Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #185916 > unrolled thread

How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?

Started byTom Browder <tom.browder@gmail.com>
First post2017-08-25 16:10 +0200
Last post2017-08-28 08:10 +0200
Articles 10 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  How does one create virtual ethernet devices with modern tools on  Debian 8 (jessie)? Tom Browder <tom.browder@gmail.com> - 2017-08-25 16:10 +0200
    Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)? Sven Hartge <sven@svenhartge.de> - 2017-08-25 16:30 +0200
      Re: How does one create virtual ethernet devices with modern tools  on Debian 8 (jessie)? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-08-25 17:10 +0200
        Re: How does one create virtual ethernet devices with modern tools on  Debian 8 (jessie)? Tom Browder <tom.browder@gmail.com> - 2017-08-25 21:10 +0200
      Re: How does one create virtual ethernet devices with modern tools on  Debian 8 (jessie)? Tom Browder <tom.browder@gmail.com> - 2017-08-25 17:10 +0200
        Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)? Sven Hartge <sven@svenhartge.de> - 2017-08-25 17:50 +0200
          Re: How does one create virtual ethernet devices with modern tools  on Debian 8 (jessie)? Zenaan Harkness <zenaan@freedbms.net> - 2017-08-28 07:10 +0200
            Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)? Sven Hartge <sven@svenhartge.de> - 2017-08-28 10:30 +0200
        Re: How does one create virtual ethernet devices with modern tools on  Debian 8 (jessie)? Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-26 17:30 +0200
    Re: How does one create virtual ethernet devices with modern tools on  Debian 8 (jessie)? Jonathan de Boyne Pollard <J.deBoynePollard-newsgroups@NTLWorld.COM> - 2017-08-28 08:10 +0200

#185916 — How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?

FromTom Browder <tom.browder@gmail.com>
Date2017-08-25 16:10 +0200
SubjectHow does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?
Message-ID<uint7-51N-1@gated-at.bofh.it>
I am currently defining my devices like this in file /etc/network/interfaces:

#=================================================
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

# The loopback network interface
auto lo
iface lo inet loopback

# The primary network interface
allow-hotplug eth0
iface eth0 inet static
  address 142.54.186.2
  netmask 255.255.255.248
  gateway 142.54.186.1
  dns-nameservers 192.187.107.16 69.30.209.16

  # added alias IPv4s:
  up   ip addr add 142.54.186.3/29 dev $IFACE label $IFACE:0
  down ip addr del 142.54.186.3/29 dev $IFACE label $IFACE:0

  up   ip addr add 142.54.186.4/29 dev $IFACE label $IFACE:1
  down ip addr del 142.54.186.4/29 dev $IFACE label $IFACE:1

  up   ip addr add 142.54.186.5/29 dev $IFACE label $IFACE:2
  down ip addr del 142.54.186.5/29 dev $IFACE label $IFACE:2

  up   ip addr add 142.54.186.6/29 dev $IFACE label $IFACE:3
  down ip addr del 142.54.186.6/29 dev $IFACE label $IFACE:3
#=================================================

I would like to add a large chunk (say 20) of my IPv6 addresses, too.

Although not yet implemented (for fear of messing my remote host up),
the following has been recommended:

#=================================================
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

# The loopback network interface
auto lo
iface lo inet loopback

# The primary network interface
allow-hotplug eth0
auto etho
iface eth0 inet static
        address 142.54.186.2
        netmask 255.255.255.248
        gateway 142.54.186.1
        dns-nameservers 192.187.107.16 69.30.209.16
iface eth0 inet static
        address 142.54.186.3
iface eth0 inet static
        address 142.54.186.4
iface eth0 inet static
        address 142.54.186.5
iface eth0 inet static
        address 142.54.186.6
iface eth0 inet6 static
        address 2604:4300:a:95::2
        netmask ffff:ffff:ffff:ffff::
        gateway 2604:4300:a:95::1
        dns-nameservers 192.187.107.16 69.30.209.16
iface eth0 inet6 static
        address 2604:4300:a:95::3
iface eth0 inet6 static
        address 2604:4300:a:95::4
iface eth0 inet6 static
        address 2604:4300:a:95::5
iface eth0 inet6 static
        address 2604:4300:a:95::6
#=================================================


