Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #262696 > unrolled thread
| Started by | Martin <martin94@cryptolab.net> |
|---|---|
| First post | 2023-10-25 06:20 +0200 |
| Last post | 2023-10-26 01:30 +0200 |
| Articles | 20 on this page of 27 — 7 participants |
Back to article view | Back to linux.debian.user
How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 06:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Geert Stappers <stappers@stappers.nl> - 2023-10-25 07:00 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 07:50 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 07:30 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 08:50 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 08:50 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:40 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 14:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 22:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-10-25 10:10 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 10:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:30 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 14:40 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 21:30 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 05:00 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-26 12:10 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 17:10 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-04 20:10 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Tixy <tixy@yxit.co.uk> - 2023-11-05 07:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-05 17:00 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-08 14:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-09 11:30 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-09 15:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-05 09:30 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? David Wright <deblis@lionunicorn.co.uk> - 2023-10-26 01:30 +0200
Page 1 of 2 [1] 2 Next page →
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-25 06:20 +0200 |
| Subject | How do I connect my new wifi router (Mi Router 4C)? |
| Message-ID | <HsDx7-Fzy-3@gated-at.bofh.it> |
Hello,
With wifi antena I receive a (rather weak) signal that connect my
computer to internet. I have to use windsurfer antena booster
(http://members.multiweb.nl/schaaijw/windsurfer_wifi_en.pdf)
to get usable signal. So my computer have internet signal from
wifi antena - yay great thing :)
Now I also want to connect to internet with my mobile phone!
So I got a wifi router (Mi Router 4C made by Xiaomi)
(web site https://www.mi.com/global/product/mi-router-4c/
documentation https://manuals.plus/_mi/mi-router-4c-manual)
As it turn out I am not so bright to make this whole setup working :(
I pluged in new router to power and connected ethernet cable from my
computer to router WAN connection. (I belive this is how it should be
connected togheder)
>From now I had some partial successes and whole lot of problems.
I will describe what I tried later, but I would like to ask you now
How do I proceed from now on to set up router?
I tried lot of setup and none worked. Here I will describe one that
i hope should work - but does not :(
While I was seting up router as described in
https://manuals.plus/_mi/mi-router-4c-manual
in Step 2 (point 3) it said I do not have internet.
So I choose to manualy set up 'Static address' for
router as folows (my computer has IP address 192.168.231.3):
IP address: 192.168.231.5
Subnet mask: 255.255.255.0
Default gateway: 192.168.231.3
DNS: 192.168.231.3
After all this setup I could issue those commands on my desktop:
(this is my desktop IP address - just to show it works)
boza@redmoon:~/work
$ ping 192.168.231.3
PING 192.168.231.3 (192.168.231.3) 56(84) bytes of data.
64 bytes from 192.168.231.3: icmp_seq=1 ttl=64 time=0.074 ms
64 bytes from 192.168.231.3: icmp_seq=2 ttl=64 time=0.058 ms
64 bytes from 192.168.231.3: icmp_seq=3 ttl=64 time=0.058 ms
64 bytes from 192.168.231.3: icmp_seq=4 ttl=64 time=0.048 ms
64 bytes from 192.168.231.3: icmp_seq=5 ttl=64 time=0.058 ms
64 bytes from 192.168.231.3: icmp_seq=6 ttl=64 time=0.048 ms
64 bytes from 192.168.231.3: icmp_seq=7 ttl=64 time=0.058 ms
^C
--- 192.168.231.3 ping statistics ---
7 packets transmitted, 7 received, 0% packet loss, time 6123ms
rtt min/avg/max/mdev = 0.048/0.057/0.074/0.008 ms
(this is new router IP address)
boza@redmoon:~/work
$ ping 192.168.231.5
PING 192.168.231.5 (192.168.231.5) 56(84) bytes of data.
64 bytes from 192.168.231.5: icmp_seq=1 ttl=64 time=0.445 ms
64 bytes from 192.168.231.5: icmp_seq=2 ttl=64 time=0.381 ms
64 bytes from 192.168.231.5: icmp_seq=3 ttl=64 time=0.384 ms
64 bytes from 192.168.231.5: icmp_seq=4 ttl=64 time=0.360 ms
64 bytes from 192.168.231.5: icmp_seq=5 ttl=64 time=0.376 ms
64 bytes from 192.168.231.5: icmp_seq=6 ttl=64 time=0.403 ms
^C
--- 192.168.231.5 ping statistics ---
6 packets transmitted, 6 received, 0% packet loss, time 5107ms
rtt min/avg/max/mdev = 0.360/0.391/0.445/0.027 ms
So ping work as expected but when i look on my mobile phone and
connect wirelesly to router and on phone I look with browser at
address 192.168.31.1 (this is addres router is using when i look
from phone) it show me that I can connet from mobile phone to router
(with green line on the picture it shows) but I can not connect
to internet (it shows red line from router to internet)
I hope someone will be able to give me some hint how to solve
this issue and be able to connect to internet from router - and
connected phone.
