Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #262696 > unrolled thread

How do I connect my new wifi router (Mi Router 4C)?

Started byMartin <martin94@cryptolab.net>
First post2023-10-25 06:20 +0200
Last post2023-10-26 01:30 +0200
Articles 7 on this page of 27 — 7 participants

Back to article view | Back to linux.debian.user


Contents

  How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 06:20 +0200
    Re: How do I connect my new wifi router (Mi Router 4C)? Geert Stappers <stappers@stappers.nl> - 2023-10-25 07:00 +0200
      Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 07:50 +0200
    Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 07:30 +0200
      Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 08:50 +0200
        Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 08:50 +0200
          Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:40 +0200
            Re: How do I connect my new wifi router (Mi Router 4C)? "Marco M." <mm@dorfdsl.de> - 2023-10-25 14:20 +0200
              Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 22:20 +0200
    Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-10-25 10:10 +0200
      Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 10:20 +0200
        Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 13:30 +0200
          Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-25 14:40 +0200
            Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-25 21:30 +0200
              Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 05:00 +0200
                Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-10-26 12:10 +0200
                  Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-10-26 17:10 +0200
                    Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-04 20:10 +0100
                      Re: How do I connect my new wifi router (Mi Router 4C)? Tixy <tixy@yxit.co.uk> - 2023-11-05 07:50 +0100
                        Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-05 17:00 +0100
                          Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-08 14:50 +0100
                            Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-09 11:30 +0100
                            Re: How do I connect my new wifi router (Mi Router 4C)? Max Nikulin <manikulin@gmail.com> - 2023-11-09 15:50 +0100
                        Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
                      Re: How do I connect my new wifi router (Mi Router 4C)? Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-05 09:30 +0100
                        Re: How do I connect my new wifi router (Mi Router 4C)? Martin <martin94@cryptolab.net> - 2023-11-05 22:50 +0100
      Re: How do I connect my new wifi router (Mi Router 4C)? David Wright <deblis@lionunicorn.co.uk> - 2023-10-26 01:30 +0200

Page 2 of 2 — ← Prev page 1 [2]


#263258

FromMartin <martin94@cryptolab.net>
Date2023-11-08 14:50 +0100
Message-ID<HxR6p-41kr-1@gated-at.bofh.it>
In reply to#263154
On Sun, Nov 05, 2023 at 10:55:12PM +0700, Max Nikulin wrote:
> It should be checked first and
> 
>     journalctl -b -u nftables.service
> 
> alongside with searching for any nft messages in "journalctl -b". I
> suggested earlier to read /usr/share/doc/nftables/README.Debian It
> explicitly recommends to enable the service.

I just enabled it (again) now:
root@redmoon:~# systemctl enable nftables.service
Created symlink /etc/systemd/system/sysinit.target.wants/nftables.service → /lib/systemd/system/nftables.service.
root@redmoon:~# systemctl status nftables.service
○ nftables.service - nftables
     Loaded: loaded (/lib/systemd/system/nftables.service; enabled; preset: enabled)
     Active: inactive (dead)
       Docs: man:nft(8)
             http://wiki.nftables.org
root@redmoon:~# journalctl -b -u nftables.service
-- No entries --

> > 2: enp3s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
> >     inet 192.168.231.3/24 brd 192.168.231.255 scope global enp3s0
> 
> I hope, your router allows to view configuration received from the DHCP
> server. Since static addresses were working (and it can be rechecked), I
> guess, gateway is not explicitly configured, so the router tries to send
> packets to 192.168.231.1. Either change the interface IP or configure
> dnsmasq to send 192.168.231.3.

I think WiFi is configured properly (with automatic setup it does have same
settings as I did with manual settings)

Here is output from phone connected to WiFi setup program:
Connectino type: DHCP
     IP address: 192.168.231.243
    Subnet mask: 255.255.255.0
Default gateway: 192.168.231.3
            DNS: 192.168.231.3

Those are same values I was providing previously when I used manual setup too.