FYI, here is a chunk of the output of "dmesg | grep -i eth":

#=================================================
[    0.898483] e1000e 0000:09:00.0 eth0: (PCI Express:2.5GT/s:Width
x4) 00:1e:68:2e:df:be
[    0.898486] e1000e 0000:09:00.0 eth0: Intel(R) PRO/1000 Network Connection
[    0.898564] e1000e 0000:09:00.0 eth0: MAC: 5, PHY: 5, PBA No: FFFFFF-0FF
[    9.525606] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
[   11.846375] e1000e: eth0 NIC Link is Up 1000 Mbps Full Duplex, Flow
Control: Rx/Tx
[   11.846877] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
#=================================================

So how does one do the same thing with "modern" tools?

Thanks.

-Tom

[toc] | [next] | [standalone]


#185917 — Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?

FromSven Hartge <sven@svenhartge.de>
Date2017-08-25 16:30 +0200
SubjectRe: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?
Message-ID<uinMt-5ah-19@gated-at.bofh.it>
In reply to#185916
Tom Browder <tom.browder@gmail.com> wrote:

Before we start:

"virtual ethernet devices" are something totally different than you are
doing here. You just want to put multiple IP addresses on one interface.

"virtual ethernet devices" are for example used with virtualization or
docker, to connect an isolated VM or container through the host to the
network.

> Although not yet implemented (for fear of messing my remote host up),
> the following has been recommended:

> #=================================================
> # This file describes the network interfaces available on your system
> # and how to activate them. For more information, see interfaces(5).

> # The loopback network interface
> auto lo
> iface lo inet loopback

> # The primary network interface
> allow-hotplug eth0
> auto etho

One of "allow-hotplug" or "auto", not both. And you have a typo there,
it should read "auto eth0".

> iface eth0 inet static
>         address 142.54.186.2
>         netmask 255.255.255.248
>         gateway 142.54.186.1
>         dns-nameservers 192.187.107.16 69.30.209.16
> iface eth0 inet static
>         address 142.54.186.3
> iface eth0 inet static
>         address 142.54.186.4
> iface eth0 inet static
>         address 142.54.186.5
> iface eth0 inet static
>         address 142.54.186.6
> iface eth0 inet6 static
>         address 2604:4300:a:95::2
>         netmask ffff:ffff:ffff:ffff::
>         gateway 2604:4300:a:95::1
>         dns-nameservers 192.187.107.16 69.30.209.16

No need to duplicate the nameservers. Also this line only gets used if
you use the package "resolvconf". On servers with static IP
configuration I usually get rid of this mechanism and set the
nameservers myself in /etc/resolv.conf

> iface eth0 inet6 static
>         address 2604:4300:a:95::3
> iface eth0 inet6 static
>         address 2604:4300:a:95::4
> iface eth0 inet6 static
>         address 2604:4300:a:95::5
> iface eth0 inet6 static
>         address 2604:4300:a:95::6

Yes, everything is fine. 

Side note: I'd truly randomize the IPv6 addresses, so the subnet is not
as easily scannable from the outside.

> So how does one do the same thing with "modern" tools?

I don't understand the question. Do you mean "systemd-networkd"?

Grüße,
S°

-- 
Sigmentation fault. Core dumped.

[toc] | [prev] | [next] | [standalone]


#185923 — Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-08-25 17:10 +0200
SubjectRe: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?
Message-ID<uiopb-5CW-19@gated-at.bofh.it>
In reply to#185917
On Fri, Aug 25, 2017 at 10:03:07AM -0500, Tom Browder wrote:
> On Fri, Aug 25, 2017 at 09:26 Sven Hartge <sven@svenhartge.de> wrote:
> > One of "allow-hotplug" or "auto", not both
> 
> Any preference for either line?

Use "auto" if the network interface is a permanent one, and "allow-hotplug"
if it's a transient one (removable, whatever).

Interfaces configured as "auto" will be respected by systemd's
"network-online.target", meaning any service that you configure to
wait for network-online will wait for all "auto" interfaces to be
brought up.  It will not wait for "allow-hotplug" interfaces.