Martin
[toc] | [next] | [standalone]
| From | Geert Stappers <stappers@stappers.nl> |
|---|---|
| Date | 2023-10-25 07:00 +0200 |
| Message-ID | <HsE9P-FTn-5@gated-at.bofh.it> |
| In reply to | #262696 |
On Wed, Oct 25, 2023 at 06:15:00AM +0200, Martin wrote:
> Hello,
>
snip
>
> I tried lot of setup and none worked.
And also missed https://lists.debian.org/debian-user/2023/10/msg00684.html
and https://lists.debian.org/debian-user/2023/10/msg00685.html
and https://lists.debian.org/debian-user/2023/10/msg00688.html
and https://lists.debian.org/debian-user/2023/10/msg00690.html
It is not how it works
Groeten
Geert Stappers
--
Silence is hard to parse
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-25 07:50 +0200 |
| Message-ID | <HsEWd-Go0-1@gated-at.bofh.it> |
| In reply to | #262698 |
On Wed, Oct 25, 2023 at 06:52:09AM +0200, Geert Stappers wrote: > On Wed, Oct 25, 2023 at 06:15:00AM +0200, Martin wrote: > > I tried lot of setup and none worked. > > And also missed https://lists.debian.org/debian-user/2023/10/msg00684.html > and https://lists.debian.org/debian-user/2023/10/msg00685.html > and https://lists.debian.org/debian-user/2023/10/msg00688.html > and https://lists.debian.org/debian-user/2023/10/msg00690.html Now I am very, very embarased. When I first posted this message i got the error message back that it cculd not be delivered. So I send more same message but did not receive any response from mailing list. This is when I started looking at browser on the link https://lists.debian.org/debian-user/2023/10/threads.html but could not find my message there (note that it shows only first page of 2 pages of emails) I did not realize that this list have 2 pages, I always looked only on the first page. And so I tried to use my different email addresses that I had and post same message again few times. I also did not receive any message back from mailing list that i send (some of addresses were not subscribed to mailing list). Finaly I made a post from this address and got the message back as posted in mailing list. I guess it all boils down that I did not realized that https://lists.debian.org/debian-user/2023/10/threads.html page have 2 pages, I was always looking at first page :( Now I will hide under the rock and be ashamed. But I really do need some advice about the problem I described in (lot of the) messages I posted. Martin
[toc] | [prev] | [next] | [standalone]
| From | "Marco M." <mm@dorfdsl.de> |
|---|---|
| Date | 2023-10-25 07:30 +0200 |
| Message-ID | <HsECR-GiD-1@gated-at.bofh.it> |
| In reply to | #262696 |
Am 25.10.2023 um 06:15:00 Uhr schrieb Martin: > As it turn out I am not so bright to make this whole setup working :( > I pluged in new router to power and connected ethernet cable from my > computer to router WAN connection. (I belive this is how it should be > connected togheder) Please specify the EXACT model names and the exact wiring of your devices. Please also tell us if you use NetworkManager or /etc/network for configuration.
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-25 08:50 +0200 |
| Message-ID | <HsFSi-GXp-7@gated-at.bofh.it> |
| In reply to | #262699 |
On Wed, Oct 25, 2023 at 07:24:10AM +0200, Marco M. wrote:
>
> Please specify the EXACT model names and the exact wiring of your
> devices.
There is no other name than 'Mi Router 4C' made by Xiaomi.
2 links that I provided are for exact model I have.
(here they are again:
https://www.mi.com/global/product/mi-router-4c/
https://manuals.plus/_mi/mi-router-4c-manual)
The wiring is as folow:
a) power cable goes from wall to the far right socket
(when looking from front of modem)
b) ethernet cable is connected from my desktop to far left scoket of router.
(there are also 2 middle ethernet cable sockets which i do not use
my guess is they are for connecting other devices -like desktop- to
subnetwork that wifi router uses which is 192.168.31.X - my phone is
geting adress from this subnetwork when connected to wifi router)
> Please also tell us if you use NetworkManager or /etc/network for
> configuration.
