Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #192456 > unrolled thread

Re: BIND and iptables config

Started byRodary Jacques <rodaryj@free.fr>
First post2018-02-15 17:20 +0100
Last post2018-02-15 20:50 +0100
Articles 8 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  Re: BIND and iptables config Rodary Jacques <rodaryj@free.fr> - 2018-02-15 17:20 +0100
    Re: BIND and iptables config Henning Follmann <hfollmann@itcfollmann.com> - 2018-02-15 17:50 +0100
      Re: BIND and iptables config Rodary Jacques <rodaryj@free.fr> - 2018-02-16 03:20 +0100
      Re: BIND and iptables config Rodary Jacques <rodaryj@free.fr> - 2018-02-16 04:30 +0100
        Re: BIND and iptables config rhkramer@gmail.com - 2018-02-16 13:00 +0100
        Re: BIND and iptables config Henning Follmann <hfollmann@itcfollmann.com> - 2018-02-16 15:00 +0100
          Re: BIND and iptables config David Wright <deblis@lionunicorn.co.uk> - 2018-02-22 19:00 +0100
    Re: BIND and iptables config Pascal Hambourg <pascal@plouf.fr.eu.org> - 2018-02-15 20:50 +0100

#192456 — Re: BIND and iptables config

FromRodary Jacques <rodaryj@free.fr>
Date2018-02-15 17:20 +0100
SubjectRe: BIND and iptables config
Message-ID<vjuql-51x-11@gated-at.bofh.it>
With NetworkManager, /etc/network/interfaces has only the loopbak interface, and I can't use wicd which can't deal with two wired interfaces. And, Henning Follmann, my English is too poor to explain clearly my setup which is the standard one when your ISP gives you one routable address and you want your home LAN to have access to internet.
	Thanks for your interest anyway.
		Jacques

[toc] | [next] | [standalone]


#192458

FromHenning Follmann <hfollmann@itcfollmann.com>
Date2018-02-15 17:50 +0100
Message-ID<vjuTo-5cP-13@gated-at.bofh.it>
In reply to#192456
On Thu, Feb 15, 2018 at 05:01:52PM +0100, Rodary Jacques wrote:
> With NetworkManager, /etc/network/interfaces has only the loopbak interface, and I can't use wicd which can't deal with two wired interfaces. And, Henning Follmann, my English is too poor to explain clearly my setup which is the standard one when your ISP gives you one routable address and you want your home LAN to have access to internet.
> 	Thanks for your interest anyway.
> 		Jacques
> 

Hello,
no your english was good enough to describe your setup. And I would say
that 90% of "us" have a form of "dialup" with on routable ip address and a
NAT setup.
First bind is not "standard" in this kind of situation and makes things
overly complicated. I would recommend dnsmasq instead. It is much more
staight forward for a NAT box to setup. It will also provide you with a
dhcp server.
And in your situation you also want to disable/avoid the NetworkManager. 
It is quite easy because evry device you list in /e/n/i will be
automaticaaly ignored by the NetworkManager.
And clearly because you have difficulties in setting this up doesn't make
all of this a bug.

Also I want to mention to setup a router with Red Hat or with debian is
possible but there a distributions which are much more suited for this
purpose. I personally like pfsense and opnsense. Both are based on BSD but
they are excellent for SOHO routing. 

-H




-- 
Henning Follmann           | hfollmann@itcfollmann.com

[toc] | [prev] | [next] | [standalone]


#192484

FromRodary Jacques <rodaryj@free.fr>
Date2018-02-16 03:20 +0100
Message-ID<vjDMZ-2wk-1@gated-at.bofh.it>
In reply to#192458
Le jeudi 15 février 2018, 11:44:36 CET Henning Follmann a écrit :
> On Thu, Feb 15, 2018 at 05:01:52PM +0100, Rodary Jacques wrote:
> > With NetworkManager, /etc/network/interfaces has only the loopbak interface, and I can't use wicd which can't deal with two wired interfaces. And, Henning Follmann, my English is too poor to explain clearly my setup which is the standard one when your ISP gives you one routable address and you want your home LAN to have access to internet.
> > 	Thanks for your interest anyway.
> > 		Jacques
> > 
> 
> Hello,
> no your english was good enough to describe your setup. And I would say
> that 90% of "us" have a form of "dialup" with on routable ip address and a
> NAT setup.
> First bind is not "standard" in this kind of situation and makes things
> overly complicated. I would recommend dnsmasq instead. It is much more
> staight forward for a NAT box to setup. It will also provide you with a
> dhcp server.
> And in your situation you also want to disable/avoid the NetworkManager. 
> It is quite easy because evry device you list in /e/n/i will be
> automaticaaly ignored by the NetworkManager.
> And clearly because you have difficulties in setting this up doesn't make
> all of this a bug.
> 
> Also I want to mention to setup a router with Red Hat or with debian is
> possible but there a distributions which are much more suited for this
> purpose. I personally like pfsense and opnsense. Both are based on BSD but
> they are excellent for SOHO routing. 
> 