[toc] | [prev] | [next] | [standalone]


#185945

FromTom Browder <tom.browder@gmail.com>
Date2017-08-25 21:10 +0200
Message-ID<uis9s-7Xf-17@gated-at.bofh.it>
In reply to#185923
On Fri, Aug 25, 2017 at 10:09 AM, Greg Wooledge <wooledg@eeg.ccf.org> wrote:
>> On Fri, Aug 25, 2017 at 09:26 Sven Hartge <sven@svenhartge.de> wrote:
>> > One of "allow-hotplug" or "auto", not both
>>
>> Any preference for either line?
>
> Use "auto" if the network interface is a permanent one, and "allow-hotplug"
> if it's a transient one (removable, whatever).
>
> Interfaces configured as "auto" will be respected by systemd's
> "network-online.target", meaning any service that you configure to
> wait for network-online will wait for all "auto" interfaces to be
> brought up.  It will not wait for "allow-hotplug" interfaces.

That's very helpful. Sounds like it's the "auto" for my situation.

Thanks much, Greg.

Best,

-Tom

[toc] | [prev] | [next] | [standalone]


#185924

FromTom Browder <tom.browder@gmail.com>
Date2017-08-25 17:10 +0200
Message-ID<uiopc-5CW-21@gated-at.bofh.it>
In reply to#185917
On Fri, Aug 25, 2017 at 09:26 Sven Hartge <sven@svenhartge.de> wrote:
>
> Tom Browder <tom.browder@gmail.com> wrote:
>
> Before we start:
>
> "virtual ethernet devices" are something totally different than you are
> doing here. You just want to put multiple IP addresses on one interface.
>
> "virtual ethernet devices" are for example used with virtualization or
> docker, to connect an isolated VM or container through the host to the
> network.
>
> > Although not yet implemented (for fear of messing my remote host up),
> > the following has been recommended:
...
> > # The primary network interface
> > allow-hotplug eth0
> > auto eth
>
> One of "allow-hotplug" or "auto", not both

Any preference for either line?

> And you have a typo there, it should read "auto eth0".

Good catch on the typo!

> > iface eth0 inet6 static
> >         address 2604:4300:a:95::2
> >         netmask ffff:ffff:ffff:ffff::
> >         gateway 2604:4300:a:95::1
> >         dns-nameservers 192.187.107.16 69.30.209.16
>
> No need to duplicate the nameservers. Also this line only gets used if
> you use the package "resolvconf". On servers with static IP
> configuration I usually get rid of this mechanism and set the
> nameservers myself in /etc/resolv.conf

Ah!  That's good advice.

> > iface eth0 inet6 static
> >         address 2604:4300:a:95::6
>
> Yes, everything is fine.
>
> Side note: I'd truly randomize the IPv6 addresses, so the subnet is not
> as easily scannable from the outside.

Also good advice.

Thanks, Sven, very helpful.  Can you recommend a good modern book on networking?

> > So how does one do the same thing with "modern" tools?
>
> I don't understand the question. Do you mean "systemd-networkd"?

I'm indirectly referencing a long-running thread on this list about
using ifconfig versus "modern" tools for viewing the current
interfaces setup.

And just how does one restart the new interfaces with systemctl?

If I mess something up, is there any way to ssh into the remote system?

Thanks very much for all your help!

Best,

-Tom

[toc] | [prev] | [next] | [standalone]


#185925 — Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?

FromSven Hartge <sven@svenhartge.de>
Date2017-08-25 17:50 +0200
SubjectRe: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?
Message-ID<uip1U-5RV-29@gated-at.bofh.it>
In reply to#185924
Tom Browder <tom.browder@gmail.com> wrote:
> On Fri, Aug 25, 2017 at 09:26 Sven Hartge <sven@svenhartge.de> wrote:
>>
>> Tom Browder <tom.browder@gmail.com> wrote:
>>
>> Before we start:
>>
>> "virtual ethernet devices" are something totally different than you are
>> doing here. You just want to put multiple IP addresses on one interface.
>>
>> "virtual ethernet devices" are for example used with virtualization or
>> docker, to connect an isolated VM or container through the host to the
>> network.
>>
>> > Although not yet implemented (for fear of messing my remote host up),
>> > the following has been recommended:
> ...
>> > # The primary network interface
>> > allow-hotplug eth0
>> > auto eth
>>
>> One of "allow-hotplug" or "auto", not both

> Any preference for either line?

