Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #175966 > unrolled thread

Sub interface not working in Debian 8

Started byMuhammad Yousuf Khan <sirtcp@gmail.com>
First post2016-12-27 12:30 +0100
Last post2016-12-30 14:30 +0100
Articles 13 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-27 12:30 +0100
    Re: Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-27 12:40 +0100
    Re: Sub interface not working in Debian 8 Xen <list@xenhideout.nl> - 2016-12-27 13:40 +0100
      Re: Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-27 14:00 +0100
        Re: Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-27 14:30 +0100
          Re: Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-27 14:30 +0100
        Re: Sub interface not working in Debian 8 Xen <list@xenhideout.nl> - 2016-12-27 14:50 +0100
          Re: Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-27 15:20 +0100
            Re: Sub interface not working in Debian 8 Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-12-27 15:40 +0100
            Re: Sub interface not working in Debian 8 Xen <list@xenhideout.nl> - 2016-12-27 16:50 +0100
              Re: Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-28 08:20 +0100
                Re: Sub interface not working in Debian 8 Xen <list@xenhideout.nl> - 2016-12-28 10:20 +0100
                  Re: Sub interface not working in Debian 8 Muhammad Yousuf Khan <sirtcp@gmail.com> - 2016-12-30 14:30 +0100

#175966 — Sub interface not working in Debian 8

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-27 12:30 +0100
SubjectSub interface not working in Debian 8
Message-ID<sSY77-1nC-3@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Dear All,

I want to reach sub interface ip from internet but i can not ping no matter
what i do.


inet 50.x.x.161/28 brd 50.255.203.175 scope global eth3 valid_lft forever
preferred_lft forever

inet 50.x.x.162/28 brd 50.255.203.175 scope global secondary eth3:1
ce public ip which is set up like this

i can reach the ip address  50.x.x.161 from internet but i can not ping
50.x.x.162. i disabled the firewall but still no luck.

i can not ping from 50.x.x.161 but can not ping from 50.x.x.162. like this

hping3 -1 8.8.8.8 -a 50.255.203.161

HPING 8.8.8.8 (eth3 8.8.8.8): icmp mode set, 28 headers + 0 data bytes
len=46 ip=8.8.8.8 ttl=57 id=17110 icmp_seq=0 rtt=27.6 ms
len=46 ip=8.8.8.8 ttl=57 id=17833 icmp_seq=1 rtt=23.3 ms


 hping3 -1 8.8.8.8 -a 50.255.203.162
HPING 8.8.8.8 (eth3 8.8.8.8): icmp mode set, 28 headers + 0 data bytes
(it stays there for every)



can you guys please guide what is going on . in old Debian version i do
this with no problem sub interfaces were very easy task. but here i invest
the whole day.

Thanks,
Yousuf

[toc] | [next] | [standalone]


#175968

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-27 12:40 +0100
Message-ID<sSYgN-1qL-9@gated-at.bofh.it>
In reply to#175966

[Multipart message — attachments visible in raw view] — view raw

adding further i can ping the virtual interfaces from local network and
through vpn users
but can not ping public IPs
.

On Tue, Dec 27, 2016 at 4:22 PM, Muhammad Yousuf Khan <sirtcp@gmail.com>
wrote:

> Dear All,
>
> I want to reach sub interface ip from internet but i can not ping no
> matter what i do.
>
>
> inet 50.x.x.161/28 brd 50.255.203.175 scope global eth3 valid_lft forever
> preferred_lft forever
>
> inet 50.x.x.162/28 brd 50.255.203.175 scope global secondary eth3:1
> ce public ip which is set up like this
>
> i can reach the ip address  50.x.x.161 from internet but i can not ping
> 50.x.x.162. i disabled the firewall but still no luck.
>
> i can not ping from 50.x.x.161 but can not ping from 50.x.x.162. like this
>
> hping3 -1 8.8.8.8 -a 50.255.203.161
>
> HPING 8.8.8.8 (eth3 8.8.8.8): icmp mode set, 28 headers + 0 data bytes
> len=46 ip=8.8.8.8 ttl=57 id=17110 icmp_seq=0 rtt=27.6 ms
> len=46 ip=8.8.8.8 ttl=57 id=17833 icmp_seq=1 rtt=23.3 ms
>
>
>  hping3 -1 8.8.8.8 -a 50.255.203.162
> HPING 8.8.8.8 (eth3 8.8.8.8): icmp mode set, 28 headers + 0 data bytes
> (it stays there for every)
>
>
>
> can you guys please guide what is going on . in old Debian version i do
> this with no problem sub interfaces were very easy task. but here i invest
> the whole day.
>
> Thanks,
> Yousuf
>
>
>
>

[toc] | [prev] | [next] | [standalone]


#175970

FromXen <list@xenhideout.nl>
Date2016-12-27 13:40 +0100
Message-ID<sSZcR-22B-1@gated-at.bofh.it>
In reply to#175966
Muhammad Yousuf Khan schreef op 27-12-2016 12:22:

> can you guys please guide what is going on . in old Debian version i
> do this with no problem sub interfaces were very easy task. but here i
> invest the whole day.

I must say I have run into many problems on my own machine but never 
this one.

Are you sure your gateway recognises your secondary IP?

I even have 2 IPs on such an alias and they all work fine:

iface eth0 inet manual
   pre-up ip link set eth0 up

iface eth0:0 inet dhcp

iface eth0:1 inet static
   address 149.x.x.127
   netmask 255.255.255.0

In my case I do additional routing:

ip rule add from 149.x.x.127 (that's the secondary) lookup 2
ip route add default via 149.x.x.1 (gateway address for the second IP) 
table 2

[toc] | [prev] | [next] | [standalone]


#175971

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-27 14:00 +0100
Message-ID<sSZwd-29x-3@gated-at.bofh.it>
In reply to#175970

[Multipart message — attachments visible in raw view] — view raw

I didnt route anything as default gateway was already there. can you please
explain your routes more. i didnt get the context of that routes you
define.

On Tue, Dec 27, 2016 at 5:39 PM, Xen <list@xenhideout.nl> wrote:

> Muhammad Yousuf Khan schreef op 27-12-2016 12:22:
>
> can you guys please guide what is going on . in old Debian version i
>> do this with no problem sub interfaces were very easy task. but here i
>> invest the whole day.
>>
>
> I must say I have run into many problems on my own machine but never this
> one.
>
> Are you sure your gateway recognises your secondary IP?
>
> I even have 2 IPs on such an alias and they all work fine:
>
> iface eth0 inet manual
>   pre-up ip link set eth0 up
>
> iface eth0:0 inet dhcp
>
> iface eth0:1 inet static
>   address 149.x.x.127
>   netmask 255.255.255.0
>
> In my case I do additional routing:
>
> ip rule add from 149.x.x.127 (that's the secondary) lookup 2
> ip route add default via 149.x.x.1 (gateway address for the second IP)
> table 2
>
>

[toc] | [prev] | [next] | [standalone]


#175973

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-27 14:30 +0100
Message-ID<sSZZf-2Az-9@gated-at.bofh.it>
In reply to#175971

[Multipart message — attachments visible in raw view] — view raw

btw i never use ip command due to its complexity. i user route command
instead. which is way more easier. however i tried your commands and it
didn't work for me any help or idea  guys?

