Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #193556 > unrolled thread

Help needed with home network configuration

Started byJohann Spies <johann.spies@gmail.com>
First post2018-03-09 15:40 +0100
Last post2018-03-10 10:20 +0100
Articles 6 on this page of 46 — 11 participants

Back to article view | Back to linux.debian.user


Contents

  Help needed with home network configuration Johann Spies <johann.spies@gmail.com> - 2018-03-09 15:40 +0100
    Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-03-09 16:20 +0100
      Re: Help needed with home network configuration Gene Heskett <gheskett@shentel.net> - 2018-03-09 18:40 +0100
        Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-15 03:30 +0100
          Re: Help needed with home network configuration Gene Heskett <gheskett@shentel.net> - 2018-03-15 06:20 +0100
          Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-15 18:20 +0100
            Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 02:50 +0100
              Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 04:30 +0100
                Re: Help needed with home network configuration Joe <joe@jretrading.com> - 2018-03-16 09:50 +0100
                  Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 14:00 +0100
                    Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 14:10 +0100
                  Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-16 14:30 +0100
                    Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-03-31 00:30 +0200
                      Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-03 13:50 +0200
                        Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-05 19:40 +0200
                          Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-06 12:20 +0200
                            Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-06 16:50 +0200
                              Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-06 18:40 +0200
                                Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-07 16:00 +0200
                                  Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-07 22:30 +0200
                                    Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-08 02:00 +0200
                                      Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-08 02:50 +0200
                                        Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-08 14:10 +0200
                                          Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-09 12:40 +0200
                                            Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-13 16:20 +0200
                                              Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-04-14 10:00 +0200
                                                Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-15 13:40 +0200
                                                Re: Help needed with home network configuration rhkramer@gmail.com - 2018-04-15 14:10 +0200
                                                  Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-04-15 18:50 +0200
                                                    Re: Help needed with home network configuration rhkramer@gmail.com - 2018-04-16 00:50 +0200
                                              Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-15 13:30 +0200
                            Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-08 14:00 +0200
                              Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-09 12:30 +0200
                  Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 17:20 +0100
                Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 15:40 +0100
              Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-16 14:20 +0100
                Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 17:10 +0100
                  Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-19 12:00 +0100
              Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-16 18:30 +0100
                Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 20:20 +0100
                  Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-16 21:00 +0100
                    Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-17 00:50 +0100
    Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-09 17:30 +0100
    Re: Help needed with home network configuration john doe <johndoe65534@mail.com> - 2018-03-09 20:30 +0100
    Re: Help needed with home network configuration Johann Spies <johann.spies@gmail.com> - 2018-03-10 10:10 +0100
      Re: Help needed with home network configuration <tomas@tuxteam.de> - 2018-03-10 10:20 +0100

Page 3 of 3 — ← Prev page 1 2 [3]


#193871

FromDon Armstrong <don@debian.org>
Date2018-03-16 21:00 +0100
Message-ID<vu3G9-w9-1@gated-at.bofh.it>
In reply to#193870
On Fri, 16 Mar 2018, David Wright wrote:
> On Fri 16 Mar 2018 at 10:24:36 (-0700), Don Armstrong wrote:
> > The software might not support it, but if openwrt or ddwrt can run
> > on the hardware, they should support bridging.
> 
> I can make sure the router I buy can run openwrt or ddwrt, but it
> would be handy to know if I need to buy two or whether the current one
> can at least do the job at one end of the diagram.

It's likely that they can run ddwrt or openwrt, but you'd have to check.

> > I suggest that you instead run the second router as a switch with an
> > attached wireless AP instead,
> 
> So you're saying that a router can run as a switch. This is presumably
> by just ignoring the WAN port and using just the LANs?¹

Yes, assuming you disable the dhcp server on the second router. [Or you
could bridging the WAN port into the lan bridge, and use all of the
ports. You'll need openwrt to do that; most router firmware doesn't
support that setup.]

> And what does buying a WAP do that the wireless on the router can't
> cope with?