I had quite enough  problems setting this config to try something else. Thank you again.
	JR

[toc] | [prev] | [next] | [standalone]


#192485

FromRodary Jacques <rodaryj@free.fr>
Date2018-02-16 04:30 +0100
Message-ID<vjESJ-3gX-1@gated-at.bofh.it>
In reply to#192458
Le jeudi 15 février 2018, 11:44:36 CET Henning Follmann a écrit :
> On Thu, Feb 15, 2018 at 05:01:52PM +0100, Rodary Jacques wrote:
> > With NetworkManager, /etc/network/interfaces has only the loopbak interface, and I can't use wicd which can't deal with two wired interfaces. And, Henning Follmann, my English is too poor to explain clearly my setup which is the standard one when your ISP gives you one routable address and you want your home LAN to have access to internet.
> > 	Thanks for your interest anyway.
> > 		Jacques
> > 
> 
> Hello,
> no your english was good enough to describe your setup. And I would say
> that 90% of "us" have a form of "dialup" with on routable ip address and a
> NAT setup.
> First bind is not "standard" in this kind of situation and makes things
> overly complicated. I would recommend dnsmasq instead. It is much more
> staight forward for a NAT box to setup. It will also provide you with a
> dhcp server.
> And in your situation you also want to disable/avoid the NetworkManager. 
I told before that wiced can't deal with two wired interfaces.
> It is quite easy because evry device you list in /e/n/i 
i don't know ( with my poor English :-)) what is /e/n/i 
> will be
> automaticaaly ignored by the NetworkManager.
> And clearly because you have difficulties in setting this up doesn't make
> all of this a bug.
I don't find it normal to try to use interfaces before they are up! It's obvously not a bug, but it's just  telling  users they shouldn't  try to understand. When I fist tried Debian in april 2016, with Jessie, I read in the bind9 doc something like "there are some issues about changing bind9 configuration, as future upgrade will loose your changes". without any more details. 
> Also I want to mention to setup a router with Red Hat or with debian is
> possible but there a distributions which are much more suited for this purpose. 
I switched to Debian not to find it easier (Redhat wasn't) but because of safety and coherence.
But NetworkManager, which was on Fedora long before that on Debian, did not the stupid things it does with resolv.conf and interfaces.
> I personally like pfsense and opnsense. Both are based on BSD but
> they are excellent for SOHO routing. 
Thanks to Wikipedia, I understood SOHO :-D
> 
> -H
Have a good day (or night).
	JR

[toc] | [prev] | [next] | [standalone]


#192497

Fromrhkramer@gmail.com
Date2018-02-16 13:00 +0100
Message-ID<vjMQi-5U-17@gated-at.bofh.it>
In reply to#192485
On Thursday, February 15, 2018 10:26:14 PM Rodary Jacques wrote:
> Le jeudi 15 février 2018, 11:44:36 CET Henning Follmann a écrit :
> > On Thu, Feb 15, 2018 at 05:01:52PM +0100, Rodary Jacques wrote:
> > > With NetworkManager, /etc/network/interfaces has only the loopbak
> > > interface, and I can't use wicd which can't deal with two wired
> > > interfaces. And, Henning Follmann, my English is too poor to explain
> > > clearly my setup which is the standard one when your ISP gives you one
> > > routable address and you want your home LAN to have access to
> > > internet.

I don't understand--what are the two wired interfaces that you have connected 
to your computer?

> > Hello,
> > no your english was good enough to describe your setup. And I would say
> > that 90% of "us" have a form of "dialup" with on routable ip address and
> > a NAT setup.
> > First bind is not "standard" in this kind of situation and makes things
> > overly complicated. I would recommend dnsmasq instead. It is much more
> > staight forward for a NAT box to setup. It will also provide you with a
> > dhcp server.
> > And in your situation you also want to disable/avoid the NetworkManager.
> 
> I told before that wiced can't deal with two wired interfaces.
> 
> > It is quite easy because evry device you list in /e/n/i

Based on context, I would say that is a difficult to understand attempt at 
abbreviating /etc/network/interfaces, especially to offer for someone with 
limited English skills.

I hope you are not giving up (I got the idea you might based on your previous 
post)--I'm not sure I can help you, but I think someone will be able to.