I am using /etc/network and here is whole /etc/network/interfaces file:
auto lo
iface lo inet loopback
auto enp3s0
iface enp3s0 inet static
address 192.168.231.3
netmask 255.255.255.0
# auto wlxe8de27a5ab1c
iface wlxe8de27a5ab1c inet dhcp
wpa-ssid Thomson
wpa-psk mybigsecret
Martin
[toc] | [prev] | [next] | [standalone]
| From | "Marco M." <mm@dorfdsl.de> |
|---|---|
| Date | 2023-10-25 08:50 +0200 |
| Message-ID | <HsFSi-GXp-9@gated-at.bofh.it> |
| In reply to | #262704 |
Am 25.10.2023 um 08:45:26 Uhr schrieb Martin: > I am using /etc/network and here is whole /etc/network/interfaces > file: > > auto lo > iface lo inet loopback > > auto enp3s0 > iface enp3s0 inet static > address 192.168.231.3 > netmask 255.255.255.0 Why don't you use DHCP like your phone does? Show ip a
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-25 13:40 +0200 |
| Message-ID | <HsKoW-K88-5@gated-at.bofh.it> |
| In reply to | #262705 |
On Wed, Oct 25, 2023 at 08:47:03AM +0200, Marco M. wrote: > > Why don't you use DHCP like your phone does? Because I used this computer before I had WiFi and phone. > Show > ip a I posted output of that command to Max Nikulin email. (Do not want to to post same info twice again as first email) Martin
[toc] | [prev] | [next] | [standalone]
| From | "Marco M." <mm@dorfdsl.de> |
|---|---|
| Date | 2023-10-25 14:20 +0200 |
| Message-ID | <HsL1D-KGh-1@gated-at.bofh.it> |
| In reply to | #262715 |
Am 25.10.2023 um 13:33:48 Uhr schrieb Martin: > On Wed, Oct 25, 2023 at 08:47:03AM +0200, Marco M. wrote: > > > > Why don't you use DHCP like your phone does? > > Because I used this computer before I had WiFi and phone. Why it is a problem to change it? Do you really want to deal with manually addressing machines? > > Show > > ip a > > I posted output of that command to Max Nikulin email. > > (Do not want to to post same info twice again as first email) This is a mailing list, please keep the discussion here on the list and do not send emails directly to subscribers. Nobody else can read them.
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-25 22:20 +0200 |
| Message-ID | <HsSw9-PvT-1@gated-at.bofh.it> |
| In reply to | #262716 |
On Wed, Oct 25, 2023 at 02:15:36PM +0200, Marco M. wrote: > Am 25.10.2023 um 13:33:48 Uhr schrieb Martin: > > > On Wed, Oct 25, 2023 at 08:47:03AM +0200, Marco M. wrote: > > > > > > Why don't you use DHCP like your phone does? > > > > Because I used this computer before I had WiFi and phone. > > Why it is a problem to change it? > Do you really want to deal with manually addressing machines? I only have one computer, and now this new router. Because I only have one computer I did not feel need to use DHCP to automaticaly assing me an IP address. Martin
[toc] | [prev] | [next] | [standalone]
| From | Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> |
|---|---|
| Date | 2023-10-25 10:10 +0200 |
| Message-ID | <HsH7H-IcH-3@gated-at.bofh.it> |
| In reply to | #262696 |
Martin <martin94@cryptolab.net> writes: > Hello, > > With wifi antena I receive a (rather weak) signal that connect my > computer to internet. I have to use windsurfer antena booster > (http://members.multiweb.nl/schaaijw/windsurfer_wifi_en.pdf) > to get usable signal. So my computer have internet signal from > wifi antena - yay great thing :) > > Now I also want to connect to internet with my mobile phone! You mean you want to use some unspecified wifi signal with your phone also? Share the connection to your phone and computer? The link to this "windsurfer" doesn't work so it's a little hard to help if you can't describe what you have. > As it turn out I am not so bright to make this whole setup working :( > I pluged in new router to power and connected ethernet cable from my > computer to router WAN connection. (I belive this is how it should be > connected togheder) The WAN connection is for the internet, not your computer. It says as much in the Xiaomi manual. > While I was seting up router as described in > https://manuals.plus/_mi/mi-router-4c-manual > in Step 2 (point 3) it said I do not have internet. > So I choose to manualy set up 'Static address' for > router as folows (my computer has IP address 192.168.231.3): > > IP address: 192.168.231.5 > Subnet mask: 255.255.255.0 > Default gateway: 192.168.231.3 > DNS: 192.168.231.3 > > After all this setup I could issue those commands on my desktop: > > (this is my desktop IP address - just to show it works) So you created a LAN between your computer and the router. > I hope someone will be able to give me some hint how to solve > this issue and be able to connect to internet from router - and > connected phone. You have some kind of mysterious internet connection from something. That needs to connect to the router's WAN port.
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-10-25 10:20 +0200 |
| Message-ID | <HsHhn-Igc-7@gated-at.bofh.it> |
| In reply to | #262708 |
On 25/10/2023 15:04, Anssi Saari wrote:
> You have some kind of mysterious internet connection from something.
> That needs to connect to the router's WAN port.