Nothing; my point was just that's what you should do with your existing
equipment. [IE, totally ignore the router functionality of the second
router.]

> Let's just imagine there's a wireless-proof gauze screen between the
> two halves of the house. One router in each half is up to the task of
> covering its half but no more. At the moment, one half of the house
> (ironically the side with the modem) has next to no coverage.

> ¹ ie what's outlined in this one
> http://smallbusiness.chron.com/setting-up-wireless-routers-same-ssid-68675.html

Right; this is basically how you cover areas where a single AP won't cut
it.


-- 
Don Armstrong                      https://www.donarmstrong.com

I would like to be the air
that inhabits you for a moment
only. I would like to be that unnoticed
& that necessary.
 -- Margaret Atwood "Poetry in Motion" p140

[toc] | [prev] | [next] | [standalone]


#193872

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2018-03-17 00:50 +0100
Message-ID<vu7gK-2VT-11@gated-at.bofh.it>
In reply to#193871
On Fri 16 Mar 2018 at 12:49:16 (-0700), Don Armstrong wrote:
> On Fri, 16 Mar 2018, David Wright wrote:
> > On Fri 16 Mar 2018 at 10:24:36 (-0700), Don Armstrong wrote:
> > > The software might not support it, but if openwrt or ddwrt can run
> > > on the hardware, they should support bridging.
> > 
> > I can make sure the router I buy can run openwrt or ddwrt, but it
> > would be handy to know if I need to buy two or whether the current one
> > can at least do the job at one end of the diagram.
> 
> It's likely that they can run ddwrt or openwrt, but you'd have to check.
> 
> > > I suggest that you instead run the second router as a switch with an
> > > attached wireless AP instead,
> > 
> > So you're saying that a router can run as a switch. This is presumably
> > by just ignoring the WAN port and using just the LANs?¹
> 
> Yes, assuming you disable the dhcp server on the second router. [Or you
> could bridging the WAN port into the lan bridge, and use all of the
> ports. You'll need openwrt to do that; most router firmware doesn't
> support that setup.]
> 
> > And what does buying a WAP do that the wireless on the router can't
> > cope with?
> 
> Nothing; my point was just that's what you should do with your existing
> equipment. [IE, totally ignore the router functionality of the second
> router.]
> 
> > Let's just imagine there's a wireless-proof gauze screen between the
> > two halves of the house. One router in each half is up to the task of
> > covering its half but no more. At the moment, one half of the house
> > (ironically the side with the modem) has next to no coverage.
> 
> > ¹ ie what's outlined in this one
> > http://smallbusiness.chron.com/setting-up-wireless-routers-same-ssid-68675.html
> 
> Right; this is basically how you cover areas where a single AP won't cut
> it.

That's all been a great help, thanks. I think I can see paths
forward. I'm going to be reading a lot of specs.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#193558

FromDan Purgert <dan@djph.net>
Date2018-03-09 17:30 +0100
Message-ID<vrt46-7r9-11@gated-at.bofh.it>
In reply to#193556
Johann Spies wrote:
> For many years I have used my desktp as a network/firewall server with
> two interfaces one facing the internet (through ADSL) and the other the
> local network.
>
> Now I have a fibre connection and for a month both connections will be
> available in parallel.
>
> I have decided to use my Raspberry Pi3 as the firewall/network server in
> future but have after many hours failed to do so successfully.
>
> [...]
>
> I really do not know the way forward from here.  Help will be
> appreciated.
>
> Regards
> Johann

The rpi is a little anemic (especially given "fiber" connectivity).  If
you're looking for a debian-based box, why not something like a Ubiquiti
EdgeRouter?  I've used them all over the place - quite solid little
units, most of them are a steal at twice the price.

Granted, they're somewhat geared towards "businesses", and so don't come
with wifi built in. You could add a UniFi access point, or if having an
"all-in-one" solution is desired, their more "consumer-oriented" AmpliFi
line may be a good fit.