On Tue, Dec 27, 2016 at 5:58 PM, Muhammad Yousuf Khan <sirtcp@gmail.com>
wrote:

> I didnt route anything as default gateway was already there. can you
> please explain your routes more. i didnt get the context of that routes you
> define.
>
> On Tue, Dec 27, 2016 at 5:39 PM, Xen <list@xenhideout.nl> wrote:
>
>> Muhammad Yousuf Khan schreef op 27-12-2016 12:22:
>>
>> can you guys please guide what is going on . in old Debian version i
>>> do this with no problem sub interfaces were very easy task. but here i
>>> invest the whole day.
>>>
>>
>> I must say I have run into many problems on my own machine but never this
>> one.
>>
>> Are you sure your gateway recognises your secondary IP?
>>
>> I even have 2 IPs on such an alias and they all work fine:
>>
>> iface eth0 inet manual
>>   pre-up ip link set eth0 up
>>
>> iface eth0:0 inet dhcp
>>
>> iface eth0:1 inet static
>>   address 149.x.x.127
>>   netmask 255.255.255.0
>>
>> In my case I do additional routing:
>>
>> ip rule add from 149.x.x.127 (that's the secondary) lookup 2
>> ip route add default via 149.x.x.1 (gateway address for the second IP)
>> table 2
>>
>>
>

[toc] | [prev] | [next] | [standalone]


#175974

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-27 14:30 +0100
Message-ID<sSZZf-2Az-11@gated-at.bofh.it>
In reply to#175973

[Multipart message — attachments visible in raw view] — view raw

one more thing i can ping to gateway with virtual ip no problem.

hping3 -1 50.x.x.174 -a 50.x.x.162
HPING 50.x.x.174 (eth3 50.x.x.174): icmp mode set, 28 headers + 0 data bytes
len=46 ip=50.x.x.174 ttl=64 id=56571 icmp_seq=0 rtt=3.4 ms
len=46 ip=50.x.x.174 ttl=64 id=56572 icmp_seq=1 rtt=3.3 ms
len=46 ip=50.x.x.174 ttl=64 id=56573 icmp_seq=2 rtt=3.3 ms

On Tue, Dec 27, 2016 at 6:20 PM, Muhammad Yousuf Khan <sirtcp@gmail.com>
wrote:

> btw i never use ip command due to its complexity. i user route command
> instead. which is way more easier. however i tried your commands and it
> didn't work for me any help or idea  guys?
>
> On Tue, Dec 27, 2016 at 5:58 PM, Muhammad Yousuf Khan <sirtcp@gmail.com>
> wrote:
>
>> I didnt route anything as default gateway was already there. can you
>> please explain your routes more. i didnt get the context of that routes you
>> define.
>>
>> On Tue, Dec 27, 2016 at 5:39 PM, Xen <list@xenhideout.nl> wrote:
>>
>>> Muhammad Yousuf Khan schreef op 27-12-2016 12:22:
>>>
>>> can you guys please guide what is going on . in old Debian version i
>>>> do this with no problem sub interfaces were very easy task. but here i
>>>> invest the whole day.
>>>>
>>>
>>> I must say I have run into many problems on my own machine but never
>>> this one.
>>>
>>> Are you sure your gateway recognises your secondary IP?
>>>
>>> I even have 2 IPs on such an alias and they all work fine:
>>>
>>> iface eth0 inet manual
>>>   pre-up ip link set eth0 up
>>>
>>> iface eth0:0 inet dhcp
>>>
>>> iface eth0:1 inet static
>>>   address 149.x.x.127
>>>   netmask 255.255.255.0
>>>
>>> In my case I do additional routing:
>>>
>>> ip rule add from 149.x.x.127 (that's the secondary) lookup 2
>>> ip route add default via 149.x.x.1 (gateway address for the second IP)
>>> table 2
>>>
>>>
>>
>

[toc] | [prev] | [next] | [standalone]


#175975

FromXen <list@xenhideout.nl>
Date2016-12-27 14:50 +0100
Message-ID<sT0iB-2Hu-1@gated-at.bofh.it>
In reply to#175971
Muhammad Yousuf Khan schreef op 27-12-2016 13:58:
> I didnt route anything as default gateway was already there. can you
> please explain your routes more. i didnt get the context of that
> routes you define.