See what Greg wrote.

> Thanks, Sven, very helpful.  Can you recommend a good modern book on networking?

The topic is quite broad today, I don't have general (or any)
recommendation at the moment.

>> > So how does one do the same thing with "modern" tools?
>>
>> I don't understand the question. Do you mean "systemd-networkd"?

> I'm indirectly referencing a long-running thread on this list about
> using ifconfig versus "modern" tools for viewing the current
> interfaces setup.

When using /e/n/interfaces and ifupdown you don't really come in contact
with "ip" or "ifconfig" directly.

> And just how does one restart the new interfaces with systemctl?

You don't. Commands like "service networking restart" have been
deprecated and partially non-functioning since at least Wheezy, because
of the internal limit of ifupdown itself.

> If I mess something up, is there any way to ssh into the remote
> system?

Unless you have an out-of-band login, for example via seriel console,
networked KVM switch or iLO/iDRAC: no. If you break the network
configuration on a hosted server, you either pay the hoster to fix it or
boot into the rescue system the hoster hopefully provides, allowing you
to mount your filesystems and fix it manually.

I, years ago, scripted a wrapper using "at" and a known-good backup
configuration, which would be copied into place and the server rebootet
if I didn't stop the at-job. That way, if I broke the configuration, I
knew the server would reboot in X minutes and be reachable again,
sparing me the drive to the housing place in the middle of the night to
fix the system.

Right now I am in the very fortunate situation of only having systems
with out-of-band management services available, removing the fear of
screwing something up fatally.

Grüße,
Sven.

-- 
Sigmentation fault. Core dumped.

[toc] | [prev] | [next] | [standalone]


#186055 — Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?

FromZenaan Harkness <zenaan@freedbms.net>
Date2017-08-28 07:10 +0200
SubjectRe: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?
Message-ID<ujktc-1ia-5@gated-at.bofh.it>
In reply to#185925
On Fri, Aug 25, 2017 at 05:45:17PM +0200, Sven Hartge wrote:
> Tom Browder <tom.browder@gmail.com> wrote:
> > On Fri, Aug 25, 2017 at 09:26 Sven Hartge <sven@svenhartge.de> wrote:
> >> Tom Browder <tom.browder@gmail.com> wrote:

> >> > So how does one do the same thing with "modern" tools?
> >>
> >> I don't understand the question. Do you mean "systemd-networkd"?
> 
> > I'm indirectly referencing a long-running thread on this list about
> > using ifconfig versus "modern" tools for viewing the current
> > interfaces setup.
> 
> When using /e/n/interfaces and ifupdown you don't really come in contact
> with "ip" or "ifconfig" directly.
> 
> > And just how does one restart the new interfaces with systemctl?
> 
> You don't. Commands like "service networking restart" have been
> deprecated and partially non-functioning since at least Wheezy, because
> of the internal limit of ifupdown itself.

So to do text-config based networking, what's
"The Recommended Way (TM)(R)(C)"?

[toc] | [prev] | [next] | [standalone]


#186065 — Re: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?

FromSven Hartge <sven@svenhartge.de>
Date2017-08-28 10:30 +0200
SubjectRe: How does one create virtual ethernet devices with modern tools on Debian 8 (jessie)?
Message-ID<ujnAK-3gC-11@gated-at.bofh.it>
In reply to#186055
Zenaan Harkness <zenaan@freedbms.net> wrote:
> On Fri, Aug 25, 2017 at 05:45:17PM +0200, Sven Hartge wrote:

>> You don't. Commands like "service networking restart" have been
>> deprecated and partially non-functioning since at least Wheezy,
>> because of the internal limit of ifupdown itself.

> So to do text-config based networking, what's
> "The Recommended Way (TM)(R)(C)"?

Your question is unclear, unfortunately.