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281

[toc] | [prev] | [next] | [standalone]


#193562

Fromjohn doe <johndoe65534@mail.com>
Date2018-03-09 20:30 +0100
Message-ID<vrvSi-Xf-11@gated-at.bofh.it>
In reply to#193556
On 3/9/2018 3:30 PM, Johann Spies wrote:
> For many years I have used my desktp as a network/firewall server with
> two interfaces one facing the internet (through ADSL) and the other the
> local network.
> 
> Now I have a fibre connection and for a month both connections will be
> available in parallel.
> 
> I have decided to use my Raspberry Pi3 as the firewall/network server in
> future but have after many hours failed to do so successfully.
> 
> First I have tried a similar Shorewall setup that I have on my desktop
> and after failing successful connections I tried ufw with no success.
> 
> My shorewall configuration:
> 
> Zones
> 
> #ZONE   TYPE    OPTIONS                 IN                      OUT
> #                                       OPTIONS                 OPTIONS
> fw      firewall
> net     ipv4
> loc     ipv4
> 
> Interfaces
> #ZONE   INTERFACE       BROADCAST       OPTIONS
> loc     eth0            detect
> tcpflags,nosmurfs,routefilter,logmartians
> net    eth1            detect
> tcpflags,nosmurfs,routefilter,logmartians
> 
> Policy
> 
> #SOURCE         DEST            POLICY          LOG LEVEL       LIMIT:BURST
> 
> loc             $FW             ACCEPT
> $FW             loc             ACCEPT
> $FW             net             ACCEPT
> loc             net             ACCEPT
> net             all             DROP            info
> # THE FOLLOWING POLICY MUST BE LAST
> all             all             REJECT          info
> 
> snat
> 
> #ACTION         SOURCE          DEST            PROTO   PORT   IPSEC
> MARK   USER    SWITCH  ORIGDEST   PROBABILITY
> #
> # Rules generated from masq file /etc/shorewall/masq by Shorewall
> 5.0.15.2 - Fri Feb 24 08:52:03 SAST 2017
> #
> MASQUERADE      192.168.0.0/24  eth1
> 
> Rules
> 
> DNS(ACCEPT)     $FW             net
> SSH(ACCEPT)     loc             $FW
> SSH(ACCEPT)     $FW             loc
> SSH(ACCEPT)     $FW             net
> SSH(ACCEPT)     loc             net
> HTTP(ACCEPT)     $FW            net
> HTTPS(ACCEPT)     $FW           net
> FTP(ACCEPT)     $FW             net
> FTP(ACCEPT)     loc             $FW
> SMTP(ACCEPT)    loc             $FW
> SMTP(ACCEPT)    $FW             net:195.190.146.50
> DNS(ACCEPT)     loc             $FW
> Ping(DROP)      net             $FW
> Ping(ACCEPT)    loc             $FW
> ACCEPT          loc             net             icmp
> ACCEPT          $FW             net             icmp
> ACCEPT          $FW             loc             icmp
>

Given your policies your rules file is almost not needed.

> In sysctl.conf I have
> 
> net.ipv4.ip_forward=1
> net.ipv4.conf.all.log_martians = 1
> 

Shorewall takes care of this.
You need to set 'IP_FORWARDING=Yes' in /etc/shorewall/shorewall.conf and 
logmartians is properly set in /etc/shorewall/interfaces.

If your willing to play with multiple ISP configuration you should look 
on shorewall.org and for the corresponding examples provided with the 
Shorewall.