My guess is the following:
- Source of weak WiFi
- WiFi booster
- WiFi adapter in computer
- ethernet port in computer
- ethernet port of Mi router
- WiFi provided by Mi router
- WiFi adapter inside the phone
So packet forwarding should be enabled on the computer. However I
suspect an issue with IP addresses. Martin, please, provide output of
ip address list
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-25 13:30 +0200 |
| Message-ID | <HsKff-K4Q-5@gated-at.bofh.it> |
| In reply to | #262709 |
On Wed, Oct 25, 2023 at 03:17:09PM +0700, Max Nikulin wrote:
> On 25/10/2023 15:04, Anssi Saari wrote:
> > You have some kind of mysterious internet connection from something.
> > That needs to connect to the router's WAN port.
>
> My guess is the following:
>
> - Source of weak WiFi
> - WiFi booster
> - WiFi adapter in computer
> - ethernet port in computer
> - ethernet port of Mi router
> - WiFi provided by Mi router
> - WiFi adapter inside the phone
>
> So packet forwarding should be enabled on the computer. However I suspect an
> issue with IP addresses. Martin, please, provide output of
>
> ip address list
You are absolutely correct with your guess - although it take me
some time to understand what you are talking about - which is all my
fault.
here is result of 'ip address list' and also 'ip route' command:
$ ip address list
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host noprefixroute
valid_lft forever preferred_lft forever
2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether e0:d5:5e:73:c9:d3 brd ff:ff:ff:ff:ff:ff
inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
valid_lft forever preferred_lft forever
inet6 fe80::e2d5:5eff:fe73:c9d3/64 scope link proto kernel_ll
valid_lft forever preferred_lft forever
3: wlxe8de27a5ab1c: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether e8:de:27:a5:ab:1c brd ff:ff:ff:ff:ff:ff
inet 192.168.0.16/24 brd 192.168.0.255 scope global dynamic wlxe8de27a5ab1c
valid_lft 535000sec preferred_lft 535000sec
inet6 fe80::eade:27ff:fea5:ab1c/64 scope link proto kernel_ll
valid_lft forever preferred_lft forever
4: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether 02:42:42:5b:a7:3b brd ff:ff:ff:ff:ff:ff
inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
valid_lft forever preferred_lft forever
5: br-7bfdce95ff27: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether 02:42:52:ec:22:75 brd ff:ff:ff:ff:ff:ff
inet 172.18.0.1/16 brd 172.18.255.255 scope global br-7bfdce95ff27
valid_lft forever preferred_lft forever
6: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
link/none
inet 10.1.1.1/24 scope global tun0
valid_lft forever preferred_lft forever
inet6 fe80::f84d:e9fc:4ea5:f7fa/64 scope link stable-privacy proto kernel_ll
valid_lft forever preferred_lft forever
$ ip route
default via 192.168.0.1 dev wlxe8de27a5ab1c
10.1.1.0/24 dev tun0 proto kernel scope link src 10.1.1.1
172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdown
172.18.0.0/16 dev br-7bfdce95ff27 proto kernel scope link src 172.18.0.1 linkdown
192.168.0.0/24 dev wlxe8de27a5ab1c proto kernel scope link src 192.168.0.16
192.168.231.0/24 dev enp3s0 proto kernel scope link src 192.168.231.3
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-10-25 14:40 +0200 |
| Message-ID | <HsLkZ-KRP-1@gated-at.bofh.it> |
| In reply to | #262714 |
On 25/10/2023 18:24, Martin wrote:
> On Wed, Oct 25, 2023 at 03:17:09PM +0700, Max Nikulin wrote:
>>
>> So packet forwarding should be enabled on the computer.
sysctl net.ipv4.ip_forward
almost certainly enabled since you have the docker0 network interface
>> However I suspect an issue with IP addresses.
I was wrong.
> 2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
> link/ether e0:d5:5e:73:c9:d3 brd ff:ff:ff:ff:ff:ff
> inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
[...]
> 3: wlxe8de27a5ab1c: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
> link/ether e8:de:27:a5:ab:1c brd ff:ff:ff:ff:ff:ff
> inet 192.168.0.16/24 brd 192.168.0.255 scope global dynamic wlxe8de27a5ab1c
looks consistent from router settings you posted earlier
> IP address: 192.168.231.5
> Subnet mask: 255.255.255.0
> Default gateway: 192.168.231.3
> DNS: 192.168.231.3
I hope, you have a DNS server running on this machine
dig debian.org @192.168.231.3
or
host debian.org 192.168.231.3
Check that you do not have blocking rules in firewall and that
masquerading is enabled for your downstream link enp3s0
nft list ruleset
should have something like
table ip sharedconnection {
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
}
}
A tool for further debugging is tcpdump or wireshark.
