Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #193556 > unrolled thread
| Started by | Johann Spies <johann.spies@gmail.com> |
|---|---|
| First post | 2018-03-09 15:40 +0100 |
| Last post | 2018-03-10 10:20 +0100 |
| Articles | 20 on this page of 46 — 11 participants |
Back to article view | Back to linux.debian.user
Help needed with home network configuration Johann Spies <johann.spies@gmail.com> - 2018-03-09 15:40 +0100
Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-03-09 16:20 +0100
Re: Help needed with home network configuration Gene Heskett <gheskett@shentel.net> - 2018-03-09 18:40 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-15 03:30 +0100
Re: Help needed with home network configuration Gene Heskett <gheskett@shentel.net> - 2018-03-15 06:20 +0100
Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-15 18:20 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 02:50 +0100
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 04:30 +0100
Re: Help needed with home network configuration Joe <joe@jretrading.com> - 2018-03-16 09:50 +0100
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 14:00 +0100
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 14:10 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-16 14:30 +0100
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-03-31 00:30 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-03 13:50 +0200
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-05 19:40 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-06 12:20 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-06 16:50 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-06 18:40 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-07 16:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-07 22:30 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-08 02:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-08 02:50 +0200
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-08 14:10 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-09 12:40 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-13 16:20 +0200
Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-04-14 10:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-15 13:40 +0200
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-04-15 14:10 +0200
Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-04-15 18:50 +0200
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-04-16 00:50 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-15 13:30 +0200
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-08 14:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-09 12:30 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 17:20 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 15:40 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-16 14:20 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 17:10 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-19 12:00 +0100
Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-16 18:30 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 20:20 +0100
Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-16 21:00 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-17 00:50 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-09 17:30 +0100
Re: Help needed with home network configuration john doe <johndoe65534@mail.com> - 2018-03-09 20:30 +0100
Re: Help needed with home network configuration Johann Spies <johann.spies@gmail.com> - 2018-03-10 10:10 +0100
Re: Help needed with home network configuration <tomas@tuxteam.de> - 2018-03-10 10:20 +0100
Page 1 of 3 [1] 2 3 Next page →
| From | Johann Spies <johann.spies@gmail.com> |
|---|---|
| Date | 2018-03-09 15:40 +0100 |
| Subject | Help needed with home network configuration |
| Message-ID | <vrrlE-6iv-5@gated-at.bofh.it> |
For many years I have used my desktp as a network/firewall server with
two interfaces one facing the internet (through ADSL) and the other the
local network.
Now I have a fibre connection and for a month both connections will be
available in parallel.
I have decided to use my Raspberry Pi3 as the firewall/network server in
future but have after many hours failed to do so successfully.
First I have tried a similar Shorewall setup that I have on my desktop
and after failing successful connections I tried ufw with no success.
First ufw:
$ sudo ufw status verbose
Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing)
New profiles: skip
To Action From
-- ------ ----
Anywhere ALLOW IN 192.168.0.0/24
Anywhere ALLOW OUT 192.168.0.0/24
53/udp ALLOW OUT 192.168.0.0/24
443/tcp ALLOW OUT 192.168.0.0/24
(Ihave added the last two lines which I thought should not be
necessary).
I get this in the log:
Mar 9 12:14:15 pi3 kernel: [403782.469448] [UFW BLOCK] IN=eth0
OUT=eth1 MAC=b8:27:eb:63:94:ea:1c:5a:3e:e0:29:fe:08:00:45:00:00:3c:50:e8:40:00:3f:06:fb:f2
SRC=192.168.0.10 DST=207.36.95.10 LEN=60 TOS=0x00 PREC=0x00 TTL=63
ID=20712 DF PROTO=TCP SPT=53337 DPT=443 WINDOW=5840 RES=0x00 SYN
URGP=0
My shorewall configuration:
Zones
#ZONE TYPE OPTIONS IN OUT
# OPTIONS OPTIONS
fw firewall
net ipv4
loc ipv4
Interfaces
#ZONE INTERFACE BROADCAST OPTIONS
loc eth0 detect
tcpflags,nosmurfs,routefilter,logmartians
net eth1 detect
tcpflags,nosmurfs,routefilter,logmartians
Policy
#SOURCE DEST POLICY LOG LEVEL LIMIT:BURST
loc $FW ACCEPT
$FW loc ACCEPT
$FW net ACCEPT
loc net ACCEPT
net all DROP info
# THE FOLLOWING POLICY MUST BE LAST
all all REJECT info
snat
#ACTION SOURCE DEST PROTO PORT IPSEC