> $ sudo ifconfig
> eth0      Link encap:Ethernet  HWaddr b8:27:eb:63:94:ea
>            inet addr:192.168.0.9  Bcast:192.168.0.255  Mask:255.255.255.0
>            inet6 addr: fe80::dbe4:63c:a02b:cb1e/64 Scope:Link
>            UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
>            RX packets:11223527 errors:0 dropped:0 overruns:0 frame:0
>            TX packets:4414187 errors:0 dropped:0 overruns:0 carrier:0
>            collisions:0 txqueuelen:1000
>            RX bytes:3648814410 (3.3 GiB)  TX bytes:381642127 (363.9 MiB)
> 
> eth1      Link encap:Ethernet  HWaddr 00:e0:4c:20:bf:5d
>            inet addr:192.168.1.249  Bcast:192.168.1.255  Mask:255.255.255.0
>            inet6 addr: fe80::9d48:f754:2113:9a80/64 Scope:Link
>            UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
>            RX packets:103887 errors:0 dropped:0 overruns:0 frame:0
>            TX packets:91137 errors:0 dropped:0 overruns:0 carrier:0
>            collisions:0 txqueuelen:1000
>            RX bytes:124760139 (118.9 MiB)  TX bytes:13325394 (12.7 MiB)
> 
> $ ip route ls
> default via 192.168.1.1 dev eth1
> default via 192.168.1.1 dev eth1  metric 204
> 192.168.0.0/24 dev eth0  proto kernel  scope link  src 192.168.0.9
> 192.168.1.0/24 dev eth1  proto kernel  scope link  src 192.168.1.249
> 192.168.1.0/24 dev eth1  proto kernel  scope link  src 192.168.1.249  metric 204
> 
> 
> I really do not know the way forward from here.  Help will be
> appreciated.
> 

If your interfaces are not configured by dhcp in your shorewall config 
you should use SNAT() and not MASQUERATE in /etc/shorewall/snat.

Do you want to buy some new hardware or can you elaborate on what you 
would like to have?

-- 
John Doe

[toc] | [prev] | [next] | [standalone]


#193570

FromJohann Spies <johann.spies@gmail.com>
Date2018-03-10 10:10 +0100
Message-ID<vrIFQ-3Rx-7@gated-at.bofh.it>
In reply to#193556
I see I have broken the thread by adding [SOLVED] to the subject.

Just to keep it in this thread:

I have tried a third option: arno-iptables-firewall.

Now I can reach the internet from the local network.  I still don't
understand why I could not
get it working with Shorewall which I have used for many years.