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-25 21:30 +0200 |
| Message-ID | <HsRJL-OYs-3@gated-at.bofh.it> |
| In reply to | #262719 |
On Wed, Oct 25, 2023 at 07:33:52PM +0700, Max Nikulin wrote:
> On 25/10/2023 18:24, Martin wrote:
> > On Wed, Oct 25, 2023 at 03:17:09PM +0700, Max Nikulin wrote:
> > >
> > > So packet forwarding should be enabled on the computer.
>
> sysctl net.ipv4.ip_forward
>
> almost certainly enabled since you have the docker0 network interface
You are right, it is enabled:
$ sudo sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 1
> I hope, you have a DNS server running on this machine
>
> host debian.org 192.168.231.3
I did not had dig installed but host worked, alas it showed me that I do
not have installed DNS server. So I installed dnsmasq package and
wonders happened (without me editing any config files - just installing
dnsmasq) - on my mobile phone when I connected to 192.168.31.1 address
(default router address when I look from phone) It showed now green line
from router to internet.
But unfortunatelly phone does not connect to internet yet. I guess I will
need to issue some 'sudo route' command to add path from my router to
outside world (actually I do not have idea if this is the problem).
> Check that you do not have blocking rules in firewall
I do not use firewall anymore, since I stoped using wired home phone
(dialup modem) to connect to internet with ppp protocol. Since I am now
connected to internet via my weak antena which is connected to router(A)
and then to internet I know that distant router(A) is protected enough
(after all it uses only local address that i can see 192.168.0.1).
> and that masquerading
> is enabled for your downstream link enp3s0
>
> nft list ruleset
>
> should have something like
>
> table ip sharedconnection {
> chain postrouting {
> type nat hook postrouting priority srcnat; policy accept;
> ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
> }
> }
I did not add any masquerading rules by myself and output of command
'nft list ruleset' is showed below. It does not have anything like you
showed in section 'table ip sharedconnection'. I remember using iptables
command to make firewall and masquerading my computer while I was using
dialup modem internet connection. I do not set up use any iptable rules
manualy anymore.
So this is probably what I need to figure out how to use masquerading
and other firewall rules to enable my new router to connect to outside
internet. (I must admit that I forgot what rules should I use to enable
this setup - so I need your help)
Here is output of 'nft list ruleset' 'iptables -S' and 'iptables -L' command:
(I am not sure they provide different info, but here they are)
Thanks a lot
Martin
$ sudo nft list ruleset
# Warning: table ip nat is managed by iptables-nft, do not touch!
table ip nat {
chain DOCKER {
iifname "docker0" counter packets 0 bytes 0 return
iifname "br-7bfdce95ff27" counter packets 0 bytes 0 return
}
chain POSTROUTING {
type nat hook postrouting priority srcnat; policy accept;
oifname "wlxe8de27a5ab1c" ip saddr 10.1.1.0/24 counter packets 192 bytes 11818 masquerade
oifname != "docker0" ip saddr 172.17.0.0/16 counter packets 0 bytes 0 masquerade
oifname != "br-7bfdce95ff27" ip saddr 172.18.0.0/16 counter packets 0 bytes 0 masquerade
}
chain PREROUTING {
type nat hook prerouting priority dstnat; policy accept;
fib daddr type local counter packets 7727 bytes 479748 jump DOCKER
}
chain OUTPUT {
type nat hook output priority dstnat; policy accept;
ip daddr != 127.0.0.0/8 fib daddr type local counter packets 3 bytes 196 jump DOCKER
