables-nft, do not touch!
table ip filter {
        chain DOCKER {
        }

        chain DOCKER-ISOLATION-STAGE-1 {
                iifname "docker0" oifname != "docker0" counter packets 0 bytes 0 jump DOCKER-ISOLATION-STAGE-2
                iifname "br-7bfdce95ff27" oifname != "br-7bfdce95ff27" counter packets 0 bytes 0 jump DOCKER-ISOLATION-STAGE-2
                counter packets 27 bytes 1780 return
        }

        chain DOCKER-ISOLATION-STAGE-2 {
                oifname "docker0" counter packets 0 bytes 0 drop
                oifname "br-7bfdce95ff27" counter packets 0 bytes 0 drop
                counter packets 0 bytes 0 return
        }

        chain FORWARD {
                type filter hook forward priority filter; policy drop;
                 counter packets 57740 bytes 51358193 accept
                counter packets 25 bytes 1644 jump DOCKER-USER
                counter packets 25 bytes 1644 jump DOCKER-ISOLATION-STAGE-1
                oifname "docker0" ct state related,established counter packets 0 bytes 0 accept
                oifname "docker0" counter packets 0 bytes 0 jump DOCKER
                iifname "docker0" oifname != "docker0" counter packets 0 bytes 0 accept
                iifname "docker0" oifname "docker0" counter packets 0 bytes 0 accept
                oifname "br-7bfdce95ff27" ct state related,established counter packets 0 bytes 0 accept
                oifname "br-7bfdce95ff27" counter packets 0 bytes 0 jump DOCKER
                iifname "br-7bfdce95ff27" oifname != "br-7bfdce95ff27" counter packets 0 bytes 0 accept
                iifname "br-7bfdce95ff27" oifname "br-7bfdce95ff27" counter packets 0 bytes 0 accept
        }

        chain DOCKER-USER {
                counter packets 25 bytes 1644 return
        }
}

$ sudo iptables -S
-P INPUT ACCEPT
-P FORWARD DROP
-P OUTPUT ACCEPT
-N DOCKER
-N DOCKER-ISOLATION-STAGE-1
-N DOCKER-ISOLATION-STAGE-2
-N DOCKER-USER
-A FORWARD -m comment --comment simple_rt -j ACCEPT
-A FORWARD -j DOCKER-USER
-A FORWARD -j DOCKER-ISOLATION-STAGE-1
-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o docker0 -j DOCKER
-A FORWARD -i docker0 ! -o docker0 -j ACCEPT
-A FORWARD -i docker0 -o docker0 -j ACCEPT
-A FORWARD -o br-7bfdce95ff27 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-7bfdce95ff27 -j DOCKER
-A FORWARD -i br-7bfdce95ff27 ! -o br-7bfdce95ff27 -j ACCEPT
-A FORWARD -i br-7bfdce95ff27 -o br-7bfdce95ff27 -j ACCEPT
-A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i br-7bfdce95ff27 ! -o br-7bfdce95ff27 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -j RETURN
-A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o br-7bfdce95ff27 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -j RETURN
-A DOCKER-USER -j RETURN

$ sudo iptables -L
Chain INPUT (policy ACCEPT)
target     prot opt source               destination

Chain FORWARD (policy DROP)
target     prot opt source               destination
ACCEPT     all  --  anywhere             anywhere             /* simple_rt */
DOCKER-USER  all  --  anywhere             anywhere
DOCKER-ISOLATION-STAGE-1  all  --  anywhere             anywhere
ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED
DOCKER     all  --  anywhere             anywhere
ACCEPT     all  --  anywhere             anywhere
ACCEPT     all  --  anywhere             anywhere
ACCEPT     all  --  anywhere             anywhere             ctstate RELATED,ESTABLISHED
DOCKER     all  --  anywhere             anywhere
ACCEPT     all  --  anywhere             anywhere
ACCEPT     all  --  anywhere             anywhere

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

Chain DOCKER (2 references)
target     prot opt source               destination

Chain DOCKER-ISOLATION-STAGE-1 (1 references)
target     prot opt source               destination
DOCKER-ISOLATION-STAGE-2  all  --  anywhere             anywhere
DOCKER-ISOLATION-STAGE-2  all  --  anywhere             anywhere
RETURN     all  --  anywhere             anywhere