> To debug run wireshark or tcpdump on enp3s0 and wlxe8de27a5ab1c to check
> that packets from the phone are properly received and routed.

Well this is the part where my knowledge is thin as it can be, sadly.
I have read part of manual page for tcpdump, some web page with tutorials
and all I came with is to issue command:
$ sudo tcpdump -s 0 -i any -w  any-0.pcap
$ tcpdump -r any-0.pcap  > any-0.tcpdump

While tcpdump was recording what was going on network I issued those commands
from my phone:
connect to with browser: http://www.google.com
In terminal program that I downloaded on phone I issued those commands
(2 top ping worked third did not)
ping -c1 192.168.0.16
ping -c1 192.168.231.3
ping -c1 google.come
connect to with browser: http://192.168.231.3/test.html

The connection to www.google.com did not worked, but connection to my own
web server did showed test.html page (which I created for this)

I have run this commands 2 times once right after rebooting when my changes to
nftables where not done yet and second time after I added this to nftables:
table ip masqrule {
        chain postrouting {
                type nat hook postrouting priority srcnat; policy accept;
                ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade
        }
}

and here are the outputs of tcpdump (I did post them to pastebin as they are not tiny)
(tcpdump -r any-0-no_masq.pcap  > any-0-no_masq.tcpdump) (pastebinit -i any-0-no_masq.tcpdump)
https://paste.debian.net/hidden/be2f7994/
(tcpdump -r any-0.pcap  > any-0.tcpdump) (pastebinit -i any-0.tcpdump)
https://paste.debian.net/hidden/1589ec04/

There are also same outputs with '-n' (to print IP numbers instead of names) option too:
(tcpdump -r any-0-no_masq.pcap -n > any-0-no_masq-n.tcpdump) (pastebinit -i any-0-no_masq-n.tcpdump)
https://paste.debian.net/hidden/08ecfd39/
(tcpdump -r any-0.pcap -n > any-0-n.tcpdump) (pastebinit -i any-0-n.tcpdump)
https://paste.debian.net/hidden/a55e6f77/

Here is extract from https://paste.debian.net/hidden/a55e6f77/ that I thing is
doing connection to google:

10:47:52.614642 enp3s0 In  IP 192.168.231.243.48257 > 192.168.231.3.53: 29809+ A? www.google.com. (32)
10:47:52.614851 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.14.53: 10155+ A? www.google.com. (32)
10:47:52.614902 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.44.53: 10155+ A? www.google.com. (32)
10:47:52.791389 wlxe8de27a5ab1c In  IP 81.24.247.14.53 > 192.168.0.16.34673: 10155 1/0/0 A 142.251.208.132 (62)
10:47:52.791559 enp3s0 Out IP 192.168.231.3.53 > 192.168.231.243.48257: 29809 1/0/0 A 142.251.208.132 (62)
10:47:52.794704 enp3s0 In  IP 192.168.231.243.46639 > 142.251.208.132.80: Flags [S], seq 4183167263, win 29200, options [mss 1460,sackOK,TS val 19413 ecr 0,nop,wscale 6], length 0
10:47:52.846385 enp3s0 In  IP 192.168.231.243.46640 > 142.251.208.132.80: Flags [S], seq 1626803236, win 29200, options [mss 1460,sackOK,TS val 19418 ecr 0,nop,wscale 6], length 0
10:47:53.819034 enp3s0 In  IP 192.168.231.243.46639 > 142.251.208.132.80: Flags [S], seq 4183167263, win 29200, options [mss 1460,sackOK,TS val 19513 ecr 0,nop,wscale 6], length 0
10:47:53.843797 enp3s0 In  IP 192.168.231.243.46640 > 142.251.208.132.80: Flags [S], seq 1626803236, win 29200, options [mss 1460,sackOK,TS val 19518 ecr 0,nop,wscale 6], length 0

Last 4 lines here are similar and there I can not find any response from
server (142.251.208.132.80) to them. One thing that is suspicious to me
is that it is using 192.168.231.243 address - maybe my masquerade is not
working properly?
I would like this packet to be rewriten as if it is comming
from 192.168.231.3 (main main computer) not from 192.168.231.243.
Is that reasanoble? And how do I achieve that?