}
}
# Warning: table ip filter is managed by iptables-nft, do not touch!
table ip filter {
chain DOCKER {
}
chain DOCKER-ISOLATION-STAGE-1 {
iifname "docker0" oifname != "docker0" counter packets 0 bytes 0 jump DOCKER-ISOLATION-STAGE-2
iifname "br-7bfdce95ff27" oifname != "br-7bfdce95ff27" counter packets 0 bytes 0 jump DOCKER-ISOLATION-STAGE-2
counter packets 27 bytes 1780 return
}
chain DOCKER-ISOLATION-STAGE-2 {
oifname "docker0" counter packets 0 bytes 0 drop
oifname "br-7bfdce95ff27" counter packets 0 bytes 0 drop
counter packets 0 bytes 0 return
}
chain FORWARD {
type filter hook forward priority filter; policy drop;
counter packets 57740 bytes 51358193 accept
counter packets 25 bytes 1644 jump DOCKER-USER
counter packets 25 bytes 1644 jump DOCKER-ISOLATION-STAGE-1
oifname "docker0" ct state related,established counter packets 0 bytes 0 accept
oifname "docker0" counter packets 0 bytes 0 jump DOCKER
iifname "docker0" oifname != "docker0" counter packets 0 bytes 0 accept
iifname "docker0" oifname "docker0" counter packets 0 bytes 0 accept
oifname "br-7bfdce95ff27" ct state related,established counter packets 0 bytes 0 accept
oifname "br-7bfdce95ff27" counter packets 0 bytes 0 jump DOCKER
iifname "br-7bfdce95ff27" oifname != "br-7bfdce95ff27" counter packets 0 bytes 0 accept
iifname "br-7bfdce95ff27" oifname "br-7bfdce95ff27" counter packets 0 bytes 0 accept
}
chain DOCKER-USER {
counter packets 25 bytes 1644 return
}
}
$ sudo iptables -S
-P INPUT ACCEPT
-P FORWARD DROP
-P OUTPUT ACCEPT
-N DOCKER
-N DOCKER-ISOLATION-STAGE-1
-N DOCKER-ISOLATION-STAGE-2
-N DOCKER-USER
-A FORWARD -m comment --comment simple_rt -j ACCEPT
-A FORWARD -j DOCKER-USER
-A FORWARD -j DOCKER-ISOLATION-STAGE-1
-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o docker0 -j DOCKER
-A FORWARD -i docker0 ! -o docker0 -j ACCEPT
-A FORWARD -i docker0 -o docker0 -j ACCEPT
-A FORWARD -o br-7bfdce95ff27 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -o br-7bfdce95ff27 -j DOCKER
-A FORWARD -i br-7bfdce95ff27 ! -o br-7bfdce95ff27 -j ACCEPT
-A FORWARD -i br-7bfdce95ff27 -o br-7bfdce95ff27 -j ACCEPT
-A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -i br-7bfdce95ff27 ! -o br-7bfdce95ff27 -j DOCKER-ISOLATION-STAGE-2
-A DOCKER-ISOLATION-STAGE-1 -j RETURN
-A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -o br-7bfdce95ff27 -j DROP
-A DOCKER-ISOLATION-STAGE-2 -j RETURN
-A DOCKER-USER -j RETURN
$ sudo iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere /* simple_rt */
DOCKER-USER all -- anywhere anywhere
DOCKER-ISOLATION-STAGE-1 all -- anywhere anywhere
ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
DOCKER all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
DOCKER all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain DOCKER (2 references)
target prot opt source destination
Chain DOCKER-ISOLATION-STAGE-1 (1 references)
target prot opt source destination
DOCKER-ISOLATION-STAGE-2 all -- anywhere anywhere
DOCKER-ISOLATION-STAGE-2 all -- anywhere anywhere
RETURN all -- anywhere anywhere
Chain DOCKER-ISOLATION-STAGE-2 (2 references)
target prot opt source destination
DROP all -- anywhere anywhere
DROP all -- anywhere anywhere
RETURN all -- anywhere anywhere
Chain DOCKER-USER (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-10-26 05:00 +0200 |
| Message-ID | <HsYLf-Tci-5@gated-at.bofh.it> |
| In reply to | #262725 |
On 26/10/2023 02:20, Martin wrote:
> On Wed, Oct 25, 2023 at 07:33:52PM +0700, Max Nikulin wrote:
>> should have something like
>>
>> table ip sharedconnection {
>> chain postrouting {
>> type nat hook postrouting priority srcnat; policy accept;
>> ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
>> }
>> }
> I did not add any masquerading rules by myself and output of command
> 'nft list ruleset' is showed below. It does not have anything like you
> showed in section 'table ip sharedconnection'.
"sharedconnection" is an arbitrary name. It should be chosen to not
conflict with other applications. Actually you have nat masquerading
rules created by docker for other interfaces. Read
/usr/share/doc/nftables/README.Debian and choose a convenient for you
way to add rules. You may add the following heading and may save rules
to a file that may be read by either "nft -f FILE.conf" or just
executing it.
#!/usr/sbin/nft -f
table inet sharedconnection {}
flush table inet sharedconnection
# table ip shared connection { ... } from above
---
Upstream WiFi router does not know that packets addressed to
192.168.231.5 (mi router) should be sent to your computer
(192.168.0.16), so you computer should make upstream router believing
that all packets from your phone originates from 192.168.0.16.
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-10-26 12:10 +0200 |
| Message-ID | <Ht5tn-Y6R-1@gated-at.bofh.it> |
| In reply to | #262736 |
On Thu, Oct 26, 2023 at 09:54:22AM +0700, Max Nikulin wrote:
> On 26/10/2023 02:20, Martin wrote:
> > On Wed, Oct 25, 2023 at 07:33:52PM +0700, Max Nikulin wrote:
> > > should have something like
> > >
> > > table ip sharedconnection {
> > > chain postrouting {
> > > type nat hook postrouting priority srcnat; policy accept;
> > > ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
> > > }
> > > }
>
> "sharedconnection" is an arbitrary name. It should be chosen to not conflict
> with other applications. Actually you have nat masquerading rules created by
> docker for other interfaces. Read /usr/share/doc/nftables/README.Debian and
> choose a convenient for you way to add rules. You may add the following
> heading and may save rules to a file that may be read by either "nft -f
> FILE.conf" or just executing it.