Nothing special there, if you use the same gateway it won't be needed. I 
just have a 2nd IP on a second subnet, so I need to use the second 
router for that second subnet.

 From your other reply it seems that your router is not routing to your 
address..

Maybe nothing changed in Debian but your host is not functioning for 
your second IP?

It would be weird unless something else was going on that you could not 
receive pings on that interface from the outside.

They are probably being sent out, but not getting back, because your 
router is not configured for your 2nd IP?

Of course you can check with tcpdump -i eth3 | grep "<second IP>"

Or tcpdump -i eth3 | grep "<second IP>" | grep echo

Regards.

[toc] | [prev] | [next] | [standalone]


#175976

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-27 15:20 +0100
Message-ID<sT0LE-36Q-17@gated-at.bofh.it>
In reply to#175975

[Multipart message — attachments visible in raw view] — view raw

Thanks this is what i already did and i was about to send you guys the
details and fortunately your msg comes in.
tcpdump is telling me very interesting story.
when i 'tcpdump -i eth3 icmp' it shows all the ping packet that are
received for ip 50.x.x161 but not for 50.x.x.162
that means ISP gateway is not sending packets to virtual IPs. so this issue
pointing to ISP or MAC related issue.

but confusion is the system before current system it has the Virtual IPs
and it was working fine it has debian 5 (old version)


Thanks,


On Tue, Dec 27, 2016 at 6:46 PM, Xen <list@xenhideout.nl> wrote:

> Muhammad Yousuf Khan schreef op 27-12-2016 13:58:
>
>> I didnt route anything as default gateway was already there. can you
>> please explain your routes more. i didnt get the context of that
>> routes you define.
>>
>
> Nothing special there, if you use the same gateway it won't be needed. I
> just have a 2nd IP on a second subnet, so I need to use the second router
> for that second subnet.
>
> From your other reply it seems that your router is not routing to your
> address..
>
> Maybe nothing changed in Debian but your host is not functioning for your
> second IP?
>
> It would be weird unless something else was going on that you could not
> receive pings on that interface from the outside.
>
> They are probably being sent out, but not getting back, because your
> router is not configured for your 2nd IP?
>
> Of course you can check with tcpdump -i eth3 | grep "<second IP>"
>
> Or tcpdump -i eth3 | grep "<second IP>" | grep echo
>
> Regards.
>
>

[toc] | [prev] | [next] | [standalone]


#175977

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2016-12-27 15:40 +0100
Message-ID<sT14Z-3dc-15@gated-at.bofh.it>
In reply to#175976
Le 27/12/2016 à 15:15, Muhammad Yousuf Khan a écrit :
> tcpdump is telling me very interesting story.
> when i 'tcpdump -i eth3 icmp' it shows all the ping packet that are
> received for ip 50.x.x161 but not for 50.x.x.162

What about ARP packets ?

[toc] | [prev] | [next] | [standalone]


#175981

FromXen <list@xenhideout.nl>
Date2016-12-27 16:50 +0100
Message-ID<sT2aJ-3Rr-11@gated-at.bofh.it>
In reply to#175976
Muhammad Yousuf Khan schreef op 27-12-2016 15:15:
> Thanks this is what i already did and i was about to send you guys the
> details and fortunately your msg comes in.
> tcpdump is telling me very interesting story.
> when i 'tcpdump -i eth3 icmp' it shows all the ping packet that are
> received for ip 50.x.x161 but not for 50.x.x.162
> that means ISP gateway is not sending packets to virtual IPs. so this
> issue pointing to ISP or MAC related issue.
> 
> but confusion is the system before current system it has the Virtual
> IPs and it was working fine it has debian 5 (old version)

Only thing I can say is to not give the address to the alias but see 
what happens if you just give it to eth3.

I don't know how you assign it but if this is your public IP then of 
course there is no such thing as "Virtual IP". They are just two IPs 
assigned to the same interface right, which is perfectly normal.

IPtables chokes on eth3:1 syntax though. Do not use it for your firewall 
pls :).