Chain DOCKER-ISOLATION-STAGE-2 (2 references)
target     prot opt source               destination
DROP       all  --  anywhere             anywhere
DROP       all  --  anywhere             anywhere
RETURN     all  --  anywhere             anywhere

Chain DOCKER-USER (1 references)
target     prot opt source               destination
RETURN     all  --  anywhere             anywhere

[toc] | [prev] | [next] | [standalone]


#262736

FromMax Nikulin <manikulin@gmail.com>
Date2023-10-26 05:00 +0200
Message-ID<HsYLf-Tci-5@gated-at.bofh.it>
In reply to#262725
On 26/10/2023 02:20, Martin wrote:
> On Wed, Oct 25, 2023 at 07:33:52PM +0700, Max Nikulin wrote:
>> should have something like
>>
>> table ip sharedconnection {
>>    chain postrouting {
>>      type nat hook postrouting priority srcnat; policy accept;
>>      ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
>>    }
>> }
> I did not add any masquerading rules by myself and output of command
> 'nft list ruleset' is showed below. It does not have anything like you
> showed in section 'table ip sharedconnection'.

"sharedconnection" is an arbitrary name. It should be chosen to not 
conflict with other applications. Actually you have nat masquerading 
rules created by docker for other interfaces. Read 
/usr/share/doc/nftables/README.Debian and choose a convenient for you 
way to add rules. You may add the following heading and may save rules 
to a file that may be read by either "nft -f FILE.conf" or just 
executing it.

#!/usr/sbin/nft -f
table inet sharedconnection {}
flush table inet sharedconnection
# table ip shared connection { ... } from above

---

Upstream WiFi router does not know that packets addressed to 
192.168.231.5 (mi router) should be sent to your computer 
(192.168.0.16), so you computer should make upstream router believing 
that all packets from your phone originates from 192.168.0.16.

[toc] | [prev] | [next] | [standalone]


#262744

FromMartin <martin94@cryptolab.net>
Date2023-10-26 12:10 +0200
Message-ID<Ht5tn-Y6R-1@gated-at.bofh.it>
In reply to#262736
On Thu, Oct 26, 2023 at 09:54:22AM +0700, Max Nikulin wrote:
> On 26/10/2023 02:20, Martin wrote:
> > On Wed, Oct 25, 2023 at 07:33:52PM +0700, Max Nikulin wrote:
> > > should have something like
> > > 
> > > table ip sharedconnection {
> > >    chain postrouting {
> > >      type nat hook postrouting priority srcnat; policy accept;
> > >      ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
> > >    }
> > > }
> 
> "sharedconnection" is an arbitrary name. It should be chosen to not conflict
> with other applications. Actually you have nat masquerading rules created by
> docker for other interfaces. Read /usr/share/doc/nftables/README.Debian and
> choose a convenient for you way to add rules. You may add the following
> heading and may save rules to a file that may be read by either "nft -f
> FILE.conf" or just executing it.
> 
> #!/usr/sbin/nft -f
> table inet sharedconnection {}
> flush table inet sharedconnection
> # table ip shared connection { ... } from above

I did create FILE.conf and after executing it I can connect to internet from
my phone. THANK YOU!

Now where do I put this FILE.conf? I would like for it to run everytime
I turn on my computer. Is there some standard place for it - perhaps in
/etc directory? Maybe i should create some script in /etc/init.d/
directory?

Martin

[toc] | [prev] | [next] | [standalone]


#262750

FromMax Nikulin <manikulin@gmail.com>
Date2023-10-26 17:10 +0200
Message-ID<Hta9I-11mN-5@gated-at.bofh.it>
In reply to#262744
On 26/10/2023 17:06, Martin wrote:
> On Thu, Oct 26, 2023 at 09:54:22AM +0700, Max Nikulin wrote:
>>
>> #!/usr/sbin/nft -f
>> table inet sharedconnection {}
>> flush table inet sharedconnection
>> # table ip shared connection { ... } from above
> 
> I did create FILE.conf and after executing it I can connect to internet from
> my phone. THANK YOU!
> 
> Now where do I put this FILE.conf? I would like for it to run everytime
> I turn on my computer.