>
> #!/usr/sbin/nft -f
> table inet sharedconnection {}
> flush table inet sharedconnection
> # table ip shared connection { ... } from above
I did create FILE.conf and after executing it I can connect to internet from
my phone. THANK YOU!
Now where do I put this FILE.conf? I would like for it to run everytime
I turn on my computer. Is there some standard place for it - perhaps in
/etc directory? Maybe i should create some script in /etc/init.d/
directory?
Martin
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-10-26 17:10 +0200 |
| Message-ID | <Hta9I-11mN-5@gated-at.bofh.it> |
| In reply to | #262744 |
On 26/10/2023 17:06, Martin wrote:
> On Thu, Oct 26, 2023 at 09:54:22AM +0700, Max Nikulin wrote:
>>
>> #!/usr/sbin/nft -f
>> table inet sharedconnection {}
>> flush table inet sharedconnection
>> # table ip shared connection { ... } from above
>
> I did create FILE.conf and after executing it I can connect to internet from
> my phone. THANK YOU!
>
> Now where do I put this FILE.conf? I would like for it to run everytime
> I turn on my computer.
I wrote "FILE" in caps trying to express that you can choose any name.
Debian has /etc/nftables.conf and nft supports the "include" directive,
see nft(8). So you may put your file to /etc or to create a dedicated
directory, e.g. /etc/nftables.conf.d, for your settings and include your
file from the main conf file, so it should be applied on each boot by
nftables.service. You may put "table ip shared ..." content directly
into /etc/nftables.conf as well, however I prefer to minimize changes in
files provided by packages when it is possible to use additional ones.
Instead of installing dnsmasq you may specify a public dns server in
your router settings (8.8.8.8, etc.). Or if you are sure that DNS
configuration provided by the upstream router 192.168.0.1 is stable then
you may use servers from DHCP lease. However having a local caching DNS
server (dnsmasq or systemd-resolved) should not harm.
By the way, since you have dnsmasq running, you may enable its DHCP
server (dhcp-range=192.168.231.5,192.168.231.254) and may switch mi
router from static network configuration to DHCP.
As a final note, NetworkManager allows to create "shared" connections
(ipv4.method). It starts dnsmasq and adds necessary firewall nat rules.
I used it in both directions: with ethernet upstream connection to share
wifi or to leverage 1G ethernet link to copy files between laptops while
one of them has an active wifi connection.
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-11-04 20:10 +0100 |
| Message-ID | <HwubT-38lr-5@gated-at.bofh.it> |
| In reply to | #262750 |
On Thu, Oct 26, 2023 at 10:00:08PM +0700, Max Nikulin wrote:
> On 26/10/2023 17:06, Martin wrote:
> > On Thu, Oct 26, 2023 at 09:54:22AM +0700, Max Nikulin wrote:
> > >
> > > #!/usr/sbin/nft -f
> > > table inet sharedconnection {}
> > > flush table inet sharedconnection
> > > table ip sharedconnection { ... } from above
> I wrote "FILE" in caps trying to express that you can choose any name.
> Debian has /etc/nftables.conf and nft supports the "include" directive, see
> nft(8). So you may put your file to /etc or to create a dedicated directory,
> e.g. /etc/nftables.conf.d, for your settings and include your file from the
> main conf file, so it should be applied on each boot by nftables.service.
> You may put "table ip shared ..." content directly into /etc/nftables.conf
> as well, however I prefer to minimize changes in files provided by packages
> when it is possible to use additional ones.
> By the way, since you have dnsmasq running, you may enable its DHCP server
> (dhcp-range=192.168.231.5,192.168.231.254) and may switch mi router from
> static network configuration to DHCP.
Sorry for long pause in reply (my hard disk was dieing so I replaced HD and
installed whole debian from scratch).
Now (after reinstall everything) I am the point where I want to make my
router to work. I set up dnsmasq to enable DHCP with line in config:
dhcp-range=192.168.231.241,192.168.231.254,12h
and reseted my WiFi router after little configuring with my phone I can
connect my phone to WiFi router and to my computer (that still has address
192.168.231.3). I can access http server on my computer when I type in my
phone address to connect in web browser: http://192.168.231.3/text.html
(I created on my computer file /var/www/html/test.html)
That is all without changing anything with nft program.
I created a file with exatly this content:
#!/usr/sbin/nft -f
table ip masqrule {}
flush table ip masqrule
table ip masqrule {
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
}
}
When I execute this file with sudo unfortunately nothing changes, I can
not connect to the internet (trying www.google.com from phone).