Johann

On 10 March 2018 at 11:04, Johann Spies <johann.spies@gmail.com> wrote:
> Thanks Bob.
>
> Regards
> Johann
>
> On 9 March 2018 at 23:50, Bob Weber <bobrweber@gmail.com> wrote:
>> On 3/9/18 2:52 PM, Johann Spies wrote:
>>
>> On 9 March 2018 at 17:31, Bob Weber <bobrweber@gmail.com> wrote:
>>
>> There are other things that you can do once you get the basics working.  I
>> have a caching DNS (with dns crypt to opendns to keep dns querys from being
>> forged) and ntp server on my router and I use the shorewall redirect command
>> to force all internal machines to use these servers instead of going outside
>> to the internet for each inside machine.
>>
>> Bob, can you share your dns setup please.  My bind9 now gives me problems:
>> e.g. named[25623]: error (network unreachable) resolving
>> 'activity-stream-icons.services.mozilla.com...'
>> but I can ping the outside world.
>>
>> Regards
>> Johann
>>
>> Answers from previous messages also.
>>
>> The eth0 port needs to be static.  If it wasn't and dchp changed the address
>> then all the local net machines couldn't connect to it to use it as a router
>> since they need to know its exact address.  My interfaces file is as
>> follows:
>>
>> #This file describes the network interfaces available on your system
>> # and how to activate them. For more information, see interfaces(5).
>>
>> # The loopback network interface
>> auto lo
>> iface lo inet loopback
>>
>> auto eth0
>> iface eth0 inet static
>>         address 172.16.0.1
>>         netmask 255.255.0.0
>>         network 172.16.0.0
>>         broadcast 172.16.255.255
>>         dns-nameservers 127.0.0.1
>>         dns-search weberhome.net
>>
>> # auto eth1 -- dont need auto since using netplug
>> iface eth1 inet dhcp
>>
>> ----------------
>> My internal net is 172.16.0.0/16 and is from the days I worked as net admin
>> for a local school so you will have to change these to 192.168.... if you
>> use them (or keep the 172 net for your system).  Notice eth1 is DHCP since
>> it has to connect to the ISP via the ISP's routers and addresses.  I have a
>> pi3 that I have played with.  At one point I had a second ethernet port
>> attached through a usb adapter and I don't remember it being slow or the
>> main port being slow.  I even installed KDE and played with a 7" touch
>> display.  The only reservation I have about the pi is the flash drive.  I
>> just don't trust them... especially for something that just needs to work
>> all the time (that is why I use raid).
>>
>> I'll first post the pertinent  lines in my shorewall files (bingo is my
>> firewall machine .. a small form factor intel atom board running debian
>> testing with 2 sata drives in raid1 configuration):
>>
>> ---- interfaces
>> ###############################################################################
>> ?FORMAT 2
>> ###############################################################################
>> #ZONE   INTERFACE       OPTIONS
>> Ex      eth1
>> dhcp,tcpflags,nosmurfs,routefilter,logmartians,sourceroute=0
>>
>> Loc     eth0            dhcp,tcpflags,nosmurfs,routefilter,logmartians
>>
>> ---- zones
>> ###############################################################################
>> #ZONE   TYPE            OPTIONS         IN                      OUT
>> #                                       OPTIONS                 OPTIONS
>> Bingo   firewall                # Bingo
>> Loc     ipv4                    # Local 172 network
>> Ex      ipv4                    # The Internet
>>
>>
>> ---- policy
>> ###############################################################################
>> #SOURCE><------>DEST<--><------>POLICY<><------>LOG LEVEL<----->LIMIT:BURST
>> Bingo           Loc             ACCEPT
>> Bingo           Ex              ACCEPT
>> Loc             Ex              ACCEPT
>> Ex              all             DROP            info
>>
>> # THE FOLLOWING POLICY MUST BE LAST
>> all             all             REJECT          info
>>
>>
>> --- rules
>> ############################################################################################################################
>> #ACTION><------>SOURCE<><------>
>> DEST<-->PROTO<->DEST<-->SOURCE<><------>ORIGINAL<------>RATE<--><------>USER/<->MARK
>> #<-----><------><------><------><------><------>