MARK USER SWITCH ORIGDEST PROBABILITY
#
# Rules generated from masq file /etc/shorewall/masq by Shorewall
5.0.15.2 - Fri Feb 24 08:52:03 SAST 2017
#
MASQUERADE 192.168.0.0/24 eth1
Rules
DNS(ACCEPT) $FW net
SSH(ACCEPT) loc $FW
SSH(ACCEPT) $FW loc
SSH(ACCEPT) $FW net
SSH(ACCEPT) loc net
HTTP(ACCEPT) $FW net
HTTPS(ACCEPT) $FW net
FTP(ACCEPT) $FW net
FTP(ACCEPT) loc $FW
SMTP(ACCEPT) loc $FW
SMTP(ACCEPT) $FW net:195.190.146.50
DNS(ACCEPT) loc $FW
Ping(DROP) net $FW
Ping(ACCEPT) loc $FW
ACCEPT loc net icmp
ACCEPT $FW net icmp
ACCEPT $FW loc icmp
In sysctl.conf I have
net.ipv4.ip_forward=1
net.ipv4.conf.all.log_martians = 1
$ sudo ifconfig
eth0 Link encap:Ethernet HWaddr b8:27:eb:63:94:ea
inet addr:192.168.0.9 Bcast:192.168.0.255 Mask:255.255.255.0
inet6 addr: fe80::dbe4:63c:a02b:cb1e/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:11223527 errors:0 dropped:0 overruns:0 frame:0
TX packets:4414187 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3648814410 (3.3 GiB) TX bytes:381642127 (363.9 MiB)
eth1 Link encap:Ethernet HWaddr 00:e0:4c:20:bf:5d
inet addr:192.168.1.249 Bcast:192.168.1.255 Mask:255.255.255.0
inet6 addr: fe80::9d48:f754:2113:9a80/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:103887 errors:0 dropped:0 overruns:0 frame:0
TX packets:91137 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:124760139 (118.9 MiB) TX bytes:13325394 (12.7 MiB)
$ ip route ls
default via 192.168.1.1 dev eth1
default via 192.168.1.1 dev eth1 metric 204
192.168.0.0/24 dev eth0 proto kernel scope link src 192.168.0.9
192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.249
192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.249 metric 204
I really do not know the way forward from here. Help will be
appreciated.
Regards
Johann
--
Because experiencing your loyal love is better than life itself,
my lips will praise you. (Psalm 63:3)
[toc] | [next] | [standalone]
| From | Reco <recoverym4n@gmail.com> |
|---|---|
| Date | 2018-03-09 16:20 +0100 |
| Message-ID | <vrrYm-6Lh-1@gated-at.bofh.it> |
| In reply to | #193556 |
Hi. On Fri, Mar 09, 2018 at 04:30:53PM +0200, Johann Spies wrote: > For many years I have used my desktp as a network/firewall server with > two interfaces one facing the internet (through ADSL) and the other the > local network. > > Now I have a fibre connection and for a month both connections will be > available in parallel. > > I have decided to use my Raspberry Pi3 as the firewall/network server in > future but have after many hours failed to do so successfully. A suboptimal idea IMO. These Broadcom chipsets are only good for video output, their 100Mbps "Ethernet" is actually hardwired to USB, and their WiFi is a PITA (I used Raspberry Pi3 as WiFi AP for half a year. Never again). They make good SPI programmers though. If you need a good Debian-friendly router, I suggest buying Linksys ACM 1200, 1900 or 3200. > First I have tried a similar Shorewall setup that I have on my desktop > and after failing successful connections I tried ufw with no success. > > First ufw: > > $ sudo ufw status verbose > Status: active > Logging: on (low) > Default: deny (incoming), allow (outgoing) > New profiles: skip > > To Action From > -- ------ ---- > Anywhere ALLOW IN 192.168.0.0/24 > > Anywhere ALLOW OUT 192.168.0.0/24 > 53/udp ALLOW OUT 192.168.0.0/24 > 443/tcp ALLOW OUT 192.168.0.0/24 > > (Ihave added the last two lines which I thought should not be > necessary). > > I get this in the log: > > Mar 9 12:14:15 pi3 kernel: [403782.469448] [UFW BLOCK] IN=eth0 > OUT=eth1 MAC=b8:27:eb:63:94:ea:1c:5a:3e:e0:29:fe:08:00:45:00:00:3c:50:e8:40:00:3f:06:fb:f2 > SRC=192.168.0.10 DST=207.36.95.10 LEN=60 TOS=0x00 PREC=0x00 TTL=63 > ID=20712 DF PROTO=TCP SPT=53337 DPT=443 WINDOW=5840 RES=0x00 SYN > URGP=0 An "iptables-save" output would be welcome. There are many frontends to netfilter, but nothing beats the original "iptables". Reco
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-03-09 18:40 +0100 |
| Message-ID | <vru9P-88Y-1@gated-at.bofh.it> |
| In reply to | #193557 |
On Friday 09 March 2018 10:18:23 Reco wrote: > Hi. > > On Fri, Mar 09, 2018 at 04:30:53PM +0200, Johann Spies wrote: > > For many years I have used my desktp as a network/firewall server > > with two interfaces one facing the internet (through ADSL) and the > > other the local network. > > > > Now I have a fibre connection and for a month both connections will > > be available in parallel. > > > > I have decided to use my Raspberry Pi3 as the firewall/network > > server in future but have after many hours failed to do so > > successfully. > > A suboptimal idea IMO. These Broadcom chipsets are only good for video > output, their 100Mbps "Ethernet" is actually hardwired to USB, and > their WiFi is a PITA (I used Raspberry Pi3 as WiFi AP for half a year. > Never again). They make good SPI programmers though. > > If you need a good Debian-friendly router, I suggest buying Linksys > ACM 1200, 1900 or 3200. I will also highly recommend the higher end Buffalo's. I have a $70 mail order Netfinity, now quite a few years old, reprogrammed with the real dd-wrt. It has bounced every attack now for around 8 years. And I mean every. I do not have its radio enabled unless my boys are on site with their smartphones. And its not bridged to my local net anyway, only to the internet. > > First I have tried a similar Shorewall setup that I have on my > > desktop and after failing successful connections I tried ufw with no > > success. > > > > First ufw: > > > > $ sudo ufw status verbose > > Status: active > > Logging: on (low) > > Default: deny (incoming), allow (outgoing) > > New profiles: skip > > > > To Action From > > -- ------ ---- > > Anywhere ALLOW IN 192.168.0.0/24 > > > > Anywhere ALLOW OUT 192.168.0.0/24 > > 53/udp ALLOW OUT 192.168.0.0/24 > > 443/tcp ALLOW OUT 192.168.0.0/24 > > > > (Ihave added the last two lines which I thought should not be > > necessary). > > > > I get this in the log: > > > > Mar 9 12:14:15 pi3 kernel: [403782.469448] [UFW BLOCK] IN=eth0 > > OUT=eth1 > > MAC=b8:27:eb:63:94:ea:1c:5a:3e:e0:29:fe:08:00:45:00:00:3c:50:e8:40:0 > >0:3f:06:fb:f2 SRC=192.168.0.10 DST=207.36.95.10 LEN=60 TOS=0x00 > > PREC=0x00 TTL=63 ID=20712 DF PROTO=TCP SPT=53337 DPT=443 WINDOW=5840 > > RES=0x00 SYN URGP=0 > > An "iptables-save" output would be welcome. There are many frontends > to netfilter, but nothing beats the original "iptables". > > Reco -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2018-03-15 03:30 +0100 |
| Message-ID | <vtqOt-4Do-1@gated-at.bofh.it> |
| In reply to | #193560 |
On Fri 09 Mar 2018 at 12:31:35 (-0500), Gene Heskett wrote: > On Friday 09 March 2018 10:18:23 Reco wrote: > > > Hi. > > > > On Fri, Mar 09, 2018 at 04:30:53PM +0200, Johann Spies wrote: > > > For many years I have used my desktp as a network/firewall server > > > with two interfaces one facing the internet (through ADSL) and the > > > other the local network. > > > > > > Now I have a fibre connection and for a month both connections will > > > be available in parallel. > > > > > > I have decided to use my Raspberry Pi3 as the firewall/network > > > server in future but have after many hours failed to do so > > > successfully. > > > > A suboptimal idea IMO. These Broadcom chipsets are only good for video > > output, their 100Mbps "Ethernet" is actually hardwired to USB, and > > their WiFi is a PITA (I used Raspberry Pi3 as WiFi AP for half a year. > > Never again). They make good SPI programmers though. > > > > If you need a good Debian-friendly router, I suggest buying Linksys > > ACM 1200, 1900 or 3200. > > I will also highly recommend the higher end Buffalo's. I have a $70 mail > order Netfinity, now quite a few years old, reprogrammed with the real > dd-wrt. It has bounced every attack now for around 8 years. And I mean > every. I do not have its radio enabled unless my boys are on site with > their smartphones. And its not bridged to my local net anyway, only to > the internet. When you reprogram routers with dd-wrt, does that allow it to do, say, wired bridging even though the manufacturer's formware doesn't allow for that? Or is wired bridging something that requires certain hardware inside the box? What's your bridging topology? I though you might have an article on your website… :) Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2018-03-15 06:20 +0100 |
| Message-ID | <vttt0-6so-5@gated-at.bofh.it> |
| In reply to | #193810 |
On Wednesday 14 March 2018 22:24:26 David Wright wrote: > On Fri 09 Mar 2018 at 12:31:35 (-0500), Gene Heskett wrote: > > On Friday 09 March 2018 10:18:23 Reco wrote: > > > Hi. > > > > > > On Fri, Mar 09, 2018 at 04:30:53PM +0200, Johann Spies wrote: > > > > For many years I have used my desktp as a network/firewall > > > > server with two interfaces one facing the internet (through > > > > ADSL) and the other the local network. > > > > > > > > Now I have a fibre connection and for a month both connections > > > > will be available in parallel. > > > > > > > > I have decided to use my Raspberry Pi3 as the firewall/network > > > > server in future but have after many hours failed to do so > > > > successfully. > > > > > > A suboptimal idea IMO. These Broadcom chipsets are only good for > > > video output, their 100Mbps "Ethernet" is actually hardwired to > > > USB, and their WiFi is a PITA (I used Raspberry Pi3 as WiFi AP for > > > half a year. Never again). They make good SPI programmers though. > > > > > > If you need a good Debian-friendly router, I suggest buying > > > Linksys ACM 1200, 1900 or 3200. > > > > I will also highly recommend the higher end Buffalo's. I have a $70 > > mail order Netfinity, now quite a few years old, reprogrammed with > > the real dd-wrt. It has bounced every attack now for around 8 years. > > And I mean every. I do not have its radio enabled unless my boys are > > on site with their smartphones. And its not bridged to my local net > > anyway, only to the internet. > > When you reprogram routers with dd-wrt, does that allow it to do, say, > wired bridging even though the manufacturer's formware doesn't allow > for that? Or is wired bridging something that requires certain > hardware inside the box? What's your bridging topology? I though you > might have an article on your website… :) With dd-wrt, port forwarding with NAT can be done, a very limited bridging, which is how you see my web site. Its actually this machine. As for the wireless, I only have it bridged to the WAN side of the network, but I'm pretty sure it can be bridged in either or both directions. So this machine, nor any of the others on my home net are not visible to the wireless, only the internet can be used. I don't recall how I do it ATM, because 99% of the time the radio is disabled. If I enable it, one of the neighbors auto connects and can use 80 GB a month w/o giving me a clue unless I am logged into the router annd see the connection lease. So I only enable the radio when my boys are in town. Sorry I can't be more specific but its been yonks since I've programmed it. > Cheers, > David. -- Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Don Armstrong <don@debian.org> |
