Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #262696 > unrolled thread
| Started by | Martin <martin94@cryptolab.net> |
|---|---|
| First post | 2023-10-25 06:20 +0200 |
| Last post | 2023-10-26 01:30 +0200 |
| Articles | 7 on this page of 27 — 7 participants |
Back to article view | Back to linux.debian.user
How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 06:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Geert Stappers <stappers@stappers.nl> - 2023-10-25 07:00 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 07:50 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 07:30 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 08:50 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 08:50 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:40 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 14:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 22:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-10-25 10:10 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 10:20 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:30 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 14:40 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 21:30 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 05:00 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-26 12:10 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 17:10 +0200
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-04 20:10 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Tixy <tixy@yxit.co.uk> - 2023-11-05 07:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-05 17:00 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-08 14:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-09 11:30 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-09 15:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-05 09:30 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
Re: How do I connect my new wifi router (Mi Router 4C)? David Wright <deblis@lionunicorn.co.uk> - 2023-10-26 01:30 +0200
Page 2 of 2 — ← Prev page 1 [2]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-11-08 14:50 +0100 |
| Message-ID | <HxR6p-41kr-1@gated-at.bofh.it> |
| In reply to | #263154 |
On Sun, Nov 05, 2023 at 10:55:12PM +0700, Max Nikulin wrote:
> It should be checked first and
>
> journalctl -b -u nftables.service
>
> alongside with searching for any nft messages in "journalctl -b". I
> suggested earlier to read /usr/share/doc/nftables/README.Debian It
> explicitly recommends to enable the service.
I just enabled it (again) now:
root@redmoon:~# systemctl enable nftables.service
Created symlink /etc/systemd/system/sysinit.target.wants/nftables.service → /lib/systemd/system/nftables.service.
root@redmoon:~# systemctl status nftables.service
○ nftables.service - nftables
Loaded: loaded (/lib/systemd/system/nftables.service; enabled; preset: enabled)
Active: inactive (dead)
Docs: man:nft(8)
http://wiki.nftables.org
root@redmoon:~# journalctl -b -u nftables.service
-- No entries --
> > 2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
> > inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
>
> I hope, your router allows to view configuration received from the DHCP
> server. Since static addresses were working (and it can be rechecked), I
> guess, gateway is not explicitly configured, so the router tries to send
> packets to 192.168.231.1. Either change the interface IP or configure
> dnsmasq to send 192.168.231.3.
I think WiFi is configured properly (with automatic setup it does have same
settings as I did with manual settings)
Here is output from phone connected to WiFi setup program:
Connectino type: DHCP
IP address: 192.168.231.243
Subnet mask: 255.255.255.0
Default gateway: 192.168.231.3
DNS: 192.168.231.3
Those are same values I was providing previously when I used manual setup too.
> To debug run wireshark or tcpdump on enp3s0 and wlxe8de27a5ab1c to check
> that packets from the phone are properly received and routed.
Well this is the part where my knowledge is thin as it can be, sadly.
I have read part of manual page for tcpdump, some web page with tutorials
and all I came with is to issue command:
$ sudo tcpdump -s 0 -i any -w any-0.pcap
$ tcpdump -r any-0.pcap > any-0.tcpdump
While tcpdump was recording what was going on network I issued those commands
from my phone:
connect to with browser: http://www.google.com
In terminal program that I downloaded on phone I issued those commands
(2 top ping worked third did not)
ping -c1 192.168.0.16
ping -c1 192.168.231.3
ping -c1 google.come
connect to with browser: http://192.168.231.3/test.html
The connection to www.google.com did not worked, but connection to my own