>> PORT<-->PORT(S)><------>DEST<--><------>LIMIT<-><------>GROUP
>> #
>> #SECTION ESTABLISHED
>> #
>> #SECTION RELATED
>> #
>> #
>> ?SECTION NEW
>> Ping/ACCEPT     Loc                     all
>> #
>> allowBcast      Loc                     Bingo   all
>> HTTP/ACCEPT     Loc:172.16.0.0/16       Bingo
>> ACCEPT          Loc:172.16.0.0/16       Bingo   tcp     3128
>> POP3/ACCEPT     Loc:172.16.0.0/16       Bingo
>> SMTP/ACCEPT     Loc:172.16.0.0/16       Bingo
>> DNS/ACCEPT      Loc:172.16.0.0/16       Bingo
>> Rdate/ACCEPT    Loc:172.16.0.0/16       Bingo
>> Auth/ACCEPT     Loc:172.16.0.0/16       Bingo
>> SSH/ACCEPT      Loc:172.16.0.0/16       Bingo
>> FTP/ACCEPT      Loc:172.16.0.0/16       Bingo
>> FTP/ACCEPT      Loc:172.16.0.0/16       Ex
>> NTP/ACCEPT      Loc:172.16.0.1/16       Bingo
>>
>> REDIRECT        Loc                     53      tcp,udp  53     -
>>
>> REDIRECT        Loc                     123     tcp,udp  123    -
>>
>>
>> ----------------------
>> note that the redirect commands above allow me to capture all dns and ntp
>> calls and answer them from my firewall no matter what server the local
>> machine )in loc zone) asks for.
>>
>>
>> ---- snat
>> ###################################################################################################################
>> #ACTION         SOURCE          DEST            PROTO   PORT   IPSEC  MARK
>> USER    SWITCH  ORIGDEST   PROBABILITY
>> #
>> # Rules generated from masq file /etc/shorewall/masq by Shorewall 5.0.15.6 -
>> Fri May 5 14:33:33 EDT 2017
>> #
>> MASQUERADE      172.16.0.1/16   eth1
>>
>> ----------------------------------
>> I wouldn't worry about the iptables -L output except to see that shorewall
>> is working.
>>
>> As far as bind goes the config is split up into several files most of which
>> don't need changing.  I have commented out the lines that connect to opendns
>> via dns crypt since I suppose you won't need that.  dnscrypt makes a secure
>> (like https) connection to opendns (or others as configured) so that dns
>> queries can't be spoofed and uses the local (to the firewall machine)
>> address 127.0.2.1 which bind can connect to.
>>
>> ---- named.conf.options
>>
>> acl "trusted" {
>>         172.16.0.0/16;
>>         192.168.0.0/16;
>>         localhost;
>>  };
>>
>>
>> options {
>>         directory "/var/cache/bind";
>>
>>         // If there is a firewall between you and nameservers you want
>>         // to talk to, you may need to fix the firewall to allow multiple
>>         // ports to talk.  See http://www.kb.cert.org/vuls/id/800113
>>
>>         // If your ISP provided one or more IP addresses for stable
>>         // nameservers, you probably want to use them as forwarders.
>>         // Uncomment the following block, and insert the addresses replacing
>>         // the all-0's placeholder.
>>
>>         forwarders {
>>         // opendns
>>            208.67.222.222;
>>            208.67.220.220;
>>         // 127.0.2.1;
>>         };
>>         forward only;
>>
>>
>>         recursion yes;
>>
>>         allow-query { any; };
>>         allow-recursion { trusted; };
>>         allow-query-cache { trusted; };
>>
>>         auth-nxdomain no;    # conform to RFC1035
>>
>>         listen-on  { 127.0.0.1; };
>>         listen-on  { 172.16.0.1; };
>> };
>>
>> The next file is where I set up for my local machines to have a domain
>> called weberhome.net  and my bind will serve as master for that domain.
>>
>> ---- named.conf.local
>> /
>> // Do any local configuration here
>> //
>>
>> // Consider adding the 1918 zones here, if they are not used in your
>> // organization
>> //include "/etc/bind/zones.rfc1918";
>>
>> # You can insert further zone records for your own domains below.
>>
>>
>> zone "weberhome.net" in {
>>         type master;
>>         file "/etc/bind/db.weberhome.net";
>>         notify no;
>>         };
>>
>> zone "0.16.172.IN-ADDR.ARPA" in {
>>         type master;
>>         notify no;
>>         file "/etc/bind/db.172.16.0";
>>         };
>>
>> ---------------------
>> The file /etc/bind/db.weberhome.net has lines like:
>>
>> $TTL 1W
>> @       IN      SOA     bingo.weberhome.net. postmaster.bingo.weberhome.net.
>> (
>>                         2006112600
>>                         10800
>>                         3600