|---|---|
| Date | 2018-03-15 18:20 +0100 |
| Message-ID | <vtEHL-5EI-1@gated-at.bofh.it> |
| In reply to | #193810 |
On Wed, 14 Mar 2018, David Wright wrote: > When you reprogram routers with dd-wrt, does that allow it to do, say, > wired bridging even though the manufacturer's formware doesn't allow > for that? openwrt and dd-wrt both allow wired bridging[1] (or pseudo-bridging by routing if your wireless hardware doesn't support that). 1: I suppose there might be some network hardware which doesn't support actual bridging of wired interfaces, but I've yet to see such an example. -- Don Armstrong https://www.donarmstrong.com You think to yourself, hey, it's a test tube, for God's sake. Pretty soon, though, the rush from a test tube isn't enough. You want to experiment more and more. Then before you know it, you're laying in the corner of a lab somewhere with a Soxhlet apparatus in one hand, a three neck flask in the other, strung out and begging for grant money. -- Tim Mitchell, 1994 Ig Nobel Chemistry Prize Speech
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2018-03-16 02:50 +0100 |
| Message-ID | <vtMFj-38n-1@gated-at.bofh.it> |
| In reply to | #193838 |
[Multipart message — attachments visible in raw view] — view raw
On Thu 15 Mar 2018 at 10:18:20 (-0700), Don Armstrong wrote:
> On Wed, 14 Mar 2018, David Wright wrote:
> > When you reprogram routers with dd-wrt, does that allow it to do, say,
> > wired bridging even though the manufacturer's formware doesn't allow
> > for that?
>
> openwrt and dd-wrt both allow wired bridging[1] (or pseudo-bridging by
> routing if your wireless hardware doesn't support that).
>
>
> 1: I suppose there might be some network hardware which doesn't support
> actual bridging of wired interfaces, but I've yet to see such an
> example.
I think the router I've been using for the last few years is one.
Although the User Manual from May 2013¹ has a brief section on
bridging, the June 2014² revision is missing that part. Both have
a "Wireless Repeating" link on the figure for Advanced Wireless
Settings, but the link is not present in the actual configuration
screen on the device.
In any case, the May 2013 manual says that to use it as a repeater,
even wired, you have to set security to WEP or None. That's no use.
I wandered into BestBuy and couldn't find much about bridging on
any of their router boxes. (Obviously I'm eschewing so-called
WiFi Wireless Repeaters.) What I'm trying to ascertain is that
all the wired bridging functionality is performed by the software
and not any special hardware in the device.
Required topology:
╲│╱ ╲│╱ ╲│╱
┌───────┐ ┌───────┐ ┌───────┐
│W L╞ CAT5 │W L╞═PC │ ROKUs │
[Modem]══╡A A╞═════════════╡A A╞ │ etc │
│N N╞ │N N╞ └───────┘
│ ╞═PC │ ╞═PC
└───────┘ └───────┘
¹ WNDR3400v3_UM_10May2013.pdf
² WNDR3400v3_UM_19June2014.pdf
(Thanks to Gene, too)
Cheers,
David.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-16 04:30 +0100 |
| Message-ID | <vtOe5-4Mg-7@gated-at.bofh.it> |
| In reply to | #193845 |
On Thursday, March 15, 2018 09:42:25 PM David Wright wrote: > On Thu 15 Mar 2018 at 10:18:20 (-0700), Don Armstrong wrote: > > On Wed, 14 Mar 2018, David Wright wrote: > > > When you reprogram routers with dd-wrt, does that allow it to do, say, > > > wired bridging even though the manufacturer's formware doesn't allow > > > for that? > > > > openwrt and dd-wrt both allow wired bridging[1] (or pseudo-bridging by > > routing if your wireless hardware doesn't support that). > > > > > > 1: I suppose there might be some network hardware which doesn't support > > actual bridging of wired interfaces, but I've yet to see such an > > example. > > I think the router I've been using for the last few years is one. > Although the User Manual from May 2013¹ has a brief section on > bridging, the June 2014² revision is missing that part. Both have > a "Wireless Repeating" link on the figure for Advanced Wireless > Settings, but the link is not present in the actual configuration > screen on the device. > > In any case, the May 2013 manual says that to use it as a repeater, > even wired, you have to set security to WEP or None. That's no use. > > I wandered into BestBuy and couldn't find much about bridging on > any of their router boxes. (Obviously I'm eschewing so-called > WiFi Wireless Repeaters.) What I'm trying to ascertain is that > all the wired bridging functionality is performed by the software > and not any special hardware in the device. > > Required topology: > > > ╲│╱ ╲│╱ ╲│╱ > ┌───────┐ ┌───────┐ ┌───────┐ > │W L╞ CAT5 │W L╞═PC │ ROKUs │ > [Modem]══╡A A╞═════════════╡A A╞ │ etc │ > │N N╞ │N N╞ └───────┘ > │ ╞═PC │ ╞═PC > └───────┘ └───────┘ > > > ¹ WNDR3400v3_UM_10May2013.pdf > ² WNDR3400v3_UM_19June2014.pdf I haven't paid attention to this thread from the beginning, but looking at the sketch, I'm wondering what the purpose of the 2nd router is? Why not instead of a router put a switch there, and then (assuming you need another WiFi access point at that position), plug the 2 PCs and a wireless access point (not sure of the right name) into the switch. (That, in essence. is how my local LAN is setup except I have a router with two switches and two wireless access points, each plugged into one of the switches (different parts of the house).