> Warning: if you have not configured network interfaces for DHCP in dnsmasq
> then do it. Otherwise other computers connected to the upstream WiFi link
> may receive DHCP leases emitted from wlxe8de27a5ab1c.

Only thing I added to dnsmasq configuration is one line in
/etc/dnsmasq.d/myHomeDHCPrange file: 
dhcp-range=192.168.231.241,192.168.231.254,12h

This seems to work as you can see above WiFi is getting address 192.168.231.243
Is there anything else I should change for dnsmasq setting?

Bye
Martin

[toc] | [prev] | [next] | [standalone]


#263280

FromAnssi Saari <anssi.saari@debian-user.mail.kapsi.fi>
Date2023-11-09 11:30 +0100
Message-ID<Hyasq-4djr-5@gated-at.bofh.it>
In reply to#263258
Martin <martin94@cryptolab.net> writes:

> I just enabled it (again) now:
> root@redmoon:~# systemctl enable nftables.service
> Created symlink /etc/systemd/system/sysinit.target.wants/nftables.service → /lib/systemd/system/nftables.service.
> root@redmoon:~# systemctl status nftables.service
> ○ nftables.service - nftables
>      Loaded: loaded (/lib/systemd/system/nftables.service; enabled; preset: enabled)
>      Active: inactive (dead)
>        Docs: man:nft(8)
>              http://wiki.nftables.org

In case it's unclear, enabling a service just means it'll be started at
boot. In practice it just creates a symlink as shown above. If you want
to start the service manually you do

systemctl start nftables.service

So if you're experimenting, you edit /etc/nftables.conf and after
editing run systemctl restart nftables.service

[toc] | [prev] | [next] | [standalone]


#263284

FromMax Nikulin <manikulin@gmail.com>
Date2023-11-09 15:50 +0100
Message-ID<Hyew1-4fDq-1@gated-at.bofh.it>
In reply to#263258
On 08/11/2023 20:39, Martin wrote:
> Here is output from phone connected to WiFi setup program:
> Default gateway: 192.168.231.3

It seems dnsmasq is able to serve reasonable settings with minimal 
configuration.

>          chain postrouting {
>                  type nat hook postrouting priority srcnat; policy accept;
>                  ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade

You had a rule that was working for you.

I do not see obvious issues with this one besides docker0 instances are 
likely inaccessible from the phone.

> 10:47:52.614642 enp3s0 In  IP 192.168.231.243.48257 > 192.168.231.3.53: 29809+ A? www.google.com. (32)
> 10:47:52.614851 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.14.53: 10155+ A? www.google.com. (32)
> 10:47:52.614902 wlxe8de27a5ab1c Out IP 192.168.0.16.34673 > 81.24.247.44.53: 10155+ A? www.google.com. (32)
> 10:47:52.791389 wlxe8de27a5ab1c In  IP 81.24.247.14.53 > 192.168.0.16.34673: 10155 1/0/0 A 142.251.208.132 (62)
> 10:47:52.791559 enp3s0 Out IP 192.168.231.3.53 > 192.168.231.243.48257: 29809 1/0/0 A 142.251.208.132 (62)
> 10:47:52.794704 enp3s0 In  IP 192.168.231.243.46639 > 142.251.208.132.80: Flags [S], seq 4183167263, win 29200, options [mss 1460,sackOK,TS val 19413 ecr 0,nop,wscale 6], length 0
> 10:47:52.846385 enp3s0 In  IP 192.168.231.243.46640 > 142.251.208.132.80: Flags [S], seq 1626803236, win 29200, options [mss 1460,sackOK,TS val 19418 ecr 0,nop,wscale 6], length 0

Since packets from wlxe8de27a5ab1c to 142.251.208.132:80 are missed, 
perhaps IP forwarding is disabled or there is a blocking forwarding rule 
in the firewall. If I am not wrong, masquerading should affect source IP 
address of forwarded packets, but not their presence.