web server did showed test.html page (which I created for this)
I have run this commands 2 times once right after rebooting when my changes to
nftables where not done yet and second time after I added this to nftables:
table ip masqrule {
chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade
}
}
and here are the outputs of tcpdump (I did post them to pastebin as they are not tiny)
(tcpdump -r any-0-no_masq.pcap > any-0-no_masq.tcpdump) (pastebinit -i any-0-no_masq.tcpdump)
https://paste.debian.net/hidden/be2f7994/
(tcpdump -r any-0.pcap > any-0.tcpdump) (pastebinit -i any-0.tcpdump)
https://paste.debian.net/hidden/1589ec04/
There are also same outputs with '-n' (to print IP numbers instead of names) option too:
(tcpdump -r any-0-no_masq.pcap -n > any-0-no_masq-n.tcpdump) (pastebinit -i any-0-no_masq-n.tcpdump)
https://paste.debian.net/hidden/08ecfd39/
(tcpdump -r any-0.pcap -n > any-0-n.tcpdump) (pastebinit -i any-0-n.tcpdump)
https://paste.debian.net/hidden/a55e6f77/
Here is extract from https://paste.debian.net/hidden/a55e6f77/ that I thing is
doing connection to google:
10:47:52.614642 enp3s0 In IP 192.168.231.243.48257 > 192.168.231.3.53: 29809+ A? www.google.com. (32)
10:47:52.614851 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.14.53: 10155+ A? www.google.com. (32)
10:47:52.614902 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.44.53: 10155+ A? www.google.com. (32)
10:47:52.791389 wlxe8de27a5ab1c In IP 81.24.247.14.53 > 192.168.0.16.34673: 10155 1/0/0 A 142.251.208.132 (62)
10:47:52.791559 enp3s0 Out IP 192.168.231.3.53 > 192.168.231.243.48257: 29809 1/0/0 A 142.251.208.132 (62)
10:47:52.794704 enp3s0 In IP 192.168.231.243.46639 > 142.251.208.132.80: Flags [S], seq 4183167263, win 29200, options [mss 1460,sackOK,TS val 19413 ecr 0,nop,wscale 6], length 0
10:47:52.846385 enp3s0 In IP 192.168.231.243.46640 > 142.251.208.132.80: Flags [S], seq 1626803236, win 29200, options [mss 1460,sackOK,TS val 19418 ecr 0,nop,wscale 6], length 0
10:47:53.819034 enp3s0 In IP 192.168.231.243.46639 > 142.251.208.132.80: Flags [S], seq 4183167263, win 29200, options [mss 1460,sackOK,TS val 19513 ecr 0,nop,wscale 6], length 0
10:47:53.843797 enp3s0 In IP 192.168.231.243.46640 > 142.251.208.132.80: Flags [S], seq 1626803236, win 29200, options [mss 1460,sackOK,TS val 19518 ecr 0,nop,wscale 6], length 0
Last 4 lines here are similar and there I can not find any response from
server (142.251.208.132.80) to them. One thing that is suspicious to me
is that it is using 192.168.231.243 address - maybe my masquerade is not
working properly?
I would like this packet to be rewriten as if it is comming
from 192.168.231.3 (main main computer) not from 192.168.231.243.
Is that reasanoble? And how do I achieve that?
> Warning: if you have not configured network interfaces for DHCP in dnsmasq
> then do it. Otherwise other computers connected to the upstream WiFi link
> may receive DHCP leases emitted from wlxe8de27a5ab1c.
Only thing I added to dnsmasq configuration is one line in
/etc/dnsmasq.d/myHomeDHCPrange file:
dhcp-range=192.168.231.241,192.168.231.254,12h
This seems to work as you can see above WiFi is getting address 192.168.231.243
Is there anything else I should change for dnsmasq setting?
Bye
Martin
[toc] | [prev] | [next] | [standalone]
| From | Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> |
|---|---|
| Date | 2023-11-09 11:30 +0100 |
| Message-ID | <Hyasq-4djr-5@gated-at.bofh.it> |
| In reply to | #263258 |
Martin <martin94@cryptolab.net> writes: > I just enabled it (again) now: > root@redmoon:~# systemctl enable nftables.service > Created symlink /etc/systemd/system/sysinit.target.wants/nftables.service → /lib/systemd/system/nftables.service. > root@redmoon:~# systemctl status nftables.service > ○ nftables.service - nftables > Loaded: loaded (/lib/systemd/system/nftables.service; enabled; preset: enabled) > Active: inactive (dead) > Docs: man:nft(8) > http://wiki.nftables.org In case it's unclear, enabling a service just means it'll be started at boot. In practice it just creates a symlink as shown above. If you want to start the service manually you do systemctl start nftables.service So if you're experimenting, you edit /etc/nftables.conf and after editing run systemctl restart nftables.service
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-11-09 15:50 +0100 |
| Message-ID | <Hyew1-4fDq-1@gated-at.bofh.it> |
| In reply to | #263258 |
On 08/11/2023 20:39, Martin wrote:
> Here is output from phone connected to WiFi setup program:
> Default gateway: 192.168.231.3
It seems dnsmasq is able to serve reasonable settings with minimal
configuration.