[[ this is about old system I had on old HD:
I remeber before reinstalling whole system at this point I had connection
from my phone to the internet (I could see google and then some videos on
youtube worked too on the phone) After I rebooted my old system I could not
connect to internet anymore from the phone. I slightly changed the script
from your post to current state (namely using ip allways instead of inet at
first two lines of script and using 'masqrule'as table name) I thing those
changes are ok.
]]
I have no idea what else should I try to make this work. Maybe I forgot
to issue some command (but I do not think so).
BTW putting above script into /etc/nftables.conf (at the bottom of file)
did not ever worked - I had always to run that file manualy as root.
Command 'nft list ruleset' only then showed this table.
I have no idea why. To me it seemed as if /etc/nftables.conf file
was not executed (I have rebooted many times so this file should run).
Bye
Martin
My current network connections, and 'ip route' command:
(I see 2 changes from my prevoius setup: missing tun0 and br-7bfdce95ff27
they were before created automaticaly so I hope it does not matter they
are not present now - both where doing local addresses 10.1.1.1/24 and
172.18.0.1/16, maybe they will appeear when I install more programs from
repository - i am not worried about them, just mentioning to be complete)
root@redmoon:~# ip address list
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host noprefixroute
valid_lft forever preferred_lft forever
2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether e0:d5:5e:73:c9:d3 brd ff:ff:ff:ff:ff:ff
inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
valid_lft forever preferred_lft forever
inet6 fe80::e2d5:5eff:fe73:c9d3/64 scope link proto kernel_ll
valid_lft forever preferred_lft forever
3: wlxe8de27a5ab1c: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether e8:de:27:a5:ab:1c brd ff:ff:ff:ff:ff:ff
inet 192.168.0.16/24 brd 192.168.0.255 scope global dynamic wlxe8de27a5ab1c
valid_lft 591334sec preferred_lft 591334sec
inet6 fe80::eade:27ff:fea5:ab1c/64 scope link proto kernel_ll
valid_lft forever preferred_lft forever
4: docker0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
link/ether 02:42:33:88:62:ce brd ff:ff:ff:ff:ff:ff
inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0
valid_lft forever preferred_lft forever
root@redmoon:~# ip route
default via 192.168.0.1 dev wlxe8de27a5ab1c
172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdown
192.168.0.0/24 dev wlxe8de27a5ab1c proto kernel scope link src 192.168.0.16
192.168.231.0/24 dev enp3s0 proto kernel scope link src 192.168.231.3
[toc] | [prev] | [next] | [standalone]
| From | Tixy <tixy@yxit.co.uk> |
|---|---|
| Date | 2023-11-05 07:50 +0100 |
| Message-ID | <HwF7j-3f5H-9@gated-at.bofh.it> |
| In reply to | #263124 |
On Sat, 2023-11-04 at 20:08 +0100, Martin wrote: [...] > BTW putting above script into /etc/nftables.conf (at the bottom of file) > did not ever worked - I had always to run that file manualy as root. > Command 'nft list ruleset' only then showed this table. > I have no idea why. To me it seemed as if /etc/nftables.conf file > was not executed (I have rebooted many times so this file should run). [...] Did you enable the nftables service? To do that, use: # systemctl enable nftables.service and to see status of the service # systemctl status nftables.service -- Tixy
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-11-05 17:00 +0100 |
| Message-ID | <HwNHz-3kzp-7@gated-at.bofh.it> |
| In reply to | #263141 |
On 05/11/2023 13:48, Tixy wrote:
> On Sat, 2023-11-04 at 20:08 +0100, Martin wrote:
> [...]
>> BTW putting above script into /etc/nftables.conf (at the bottom of file)
>> did not ever worked - I had always to run that file manualy as root.
>> Command 'nft list ruleset' only then showed this table.
>> I have no idea why. To me it seemed as if /etc/nftables.conf file
>> was not executed (I have rebooted many times so this file should run).
> [...]
>
> Did you enable the nftables service? To do that, use:
>
> # systemctl enable nftables.service
>
> and to see status of the service
>
> # systemctl status nftables.service
It should be checked first and
journalctl -b -u nftables.service
alongside with searching for any nft messages in "journalctl -b". I
suggested earlier to read /usr/share/doc/nftables/README.Debian It
explicitly recommends to enable the service.
> 2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
> inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
I hope, your router allows to view configuration received from the DHCP
server. Since static addresses were working (and it can be rechecked), I
guess, gateway is not explicitly configured, so the router tries to send
packets to 192.168.231.1. Either change the interface IP or configure
dnsmasq to send 192.168.231.3.
To debug run wireshark or tcpdump on enp3s0 and wlxe8de27a5ab1c to check
that packets from the phone are properly received and routed.
Warning: if you have not configured network interfaces for DHCP in
dnsmasq then do it. Otherwise other computers connected to the upstream
WiFi link may receive DHCP leases emitted from wlxe8de27a5ab1c.
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web