>> Warning: if you have not configured network interfaces for DHCP in dnsmasq
>> then do it. Otherwise other computers connected to the upstream WiFi link
>> may receive DHCP leases emitted from wlxe8de27a5ab1c.
> 
> Only thing I added to dnsmasq configuration is one line in
> /etc/dnsmasq.d/myHomeDHCPrange file:
> dhcp-range=192.168.231.241,192.168.231.254,12h

Dnsmasq may be smart enough to not send DHCP leases to interfaces with 
addresses inconsistent with the specified range, but I would still limit 
interfaces that dnsmasq listens to.

On 08/11/2023 21:30, Anssi Saari wrote:
> 
> systemctl start nftables.service
> 
> So if you're experimenting, you edit /etc/nftables.conf and after
> editing run systemctl restart nftables.service

And be prepared that this command flushes away rules added by docker. It 
is a reason why earlier I suggested to create a dedicated file that may 
reload specific set of rules using "nft -f".

Current set of rules is more important than state of the service.

[toc] | [prev] | [next] | [standalone]


#263159

FromMartin <martin94@cryptolab.net>
Date2023-11-05 22:50 +0100
Message-ID<HwTah-3o4F-1@gated-at.bofh.it>
In reply to#263141
On Sun, Nov 05, 2023 at 06:48:47AM +0000, Tixy wrote:
> On Sat, 2023-11-04 at 20:08 +0100, Martin wrote:
> [...]
> > BTW putting above script into /etc/nftables.conf (at the bottom of file)
> > did not ever worked - I had always to run that file manualy as root.
> > Command 'nft list ruleset' only then showed this table.
> > I have no idea why. To me it seemed as if /etc/nftables.conf file
> > was not executed (I have rebooted many times so this file should run).
> [...]
> 
> Did you enable the nftables service? To do that, use:
> 
> # systemctl enable nftables.service
> 
> and to see status of the service
> 
> # systemctl status nftables.service

It was not enabled by default. I enabled it now.
That is great - now i know where to put script when it start working.
Unfortunately I am not there yet :(

Thank you.
Martin

[toc] | [prev] | [next] | [standalone]


#263145

FromAnssi Saari <anssi.saari@debian-user.mail.kapsi.fi>
Date2023-11-05 09:30 +0100
Message-ID<HwGG5-3g8x-3@gated-at.bofh.it>
In reply to#263124
Martin <martin94@cryptolab.net> writes:

> #!/usr/sbin/nft -f
>
> table ip masqrule {}
> flush table ip masqrule
> table ip masqrule {
>   chain postrouting {
>     type nat hook postrouting priority srcnat; policy accept;
>     ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
>   }
> }
>
> When I execute this file with sudo unfortunately nothing changes, I can
> not connect to the internet (trying www.google.com from phone).

I might guess it's because your masquerade rule does nothing. I'm not
sure though.

Anyways, a typical masquerade rule would specify the source network and
an outgoing interface. For example, I have in my Linux router:

ip saddr 10.0.2.0/24 oifname "enp1s0" masquerade

so for you that would become

ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade

[toc] | [prev] | [next] | [standalone]


#263158

FromMartin <martin94@cryptolab.net>
Date2023-11-05 22:50 +0100
Message-ID<HwTah-3o4F-3@gated-at.bofh.it>
In reply to#263145
On Sun, Nov 05, 2023 at 10:26:17AM +0200, Anssi Saari wrote:
> Anyways, a typical masquerade rule would specify the source network and
> an outgoing interface. For example, I have in my Linux router:
> 
> ip saddr 10.0.2.0/24 oifname "enp1s0" masquerade
> 
> so for you that would become
> 
> ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade

I tried this line too, unforutately it does not work either.
I mean after executing the config file with this line it shows itself in
output of command 'nft list ruleset' but I still can not connect to
internet from my phone.