S°

-- 
Sigmentation fault. Core dumped.

[toc] | [prev] | [next] | [standalone]


#185990

FromMario Castelán Castro <marioxcc.MT@yandex.com>
Date2017-08-26 17:30 +0200
Message-ID<uiLc5-2R7-1@gated-at.bofh.it>
In reply to#185924

[Multipart message — attachments visible in raw view] — view raw

On 25/08/17 10:03, Tom Browder wrote:
> Thanks, Sven, very helpful.  Can you recommend a good modern book on networking?

I learned the fundamentals of networking (which is very different from
learning how to use the networking tools in GNU/Linux) from this book:

http://libgen.io/book/index.php?md5=46C141A599089425669194E107EEFB4E

This is edition 6, but I learned from edition 5 (6 was not released back
then).

-- 
Do not eat animals, respect them as you respect people.
https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan

[toc] | [prev] | [next] | [standalone]


#186057

FromJonathan de Boyne Pollard <J.deBoynePollard-newsgroups@NTLWorld.COM>
Date2017-08-28 08:10 +0200
Message-ID<ujlpg-1UB-31@gated-at.bofh.it>
In reply to#185916

[Multipart message — attachments visible in raw view] — view raw

Tom Browder:

>    # added alias IPv4s:
>    up   ip addr add 142.54.186.3/29 dev $IFACE label $IFACE:0
>    down ip addr del 142.54.186.3/29 dev $IFACE label $IFACE:0

Ironically, the "modern tools" aspect is the thing that you are in fact 
aiming to eliminate here. |/etc/network/interfaces| is best treated as 
an entirely descriptive mechanism, with as little imperative stuff in it 
as can be arranged.  Here, you are getting rid of the imperative 
explicit invocations of the |ip| command, the "modern tool" as you 
mention, and replacing them with the descriptive "stanzas" that 
|/etc/network/interfaces| /already has/ as a mechanism for 
non-imperatively describing multiple IPv4/IPv6 addresses on a single 
|eth0| interface.

|ifup| and |ifdown| are best thought of as translators, as their manual 
page implies.  They take what is in |/etc/network/interfaces| and 
translate it into the necessary sequences of imperative commands for 
actually doing the job, which they run under the covers. Those 
underlying commands can include |bootpc|, |avahi-autoipd|, 
|settle-dad.sh|, |pon|, |poff|, |wvdial|, |dhclient|, |dhclient3|, 
|pump|, |udhcpc|, |dhcpd|, |kill|, |ip|, and (sic!) |ifconfig|, all 
invoked with various parameters calculated from the 
|/etc/network/interfaces| description.

They aren't the only translators for that file.  For example, here's 
what happens when one runs your proposed non-imperative 
|/etc/network/interfaces| (with the typing errors mentioned elsewhere 
cleaned up) through mine, which translates from that description 
<http://jdebp.eu./Softwares/nosh/guide/rcconf-amalgamation.html> into 
(roughly) the |rc.conf| configuration format for FreeBSD/TrueOS 
<https://www.freebsd.org/cgi/man.cgi?query=rc.conf>:

> JdeBP % sudo redo -C /etc/system-control/convert/ rc.conf
> Password:
> redo: INFO: rc.conf: Redone.
> JdeBP % sed -ne '/etc.network.interfaces/,/sysrc:/p' /etc/system-control/convert/rc.conf
> # Converted from /etc/network/interfaces:
> network_interfaces="lo eth0 "
> ifconfig_lo="AUTO inet  127.0.0.1 "
> ifconfig_eth0="AUTO inet  142.54.186.2 netmask 255.255.255.248 gateway 142.54.186.1 "
> ifconfig_eth0_ipv6="inet6  2604:4300:a:95::2 netmask ffff:ffff:ffff:ffff:: "
> ifconfig_eth0_aliases="inet 142.54.186.3
> inet 142.54.186.4
> inet 142.54.186.5
> inet 142.54.186.6
> inet6 2604:4300:a:95::3
> inet6 2604:4300:a:95::4
> inet6 2604:4300:a:95::5
> inet6 2604:4300:a:95::6"
> # dump by sysrc:
> JdeBP %


[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web