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2018-03-16 09:50 +0100 |
| Message-ID | <vtTdL-Em-1@gated-at.bofh.it> |
| In reply to | #193848 |
On Thu, 15 Mar 2018 23:26:38 -0400 rhkramer@gmail.com wrote: > On Thursday, March 15, 2018 09:42:25 PM David Wright wrote: > > On Thu 15 Mar 2018 at 10:18:20 (-0700), Don Armstrong wrote: > > > On Wed, 14 Mar 2018, David Wright wrote: > > > > When you reprogram routers with dd-wrt, does that allow it to > > > > do, say, wired bridging even though the manufacturer's formware > > > > doesn't allow for that? > > > > > > openwrt and dd-wrt both allow wired bridging[1] (or > > > pseudo-bridging by routing if your wireless hardware doesn't > > > support that). > > > > > > > > > 1: I suppose there might be some network hardware which doesn't > > > support actual bridging of wired interfaces, but I've yet to see > > > such an example. > > > > I think the router I've been using for the last few years is one. > > Although the User Manual from May 2013¹ has a brief section on > > bridging, the June 2014² revision is missing that part. Both have > > a "Wireless Repeating" link on the figure for Advanced Wireless > > Settings, but the link is not present in the actual configuration > > screen on the device. > > > > In any case, the May 2013 manual says that to use it as a repeater, > > even wired, you have to set security to WEP or None. That's no use. > > > > I wandered into BestBuy and couldn't find much about bridging on > > any of their router boxes. (Obviously I'm eschewing so-called > > WiFi Wireless Repeaters.) What I'm trying to ascertain is that > > all the wired bridging functionality is performed by the software > > and not any special hardware in the device. I'd have thought that hardwired hubs are long gone, that all devices with multiple Ethernet ports are switches and therefore software-based. Indeed, many routers can be configured as VLANs. I had a different problem recently, trying to work out which of a few high-bandwidth 802.11ac routers could be configured in pairs as wireless point-to-point links, which also uses the term 'bridging', and no, they can't all do it. But documentation is usually very poor for the lesser-used functions of most things. 'Bridging' is also used to mean wireless repeating, which is a different thing again. > > > > Required topology: > > > > > > ╲│╱ ╲│╱ ╲│╱ > > ┌───────┐ ┌───────┐ ┌───────┐ > > │W L╞ CAT5 │W L╞═PC │ ROKUs │ > > [Modem]══╡A A╞═════════════╡A A╞ │ etc │ > > │N N╞ │N N╞ └───────┘ > > │ ╞═PC │ ╞═PC > > └───────┘ └───────┘ > > > > > > ¹ WNDR3400v3_UM_10May2013.pdf > > ² WNDR3400v3_UM_19June2014.pdf > > I haven't paid attention to this thread from the beginning, but > looking at the sketch, I'm wondering what the purpose of the 2nd > router is? Why not instead of a router put a switch there, and then > (assuming you need another WiFi access point at that position), plug > the 2 PCs and a wireless access point (not sure of the right name) > into the switch. The network between the routers is a low-security DMZ, with access to the main network only through the port-forwarding of the second router. I have an Internet router, which provides occasional wireless for visitors, and a server acting as a firewall leading to the rest of the network, so there's no wireless access to the main network, though I do have an old wireless router that I can plug in if I need it temporarily. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-16 14:00 +0100 |
| Message-ID | <vtX7I-3P5-49@gated-at.bofh.it> |
| In reply to | #193852 |
On Friday, March 16, 2018 04:48:50 AM Joe wrote: > On Thu, 15 Mar 2018 23:26:38 -0400 > rhkramer@gmail.com wrote: ... > > I haven't paid attention to this thread from the beginning, but > > looking at the sketch, I'm wondering what the purpose of the 2nd > > router is? Why not instead of a router put a switch there, and then > > (assuming you need another WiFi access point at that position), plug > > the 2 PCs and a wireless access point (not sure of the right name) > > into the switch. > > The network between the routers is a low-security DMZ, with access to > the main network only through the port-forwarding of the second router. > > I have an Internet router, which provides occasional wireless for > visitors, and a server acting as a firewall leading to the rest of the > network, so there's no wireless access to the main network, though I do > have an old wireless router that I can plug in if I need it temporarily. Ahh, understood, thanks! I haven't had the need to do that, and I'm not quite sure how I would go about it, but (thinking on the fly now), I might try putting a switch immediately after the modem, with two routers plugged into that, then a router and one firewall (and one WAP) for the DMZ, and the 2nd router, with a stonger firewall, and 2nd WAP for the LAN. (I like switches ;-) (Of course, most routers incorporate a switch, iiuc.)