I wrote "FILE" in caps trying to express that you can choose any name. 
Debian has /etc/nftables.conf and nft supports the "include" directive, 
see nft(8). So you may put your file to /etc or to create a dedicated 
directory, e.g. /etc/nftables.conf.d, for your settings and include your 
file from the main conf file, so it should be applied on each boot by 
nftables.service. You may put "table ip shared ..." content directly 
into /etc/nftables.conf as well, however I prefer to minimize changes in 
files provided by packages when it is possible to use additional ones.

Instead of installing dnsmasq you may specify a public dns server in 
your router settings (8.8.8.8, etc.). Or if you are sure that DNS 
configuration provided by the upstream router 192.168.0.1 is stable then 
you may use servers from DHCP lease. However having a local caching DNS 
server (dnsmasq or systemd-resolved) should not harm.

By the way, since you have dnsmasq running, you may enable its DHCP 
server (dhcp-range=192.168.231.5,192.168.231.254) and may switch mi 
router from static network configuration to DHCP.

As a final note, NetworkManager allows to create "shared" connections 
(ipv4.method). It starts dnsmasq and adds necessary firewall nat rules. 
I used it in both directions: with ethernet upstream connection to share 
wifi or to leverage 1G ethernet link to copy files between laptops while 
one of them has an active wifi connection.

[toc] | [prev] | [next] | [standalone]


#263124

FromMartin <martin94@cryptolab.net>
Date2023-11-04 20:10 +0100
Message-ID<HwubT-38lr-5@gated-at.bofh.it>
In reply to#262750
On Thu, Oct 26, 2023 at 10:00:08PM +0700, Max Nikulin wrote:
> On 26/10/2023 17:06, Martin wrote:
> > On Thu, Oct 26, 2023 at 09:54:22AM +0700, Max Nikulin wrote:
> > > 
> > > #!/usr/sbin/nft -f
> > > table inet sharedconnection {}
> > > flush table inet sharedconnection
> > > table ip sharedconnection { ... } from above

> I wrote "FILE" in caps trying to express that you can choose any name.
> Debian has /etc/nftables.conf and nft supports the "include" directive, see
> nft(8). So you may put your file to /etc or to create a dedicated directory,
> e.g. /etc/nftables.conf.d, for your settings and include your file from the
> main conf file, so it should be applied on each boot by nftables.service.
> You may put "table ip shared ..." content directly into /etc/nftables.conf
> as well, however I prefer to minimize changes in files provided by packages
> when it is possible to use additional ones.

> By the way, since you have dnsmasq running, you may enable its DHCP server
> (dhcp-range=192.168.231.5,192.168.231.254) and may switch mi router from
> static network configuration to DHCP.

Sorry for long pause in reply (my hard disk was dieing so I replaced HD and
installed whole debian from scratch).

Now (after reinstall everything) I am the point where I want to make my
router to work. I set up dnsmasq to enable DHCP with line in config:
dhcp-range=192.168.231.241,192.168.231.254,12h
and reseted my WiFi router after little configuring with my phone I can
connect my phone to WiFi router and to my computer (that still has address
192.168.231.3). I can access http server on my computer when I type in my
phone address to connect in web browser: http://192.168.231.3/text.html
(I created on my computer file /var/www/html/test.html)

That is all without changing anything with nft program.
I created a file with exatly this content:

#!/usr/sbin/nft -f

table ip masqrule {}
flush table ip masqrule
table ip masqrule {
  chain postrouting {
    type nat hook postrouting priority srcnat; policy accept;
    ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
  }
}

When I execute this file with sudo unfortunately nothing changes, I can
not connect to the internet (trying www.google.com from phone).

[[ this is about old system I had on old HD:
I remeber before reinstalling whole system at this point I had connection
from my phone to the internet (I could see google and then some videos on
youtube worked too on the phone) After I rebooted my old system I could not
connect to internet anymore from the phone. I slightly changed the script
from your post to current state (namely using ip allways instead of inet at
first two lines of script and using 'masqrule'as table name) I thing those
changes are ok.
]]

I have no idea what else should I try to make this work. Maybe I forgot
to issue some command (but I do not think so).

BTW putting above script into /etc/nftables.conf (at the bottom of file)
did not ever worked - I had always to run that file manualy as root.
Command 'nft list ruleset' only then showed this table.
I have no idea why. To me it seemed as if /etc/nftables.conf file
was not executed (I have rebooted many times so this file should run).