> chain postrouting {
> type nat hook postrouting priority srcnat; policy accept;
> ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade
You had a rule that was working for you.
I do not see obvious issues with this one besides docker0 instances are
likely inaccessible from the phone.
> 10:47:52.614642 enp3s0 In IP 192.168.231.243.48257 > 192.168.231.3.53: 29809+ A? www.google.com. (32)
> 10:47:52.614851 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.14.53: 10155+ A? www.google.com. (32)
> 10:47:52.614902 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.44.53: 10155+ A? www.google.com. (32)
> 10:47:52.791389 wlxe8de27a5ab1c In IP 81.24.247.14.53 > 192.168.0.16.34673: 10155 1/0/0 A 142.251.208.132 (62)
> 10:47:52.791559 enp3s0 Out IP 192.168.231.3.53 > 192.168.231.243.48257: 29809 1/0/0 A 142.251.208.132 (62)
> 10:47:52.794704 enp3s0 In IP 192.168.231.243.46639 > 142.251.208.132.80: Flags [S], seq 4183167263, win 29200, options [mss 1460,sackOK,TS val 19413 ecr 0,nop,wscale 6], length 0
> 10:47:52.846385 enp3s0 In IP 192.168.231.243.46640 > 142.251.208.132.80: Flags [S], seq 1626803236, win 29200, options [mss 1460,sackOK,TS val 19418 ecr 0,nop,wscale 6], length 0
Since packets from wlxe8de27a5ab1c to 142.251.208.132:80 are missed,
perhaps IP forwarding is disabled or there is a blocking forwarding rule
in the firewall. If I am not wrong, masquerading should affect source IP
address of forwarded packets, but not their presence.
>> Warning: if you have not configured network interfaces for DHCP in dnsmasq
>> then do it. Otherwise other computers connected to the upstream WiFi link
>> may receive DHCP leases emitted from wlxe8de27a5ab1c.
>
> Only thing I added to dnsmasq configuration is one line in
> /etc/dnsmasq.d/myHomeDHCPrange file:
> dhcp-range=192.168.231.241,192.168.231.254,12h
Dnsmasq may be smart enough to not send DHCP leases to interfaces with
addresses inconsistent with the specified range, but I would still limit
interfaces that dnsmasq listens to.
On 08/11/2023 21:30, Anssi Saari wrote:
>
> systemctl start nftables.service
>
> So if you're experimenting, you edit /etc/nftables.conf and after
> editing run systemctl restart nftables.service
And be prepared that this command flushes away rules added by docker. It
is a reason why earlier I suggested to create a dedicated file that may
reload specific set of rules using "nft -f".
Current set of rules is more important than state of the service.
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-11-05 22:50 +0100 |
| Message-ID | <HwTah-3o4F-1@gated-at.bofh.it> |
| In reply to | #263141 |
On Sun, Nov 05, 2023 at 06:48:47AM +0000, Tixy wrote: > On Sat, 2023-11-04 at 20:08 +0100, Martin wrote: > [...] > > BTW putting above script into /etc/nftables.conf (at the bottom of file) > > did not ever worked - I had always to run that file manualy as root. > > Command 'nft list ruleset' only then showed this table. > > I have no idea why. To me it seemed as if /etc/nftables.conf file > > was not executed (I have rebooted many times so this file should run). > [...] > > Did you enable the nftables service? To do that, use: > > # systemctl enable nftables.service > > and to see status of the service > > # systemctl status nftables.service It was not enabled by default. I enabled it now. That is great - now i know where to put script when it start working. Unfortunately I am not there yet :( Thank you. Martin
[toc] | [prev] | [next] | [standalone]
| From | Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> |
|---|---|
| Date | 2023-11-05 09:30 +0100 |
| Message-ID | <HwGG5-3g8x-3@gated-at.bofh.it> |
| In reply to | #263124 |
Martin <martin94@cryptolab.net> writes:
> #!/usr/sbin/nft -f
>
> table ip masqrule {}
> flush table ip masqrule
> table ip masqrule {
> chain postrouting {
> type nat hook postrouting priority srcnat; policy accept;
> ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
> }
> }
>
> When I execute this file with sudo unfortunately nothing changes, I can
> not connect to the internet (trying www.google.com from phone).