Regards.

Or if you do: iptables-save | sed "s/ eth3:. / eth3 /g" | 
iptables-restore

But maybe it is completely different, I don't know, it's just odd I 
guess to me.

Regards.

[toc] | [prev] | [next] | [standalone]


#175997

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-28 08:20 +0100
Message-ID<sTgGJ-4Zl-5@gated-at.bofh.it>
In reply to#175981

[Multipart message — attachments visible in raw view] — view raw

Thanks issue is resolved. as i mentioned tcpdump command not receving
packets from ISP gateway. thus we discussed this matter with ISP and the
restarted the router. and things got fixed. it seems that ISP router keeps
the old MAC entries thats why it didn't worked


On Tue, Dec 27, 2016 at 8:41 PM, Xen <list@xenhideout.nl> wrote:

> Muhammad Yousuf Khan schreef op 27-12-2016 15:15:
>
>> Thanks this is what i already did and i was about to send you guys the
>> details and fortunately your msg comes in.
>> tcpdump is telling me very interesting story.
>> when i 'tcpdump -i eth3 icmp' it shows all the ping packet that are
>> received for ip 50.x.x161 but not for 50.x.x.162
>> that means ISP gateway is not sending packets to virtual IPs. so this
>> issue pointing to ISP or MAC related issue.
>>
>> but confusion is the system before current system it has the Virtual
>> IPs and it was working fine it has debian 5 (old version)
>>
>
> Only thing I can say is to not give the address to the alias but see what
> happens if you just give it to eth3.
>
> I don't know how you assign it but if this is your public IP then of
> course there is no such thing as "Virtual IP". They are just two IPs
> assigned to the same interface right, which is perfectly normal.
>
> IPtables chokes on eth3:1 syntax though. Do not use it for your firewall
> pls :).
>
> Regards.
>
> Or if you do: iptables-save | sed "s/ eth3:. / eth3 /g" | iptables-restore
>
> But maybe it is completely different, I don't know, it's just odd I guess
> to me.
>
> Regards.
>
>

[toc] | [prev] | [next] | [standalone]


#175999

FromXen <list@xenhideout.nl>
Date2016-12-28 10:20 +0100
Message-ID<sTiyR-6cx-5@gated-at.bofh.it>
In reply to#175997
Muhammad Yousuf Khan schreef op 28-12-2016 8:10:
> Thanks issue is resolved. as i mentioned tcpdump command not receving
> packets from ISP gateway. thus we discussed this matter with ISP and
> the restarted the router. and things got fixed. it seems that ISP
> router keeps the old MAC entries thats why it didn't worked

Nice, so assumption was correct. Thank you.

[toc] | [prev] | [next] | [standalone]


#176098

FromMuhammad Yousuf Khan <sirtcp@gmail.com>
Date2016-12-30 14:30 +0100
Message-ID<sU5pT-4TD-1@gated-at.bofh.it>
In reply to#175999

[Multipart message — attachments visible in raw view] — view raw

Yes the assumption was correct, Thanks mate. thank you all for your
advices. i really appreciate

On Fri, Dec 30, 2016 at 6:26 PM, Muhammad Yousuf Khan <sirtcp@gmail.com>
wrote:

> Yes the assumption was correct, Thanks mate. thank you all for your
> advices. i really appreciate
>
> On Wed, Dec 28, 2016 at 2:16 PM, Xen <list@xenhideout.nl> wrote:
>
>> Muhammad Yousuf Khan schreef op 28-12-2016 8:10:
>>
>>> Thanks issue is resolved. as i mentioned tcpdump command not receving
>>> packets from ISP gateway. thus we discussed this matter with ISP and
>>> the restarted the router. and things got fixed. it seems that ISP
>>> router keeps the old MAC entries thats why it didn't worked
>>>
>>
>> Nice, so assumption was correct. Thank you.
>>
>>
>

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web