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-16 14:10 +0100 |
| Message-ID | <vtXho-49w-21@gated-at.bofh.it> |
| In reply to | #193858 |
On Friday, March 16, 2018 08:53:00 AM rhkramer@gmail.com wrote: > I haven't had the need to do that, and I'm not quite sure how I would go > about it, but (thinking on the fly now), I might try putting a switch > immediately after the modem, with two routers plugged into that, then a > router and one firewall (and one WAP) for the DMZ, and the 2nd router, > with a stonger firewall, and 2nd WAP for the LAN. > > (I like switches ;-) (Of course, most routers incorporate a switch, iiuc.) Oh, thinking about it a little more (but not much ;-) , I may be assuming that the modem has the capability to serve as a, I guess you'd call it a DHCP server--mine does. (Although I don't use it that way--in my case, I installed and prefer to use a Ubiquiti edge router immediately after the modem (with the modem in "bridge mode" (in at least one sense of the way "bridge" is used)--I forget all the reasons--oh, now I remember--I have some VOIP phones on the LAN, and the Ubiquiti lets me set up some QOS stuff to give them higher prioritiy.) If my modem didn't have that capability, or maybe even if it did, I might rout everything through a (probably, again, a Ubiquity edge router), then to one router for the DMZ and one router for the LAN. (I wish my brain worked more like it did when I was younger. Well, at least in some respects ;-)
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2018-03-16 14:30 +0100 |
| Message-ID | <vtXAK-4jA-1@gated-at.bofh.it> |
| In reply to | #193852 |
Joe wrote: > [...] > I'd have thought that hardwired hubs are long gone, that all devices > with multiple Ethernet ports are switches and therefore software-based. > Indeed, many routers can be configured as VLANs. Hubs pretty much are. Not entirely sure where you're thinking switches are "software-based" though. Switching is typically done in ASICs these days ... > > I had a different problem recently, trying to work out which of a few > high-bandwidth 802.11ac routers could be configured in pairs as wireless > point-to-point links, which also uses the term 'bridging', and no, they > can't all do it. But documentation is usually very poor for the > lesser-used functions of most things. 'Bridging' is also used to mean > wireless repeating, which is a different thing again. Honestly, I'd never trust an "all-in-one" consumer router for that (even if it "supports" it on the box). Pair of purpose-built radios (e.g. Ubiquiti AirMAX) would probably do best for that situation. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2018-03-31 00:30 +0200 |
| Message-ID | <vzaGZ-4Ec-3@gated-at.bofh.it> |
| In reply to | #193861 |
On Fri, 16 Mar 2018 13:13:30 -0000 (UTC) Dan Purgert <dan@djph.net> wrote: > Joe wrote: > > [...] > > I'd have thought that hardwired hubs are long gone, that all devices > > with multiple Ethernet ports are switches and therefore software-based. > > Indeed, many routers can be configured as VLANs. > > Hubs pretty much are. Not entirely sure where you're thinking switches > are "software-based" though. Switching is typically done in ASICs these > days ... > > > > > I had a different problem recently, trying to work out which of a few > > high-bandwidth 802.11ac routers could be configured in pairs as wireless > > point-to-point links, which also uses the term 'bridging', and no, they > > can't all do it. But documentation is usually very poor for the > > lesser-used functions of most things. 'Bridging' is also used to mean > > wireless repeating, which is a different thing again. > > Honestly, I'd never trust an "all-in-one" consumer router for that (even > if it "supports" it on the box). Pair of purpose-built radios (e.g. > Ubiquiti AirMAX) would probably do best for that situation. FWIW, I recently followed these directions: https://wiki.openwrt.org/doc/recipes/atheroswds to use an old Buffalo WZR-HP-G300NH to bring network connectivity to a server in a location without ethernet cabling and lacking wireless hardware. The Buffalo is configured as a wireless client connecting to the main switch / router / AP (a TP-Link Archer [A]C2600), and the Buffalo's wired switch is bridged to the rest of the network. The TP-Link and Buffalo are both running OpenWRT [LEDE]. I'm not sure if I'm using the terminology correctly, but what this means in practice is that I have one big network, with all wireless and wired clients of the main AP [except those on the guest wireless network, of course], as well as the wired clients of the Buffalo, on the same network. [I haven't enabled access point functionality on the Buffalo, since I don't need it.] Works flawlessly, once I managed to follow the directions correctly ;) This is the opposite of common multi-ap solutions, that use wired backhaul and provide wireless connectivity to clients. In my configuration, I use the 2.4 GHz wireless band for the "backhaul" (my main wireless clients are using the 5 GHz band), and the server is wired to the Buffalo. Celejar