Bye
Martin

My current network connections, and 'ip route' command:
(I see 2 changes from my prevoius setup: missing tun0 and  br-7bfdce95ff27
they were before created automaticaly so I hope it does not matter they
are not present now - both where doing local addresses 10.1.1.1/24 and
172.18.0.1/16, maybe they will appeear when I install more programs from
repository - i am not worried about them, just mentioning to be complete)
root@redmoon:~# ip address list
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host noprefixroute
       valid_lft forever preferred_lft forever
2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether e0:d5:5e:73:c9:d3 brd ff:ff:ff:ff:ff:ff
    inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
       valid_lft forever preferred_lft forever
    inet6 fe80::e2d5:5eff:fe73:c9d3/64 scope link proto kernel_ll
       valid_lft forever preferred_lft forever
3: wlxe8de27a5ab1c: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether e8:de:27:a5:ab:1c brd ff:ff:ff:ff:ff:ff
    inet 192.168.0.16/24 brd 192.168.0.255 scope global dynamic wlxe8de27a5ab1c
       valid_lft 591334sec preferred_lft 591334sec
    inet6 fe80::eade:27ff:fea5:ab1c/64 scope link proto kernel_ll
       valid_lft forever preferred_lft forever
4: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
    link/ether 02:42:33:88:62:ce brd ff:ff:ff:ff:ff:ff
    inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
       valid_lft forever preferred_lft forever
root@redmoon:~# ip route
default via 192.168.0.1 dev wlxe8de27a5ab1c
172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdown
192.168.0.0/24 dev wlxe8de27a5ab1c proto kernel scope link src 192.168.0.16
192.168.231.0/24 dev enp3s0 proto kernel scope link src 192.168.231.3

[toc] | [prev] | [next] | [standalone]


#263141

FromTixy <tixy@yxit.co.uk>
Date2023-11-05 07:50 +0100
Message-ID<HwF7j-3f5H-9@gated-at.bofh.it>
In reply to#263124
On Sat, 2023-11-04 at 20:08 +0100, Martin wrote:
[...]
> BTW putting above script into /etc/nftables.conf (at the bottom of file)
> did not ever worked - I had always to run that file manualy as root.
> Command 'nft list ruleset' only then showed this table.
> I have no idea why. To me it seemed as if /etc/nftables.conf file
> was not executed (I have rebooted many times so this file should run).
[...]

Did you enable the nftables service? To do that, use:

# systemctl enable nftables.service

and to see status of the service

# systemctl status nftables.service

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#263154

FromMax Nikulin <manikulin@gmail.com>
Date2023-11-05 17:00 +0100
Message-ID<HwNHz-3kzp-7@gated-at.bofh.it>
In reply to#263141
On 05/11/2023 13:48, Tixy wrote:
> On Sat, 2023-11-04 at 20:08 +0100, Martin wrote:
> [...]
>> BTW putting above script into /etc/nftables.conf (at the bottom of file)
>> did not ever worked - I had always to run that file manualy as root.
>> Command 'nft list ruleset' only then showed this table.
>> I have no idea why. To me it seemed as if /etc/nftables.conf file
>> was not executed (I have rebooted many times so this file should run).
> [...]
> 
> Did you enable the nftables service? To do that, use:
> 
> # systemctl enable nftables.service
> 
> and to see status of the service
> 
> # systemctl status nftables.service

It should be checked first and

     journalctl -b -u nftables.service

alongside with searching for any nft messages in "journalctl -b". I 
suggested earlier to read /usr/share/doc/nftables/README.Debian It 
explicitly recommends to enable the service.

> 2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
>     inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0

I hope, your router allows to view configuration received from the DHCP 
server. Since static addresses were working (and it can be rechecked), I 
guess, gateway is not explicitly configured, so the router tries to send 
packets to 192.168.231.1. Either change the interface IP or configure 
dnsmasq to send 192.168.231.3.

To debug run wireshark or tcpdump on enp3s0 and wlxe8de27a5ab1c to check 
that packets from the phone are properly received and routed.

Warning: if you have not configured network interfaces for DHCP in 
dnsmasq then do it. Otherwise other computers connected to the upstream 
WiFi link may receive DHCP leases emitted from wlxe8de27a5ab1c.

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web