>>                         3600000
>>                         86400 )
>> ;
>> bingo           IN      A       172.16.0.1
>> bob              IN      A       172.16.0.3
>>
>> So that access to the firewall machine can be just the name bingo (like ping
>> bingo).
>>
>> The file /etc/bind/db.172.16.0 looks like this:
>> $TTL 1W
>> @       IN      SOA     bingo.weberhome.net. postmaster.bingo.weberhome.net.
>> (
>>                         2006112600
>>                         10800
>>                         3600
>>                         3600000
>>                         86400 )
>> ;
>> 1               PTR     bingo.weberhome.net.
>> 3               PTR     bob.weberhome.net.
>>
>> Which allows for reverse dns (the command "host 172.16.0.1" gives back
>> bingo.weberhome.net.
>>
>> Now for the local dhcp server.  The file /etc/dhcp/dhcpd.conf looks like
>> this:
>>
>> #
>> # Sample configuration file for ISC dhcpd for Debian
>> #
>> #
>>
>> # The ddns-updates-style parameter controls whether or not the server will
>> # attempt to do a DNS update when a lease is confirmed. We default to the
>> # behavior of the version 2 packages ('none', since DHCP v2 didn't
>> # have support for DDNS.)
>> ddns-update-style none;
>>
>> # option definitions common to all supported networks...
>> #option domain-name "example.org";
>> #option domain-name-servers ns1.example.org, ns2.example.org;
>>
>> option routers                  172.16.0.1;
>> option subnet-mask              255.255.0.0;
>>
>> option domain-name              "weberhome.net";
>> option domain-name-servers      172.16.0.1;
>> option domain-search            "weberhome.net";
>>
>> option time-offset              -5;     # Eastern Standard Time
>>
>>
>>
>> default-lease-time 600;
>> max-lease-time 7200;
>>
>> # If this DHCP server is the official DHCP server for the local
>> # network, the authoritative directive should be uncommented.
>> authoritative;
>>
>> # Fixed IP addresses can also be specified for hosts.
>>
>> host bob {
>>         hardware ethernet 48:5b:39:29:c3:ae;
>>         fixed-address   172.16.0.3;
>> }
>>
>> ---------------
>> So that is the setup for firewall, dns and dhcpd.  I also use openntpd for
>> the time server on the firewall machine.  As for bind if you don't want a
>> local domain then you should only need to change the named.conf.options
>> file.
>>
>> Remember ping is your friend.  You need to be able to ping to the outside
>> and inside from the firewall machine.  So "ping 208.67.222.222" has to work
>> if you have any chance of getting bind to work.
>>
>> One last thing... the output of my "route -n" command:
>>
>> Kernel IP routing table
>> Destination     Gateway         Genmask         Flags Metric Ref    Use
>> Iface
>> 0.0.0.0         24.153.63.1     0.0.0.0         UG    0      0        0 eth1
>> 24.153.63.0     0.0.0.0         255.255.255.0   U     0      0        0 eth1
>> 172.16.0.0      0.0.0.0         255.255.0.0     U     0      0        0 eth0
>>
>> So the first two entries are set up by the ISP (on eth1) and the third
>> should be set up by the firewall's networking ifup configuration run at boot
>> using the static entry in the interfaces file.
>>
>> WOW that's a lot to go through.  I hope I haven't forgotten anything.
>>
>> ...Bob
>
>
>
> --
> Because experiencing your loyal love is better than life itself,
> my lips will praise you.  (Psalm 63:3)



-- 
Because experiencing your loyal love is better than life itself,
my lips will praise you.  (Psalm 63:3)

[toc] | [prev] | [next] | [standalone]


#193571

From<tomas@tuxteam.de>
Date2018-03-10 10:20 +0100
Message-ID<vrIPv-3WN-3@gated-at.bofh.it>
In reply to#193570
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sat, Mar 10, 2018 at 11:06:12AM +0200, Johann Spies wrote:
> I see I have broken the thread by adding [SOLVED] to the subject.

But only because gmail is a broken mail user agent: it seems to have
dropped the In-Reply-To header. The change of subject shouldn't
be a problem.

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlqjouwACgkQBcgs9XrR2kbI1gCfQ4BHqBySnJceooezmZfvp5if
S8cAmwQpiqhvXniIW/BOVUOocIVUODr5
=qfds
-----END PGP SIGNATURE-----

[toc] | [prev] | [standalone]


Page 3 of 3 — ← Prev page 1 2 [3]

Back to top | Article view | linux.debian.user


csiph-web