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2018-04-03 13:50 +0200 |
| Message-ID | <vAsBQ-7m1-13@gated-at.bofh.it> |
| In reply to | #194343 |
Celejar wrote: > On Fri, 16 Mar 2018 13:13:30 -0000 (UTC) > Dan Purgert <dan@djph.net> wrote: > >> Joe wrote: >> > [...] >> > I'd have thought that hardwired hubs are long gone, that all devices >> > with multiple Ethernet ports are switches and therefore software-based. >> > Indeed, many routers can be configured as VLANs. >> >> Hubs pretty much are. Not entirely sure where you're thinking switches >> are "software-based" though. Switching is typically done in ASICs these >> days ... >> >> > >> > I had a different problem recently, trying to work out which of a few >> > high-bandwidth 802.11ac routers could be configured in pairs as wireless >> > point-to-point links, which also uses the term 'bridging', and no, they >> > can't all do it. But documentation is usually very poor for the >> > lesser-used functions of most things. 'Bridging' is also used to mean >> > wireless repeating, which is a different thing again. >> >> Honestly, I'd never trust an "all-in-one" consumer router for that (even >> if it "supports" it on the box). Pair of purpose-built radios (e.g. >> Ubiquiti AirMAX) would probably do best for that situation. > > FWIW, I recently followed these directions: > > https://wiki.openwrt.org/doc/recipes/atheroswds > > to use an old Buffalo WZR-HP-G300NH to bring network connectivity to a > server in a location without ethernet cabling and lacking wireless > hardware. The Buffalo is configured as a wireless client connecting to > the main switch / router / AP (a TP-Link Archer [A]C2600), and the > Buffalo's wired switch is bridged to the rest of the network. The > TP-Link and Buffalo are both running OpenWRT [LEDE]. > > I'm not sure if I'm using the terminology correctly [...] Yep, you've got the terms right. Does the buffalo also provide wifi access to other clients close to it? or is it JUST trying to pretend that it's a client device to the TP-Link? -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2018-04-05 19:40 +0200 |
| Message-ID | <vBh1D-7v0-5@gated-at.bofh.it> |
| In reply to | #194442 |
On Tue, 3 Apr 2018 11:30:24 -0000 (UTC) Dan Purgert <dan@djph.net> wrote: > Celejar wrote: > > On Fri, 16 Mar 2018 13:13:30 -0000 (UTC) > > Dan Purgert <dan@djph.net> wrote: > > > >> Joe wrote: > >> > [...] > >> > I'd have thought that hardwired hubs are long gone, that all devices > >> > with multiple Ethernet ports are switches and therefore software-based. > >> > Indeed, many routers can be configured as VLANs. > >> > >> Hubs pretty much are. Not entirely sure where you're thinking switches > >> are "software-based" though. Switching is typically done in ASICs these > >> days ... > >> > >> > > >> > I had a different problem recently, trying to work out which of a few > >> > high-bandwidth 802.11ac routers could be configured in pairs as wireless > >> > point-to-point links, which also uses the term 'bridging', and no, they > >> > can't all do it. But documentation is usually very poor for the > >> > lesser-used functions of most things. 'Bridging' is also used to mean > >> > wireless repeating, which is a different thing again. > >> > >> Honestly, I'd never trust an "all-in-one" consumer router for that (even > >> if it "supports" it on the box). Pair of purpose-built radios (e.g. > >> Ubiquiti AirMAX) would probably do best for that situation. > > > > FWIW, I recently followed these directions: > > > > https://wiki.openwrt.org/doc/recipes/atheroswds > > > > to use an old Buffalo WZR-HP-G300NH to bring network connectivity to a > > server in a location without ethernet cabling and lacking wireless > > hardware. The Buffalo is configured as a wireless client connecting to > > the main switch / router / AP (a TP-Link Archer [A]C2600), and the > > Buffalo's wired switch is bridged to the rest of the network. The > > TP-Link and Buffalo are both running OpenWRT [LEDE]. > > > > I'm not sure if I'm using the terminology correctly [...] > > Yep, you've got the terms right. > > Does the buffalo also provide wifi access to other clients close to it? > or is it JUST trying to pretend that it's a client device to the > TP-Link? I'm not using the Buffalo to provide wireless connectivity to any clients. The page I linked to does have instructions for doing that, but I don't need it. Celejar
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2018-04-06 12:20 +0200 |
| Message-ID | <vBwDn-1jM-1@gated-at.bofh.it> |
| In reply to | #194528 |
Celejar wrote: > On Tue, 3 Apr 2018 11:30:24 -0000 (UTC) > Dan Purgert <dan@djph.net> wrote: >> [...] >> >> Yep, you've got the terms right. >> >> Does the buffalo also provide wifi access to other clients close to it? >> or is it JUST trying to pretend that it's a client device to the >> TP-Link? > > I'm not using the Buffalo to provide wireless connectivity to any > clients. The page I linked to does have instructions for doing that, > but I don't need it. Good deal. Using the buffalo as a wifi repeater would kill throughput for everything connected to it :) -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2018-04-06 16:50 +0200 |