[toc] | [prev] | [next] | [standalone]


#192503

FromHenning Follmann <hfollmann@itcfollmann.com>
Date2018-02-16 15:00 +0100
Message-ID<vjOIq-1jP-7@gated-at.bofh.it>
In reply to#192485
On Fri, Feb 16, 2018 at 04:26:14AM +0100, Rodary Jacques wrote:
> Le jeudi 15 février 2018, 11:44:36 CET Henning Follmann a écrit :
> > On Thu, Feb 15, 2018 at 05:01:52PM +0100, Rodary Jacques wrote:
> > > With NetworkManager, /etc/network/interfaces has only the loopbak interface, and I can't use wicd which can't deal with two wired interfaces. And, Henning Follmann, my English is too poor to explain clearly my setup which is the standard one when your ISP gives you one routable address and you want your home LAN to have access to internet.
> > > 	Thanks for your interest anyway.
> > > 		Jacques
> > > 
> > 
> > Hello,
> > no your english was good enough to describe your setup. And I would say
> > that 90% of "us" have a form of "dialup" with on routable ip address and a
> > NAT setup.
> > First bind is not "standard" in this kind of situation and makes things
> > overly complicated. I would recommend dnsmasq instead. It is much more
> > staight forward for a NAT box to setup. It will also provide you with a
> > dhcp server.
> > And in your situation you also want to disable/avoid the NetworkManager. 
> I told before that wiced can't deal with two wired interfaces.

That is not true, but lets ignore this for now.

> > It is quite easy because evry device you list in /e/n/i 
> i don't know ( with my poor English :-)) what is /e/n/i

Again your English is fine it's me being lazy.
/e/n/i is short for /etc/network/interfaces
This is the "old" way to configure your network interfaces.
 
> > will be
> > automaticaaly ignored by the NetworkManager.
> > And clearly because you have difficulties in setting this up doesn't make
> > all of this a bug.
> I don't find it normal to try to use interfaces before they are up! It's obvously not a bug, but it's just  telling  users they shouldn't  try to understand. When I fist tried Debian in april 2016, with Jessie, I read in the bind9 doc something like "there are some issues about changing bind9 configuration, as future upgrade will loose your changes". without any more details. 

Again, everything is behaving as expected. It is how you do things. And to
repeat myself, bind is not best in this situation. But if you insist in
using bind make sure it listens on your inside network interface, which
should be up without delay. You do not want ( and most likely neither does
your ISP) a full recursive resolver on your public interface.

You insisting to stick to this setup because you already invested too much
time in it is kind of stubborn (and I thought that was a German trait). You
either have to invest a lot more time to understand this or you could
switch to something more suited like dnsmasq. 

> > Also I want to mention to setup a router with Red Hat or with debian is
> > possible but there a distributions which are much more suited for this purpose. 
> I switched to Debian not to find it easier (Redhat wasn't) but because of safety and coherence.
> But NetworkManager, which was on Fedora long before that on Debian, did not the stupid things it does with resolv.conf and interfaces.

You most likely have resolvconf installed which updates /etc/resolv.conf.
Anything you change in there will be overwritten whenever something happens
on any network device.

> > I personally like pfsense and opnsense. Both are based on BSD but
> > they are excellent for SOHO routing. 
> Thanks to Wikipedia, I understood SOHO :-Da

And have you looked up OPNSense or pfsense?


-H



-- 
Henning Follmann           | hfollmann@itcfollmann.com

[toc] | [prev] | [next] | [standalone]


#192905

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2018-02-22 19:00 +0100
Message-ID<vm3jY-89a-13@gated-at.bofh.it>
In reply to#192503
On Fri 16 Feb 2018 at 08:53:27 (-0500), Henning Follmann wrote:
> On Fri, Feb 16, 2018 at 04:26:14AM +0100, Rodary Jacques wrote:
> > Le jeudi 15 février 2018, 11:44:36 CET Henning Follmann a écrit :
> > > On Thu, Feb 15, 2018 at 05:01:52PM +0100, Rodary Jacques wrote:
> > > > With NetworkManager, /etc/network/interfaces has only the loopbak interface, and I can't use wicd which can't deal with two wired interfaces. And, Henning Follmann, my English is too poor to explain clearly my setup which is the standard one when your ISP gives you one routable address and you want your home LAN to have access to internet.
> > > > 	Thanks for your interest anyway.
> > > > 		Jacques
> > > > 
> > > 
> > > Hello,
> > > no your english was good enough to describe your setup. And I would say
> > > that 90% of "us" have a form of "dialup" with on routable ip address and a
> > > NAT setup.
> > > First bind is not "standard" in this kind of situation and makes things
> > > overly complicated. I would recommend dnsmasq instead. It is much more
> > > staight forward for a NAT box to setup. It will also provide you with a
> > > dhcp server.
> > > And in your situation you also want to disable/avoid the NetworkManager. 
> > I told before that wiced can't deal with two wired interfaces.
> 
> That is not true, but lets ignore this for now.

I would be interested to know how you do this. I can't even see a way
to make wicd make connections on two interfaces at the same time where
one is wired and the other wireless. As soon as you select one
interface, the other gets disconnected. Do you have some CLI magic
that makes it keep the first connection going?

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#192467

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2018-02-15 20:50 +0100
Message-ID<vjxHA-70W-23@gated-at.bofh.it>
In reply to#192456
Le 15/02/2018 à 17:01, Rodary Jacques a écrit :
> my English is too poor to explain clearly my setup
Why don't you post in French in the debian-user-french mailing list ?

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web