I might guess it's because your masquerade rule does nothing. I'm not
sure though.
Anyways, a typical masquerade rule would specify the source network and
an outgoing interface. For example, I have in my Linux router:
ip saddr 10.0.2.0/24 oifname "enp1s0" masquerade
so for you that would become
ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade
[toc] | [prev] | [next] | [standalone]
| From | Martin <martin94@cryptolab.net> |
|---|---|
| Date | 2023-11-05 22:50 +0100 |
| Message-ID | <HwTah-3o4F-3@gated-at.bofh.it> |
| In reply to | #263145 |
On Sun, Nov 05, 2023 at 10:26:17AM +0200, Anssi Saari wrote:
> Anyways, a typical masquerade rule would specify the source network and
> an outgoing interface. For example, I have in my Linux router:
>
> ip saddr 10.0.2.0/24 oifname "enp1s0" masquerade
>
> so for you that would become
>
> ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade
I tried this line too, unforutately it does not work either.
I mean after executing the config file with this line it shows itself in
output of command 'nft list ruleset' but I still can not connect to
internet from my phone.
I tried many lines similar to this, none works:
ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
ip saddr 192.168.231.0/24 ip daddr != 192.168.231.0/24 masquerade
ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade
oifname "wlxe8de27a5ab1c" masquerade
I also noticed in output of 'nft list ruleset' that other rules there are
using capitalized letter so i try it too:
istead of chain postrouting {
I used chain POSTROUTING {
I also tried to put this command in table that already exist instead of
creating new one (masqrule) - instead of running my whole script I run
only one command (after reboot so there are no more changes made by me before):
nft add rule ip nat POSTROUTING oifname wlxe8de27a5ab1c masquerade
(note that here I used 'ip nat' table that is added autmaticaly by
docker server i guess)
Since nothing I tried does work I guess my next step should be to see
where/how those packets from phone are handled. I guess program for that
is tcpdump which I have installed. But since I am unfamiliar with this tool
I would need help from mailing list to guide me what to look for and how
to use this tool.
So please can you give me some info what command should I use with
tcpdump to see where packets from phone are going - or why they do not
go where they should?
Just a reminder - I can connect from phone to my computers web server - which
I also installed just for debugging this. The problem is I can not connect from
phone to internet (let say google.com)
Martin
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2023-10-26 01:30 +0200 |
| Message-ID | <HsVu1-RiZ-1@gated-at.bofh.it> |
| In reply to | #262708 |
On Wed 25 Oct 2023 at 11:04:59 (+0300), Anssi Saari wrote: > Martin <martin94@cryptolab.net> writes: > > With wifi antena I receive a (rather weak) signal that connect my > > computer to internet. I have to use windsurfer antena booster > > (http://members.multiweb.nl/schaaijw/windsurfer_wifi_en.pdf) > > to get usable signal. So my computer have internet signal from > > wifi antena - yay great thing :) > > > > Now I also want to connect to internet with my mobile phone! > > You mean you want to use some unspecified wifi signal with your phone > also? Share the connection to your phone and computer? The link to this > "windsurfer" doesn't work so it's a little hard to help if you can't > describe what you have. I presume what's going on here is that the Internet is provided by a wifi access point that is distant and inaccessible (say, next door). The windsurfer is a shaped piece of aluminium foil that pops over the aerial to make a sort of parabola. Normally, you'd put this over your modem/router's (external) aerial to increase the signal transmitted to parts of your house (though it decreases it in the opposite direction). But I'm guessing that here the windsurfer is on the computer's wifi aerial, to improve the received signal. That's why the OP's router (which, again presumably, has no Internet Service) is connected "backwards", so the computer is the WAN, and the mobile phone is the sole device on the LAN. IOW Max's reply represents a string↔of↔connected↔devices rather than - a - bullet - list. > You have some kind of mysterious internet connection from > something. That needs to connect to the router's WAN port. That's how I would cascade two routers: a LAN port on the main router connects by a plumbed-in Cat5 cable to a port on the secondary router. The latter port would be the WAN connection, but that's broken on mine, so I have to connect the cable to a LAN port. I guess that makes my secondary router a switch? Cheers, David.
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | linux.debian.user
csiph-web