| Message-ID | <vBAQF-3ZY-3@gated-at.bofh.it> |
| In reply to | #194545 |
On Fri 06 Apr 2018 at 10:00:31 (-0000), Dan Purgert wrote: > Celejar wrote: > > On Tue, 3 Apr 2018 11:30:24 -0000 (UTC) > > Dan Purgert <dan@djph.net> wrote: > >> [...] > >> > >> Yep, you've got the terms right. > >> > >> Does the buffalo also provide wifi access to other clients close to it? > >> or is it JUST trying to pretend that it's a client device to the > >> TP-Link? > > > > I'm not using the Buffalo to provide wireless connectivity to any > > clients. The page I linked to does have instructions for doing that, > > but I don't need it. > > Good deal. Using the buffalo as a wifi repeater would kill throughput > for everything connected to it :) I was under the impression that this would work even with consumer grade routers if the backhaul was on a different band or, with dual radio routers, a different channel from the clients. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2018-04-06 18:40 +0200 |
| Message-ID | <vBCz7-5cW-3@gated-at.bofh.it> |
| In reply to | #194551 |
David Wright wrote: > On Fri 06 Apr 2018 at 10:00:31 (-0000), Dan Purgert wrote: >> Celejar wrote: >> > On Tue, 3 Apr 2018 11:30:24 -0000 (UTC) >> > Dan Purgert <dan@djph.net> wrote: >> >> [...] >> >> >> >> Yep, you've got the terms right. >> >> >> >> Does the buffalo also provide wifi access to other clients close to it? >> >> or is it JUST trying to pretend that it's a client device to the >> >> TP-Link? >> > >> > I'm not using the Buffalo to provide wireless connectivity to any >> > clients. The page I linked to does have instructions for doing that, >> > but I don't need it. >> >> Good deal. Using the buffalo as a wifi repeater would kill throughput >> for everything connected to it :) > > I was under the impression that this would work even with consumer > grade routers if the backhaul was on a different band or, with dual > radio routers, a different channel from the clients. > It's a nuance in the semantics of what it means to "repeat" wifi. Suffice to say, in order to "repeat" wifi, you have one radio splitting its time between pretending to be an AP for a client device, and pretending to be a client device to the upstream AP. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2018-04-07 16:00 +0200 |
| Message-ID | <vBWxP-2EM-9@gated-at.bofh.it> |
| In reply to | #194555 |
On Fri 06 Apr 2018 at 16:26:47 (-0000), Dan Purgert wrote: > David Wright wrote: > > On Fri 06 Apr 2018 at 10:00:31 (-0000), Dan Purgert wrote: > >> Celejar wrote: > >> > On Tue, 3 Apr 2018 11:30:24 -0000 (UTC) > >> > Dan Purgert <dan@djph.net> wrote: > >> >> [...] > >> >> > >> >> Yep, you've got the terms right. > >> >> > >> >> Does the buffalo also provide wifi access to other clients close to it? > >> >> or is it JUST trying to pretend that it's a client device to the > >> >> TP-Link? > >> > > >> > I'm not using the Buffalo to provide wireless connectivity to any > >> > clients. The page I linked to does have instructions for doing that, > >> > but I don't need it. > >> > >> Good deal. Using the buffalo as a wifi repeater would kill throughput > >> for everything connected to it :) > > > > I was under the impression that this would work even with consumer > > grade routers if the backhaul was on a different band or, with dual > > radio routers, a different channel from the clients. > > > > It's a nuance in the semantics of what it means to "repeat" wifi. > Suffice to say, in order to "repeat" wifi, you have one radio splitting > its time between pretending to be an AP for a client device, and > pretending to be a client device to the upstream AP. Then I'm not sure why you wrote "Good deal". I'd be wanting the wireless connectivity described above as not needed, though obviously on a separate band/channel. Were you implying that that would kill throughput for everything too? Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2018-04-07 22:30 +0200 |
| Message-ID | <vC2Df-7db-3@gated-at.bofh.it> |
| In reply to | #194573 |
David Wright wrote: > On Fri 06 Apr 2018 at 16:26:47 (-0000), Dan Purgert wrote: >> >> It's a nuance in the semantics of what it means to "repeat" wifi. >> Suffice to say, in order to "repeat" wifi, you have one radio splitting >> its time between pretending to be an AP for a client device, and >> pretending to be a client device to the upstream AP. > > Then I'm not sure why you wrote "Good deal". I'd be wanting the > wireless connectivity described above as not needed, though obviously > on a separate band/channel. Were you implying that that would kill > throughput for everything too? If he's using the buffalo device to "repeat" the wifi signal (which he isn't), then yes the throughput would tank. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web