I tried many lines similar to this, none works:
    ip saddr 192.168.231.3/24 ip daddr != 192.168.231.3/24 masquerade
    ip saddr 192.168.231.0/24 ip daddr != 192.168.231.0/24 masquerade
    ip saddr 192.168.231.0/24 oifname "wlxe8de27a5ab1c" masquerade
    oifname "wlxe8de27a5ab1c" masquerade

I also noticed in output of 'nft list ruleset' that other rules there are
using capitalized letter so i try it too:
istead of       chain postrouting {
I used          chain POSTROUTING {

I also tried to put this command in table that already exist instead of
creating new one (masqrule) - instead of running my whole script I run
only one command (after reboot so there are no more changes made by me before):

nft add rule ip nat POSTROUTING oifname  wlxe8de27a5ab1c  masquerade

(note that here I used 'ip nat' table that is added autmaticaly by
docker server i guess)

Since nothing I tried does work I guess my next step should be to see
where/how those packets from phone are handled. I guess program for that
is tcpdump which I have installed. But since I am unfamiliar with this tool
I would need help from mailing list to guide me what to look for and how
to use this tool.

So please can you give me some info what command should I use with
tcpdump to see where packets from phone are going - or why they do not
go where they should?

Just a reminder - I can connect from phone to my computers web server - which
I also installed just for debugging this. The problem is I can not connect from
phone to internet (let say google.com)

Martin

[toc] | [prev] | [next] | [standalone]


#262728

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2023-10-26 01:30 +0200
Message-ID<HsVu1-RiZ-1@gated-at.bofh.it>
In reply to#262708
On Wed 25 Oct 2023 at 11:04:59 (+0300), Anssi Saari wrote:
> Martin <martin94@cryptolab.net> writes:
> > With wifi antena I receive a (rather weak) signal that connect my
> > computer to internet. I have to use windsurfer antena booster
> > (http://members.multiweb.nl/schaaijw/windsurfer_wifi_en.pdf)
> > to get usable signal. So my computer have internet signal from
> > wifi antena - yay great thing :)
> >
> > Now I also want to connect to internet with my mobile phone!
> 
> You mean you want to use some unspecified wifi signal with your phone
> also? Share the connection to your phone and computer? The link to this
> "windsurfer" doesn't work so it's a little hard to help if you can't
> describe what you have.

I presume what's going on here is that the Internet is provided by
a wifi access point that is distant and inaccessible (say, next door).
The windsurfer is a shaped piece of aluminium foil that pops over the
aerial to make a sort of parabola. Normally, you'd put this over your
modem/router's (external) aerial to increase the signal transmitted to
parts of your house (though it decreases it in the opposite direction).
But I'm guessing that here the windsurfer is on the computer's wifi
aerial, to improve the received signal.

That's why the OP's router (which, again presumably, has no Internet
Service) is connected "backwards", so the computer is the WAN, and
the mobile phone is the sole device on the LAN.

IOW Max's reply represents a string↔of↔connected↔devices rather than
- a
- bullet
- list.

> You have some kind of mysterious internet connection from
> something. That needs to connect to the router's WAN port.

That's how I would cascade two routers: a LAN port on the main
router connects by a plumbed-in Cat5 cable to a port on the
secondary router. The latter port would be the WAN connection,
but that's broken on mine, so I have to connect the cable to
a LAN port. I guess that makes my secondary router a switch?

Cheers,
David.

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | linux.debian.user


csiph-web