Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #193556 > unrolled thread
| Started by | Johann Spies <johann.spies@gmail.com> |
|---|---|
| First post | 2018-03-09 15:40 +0100 |
| Last post | 2018-03-10 10:20 +0100 |
| Articles | 6 on this page of 46 — 11 participants |
Back to article view | Back to linux.debian.user
Help needed with home network configuration Johann Spies <johann.spies@gmail.com> - 2018-03-09 15:40 +0100
Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-03-09 16:20 +0100
Re: Help needed with home network configuration Gene Heskett <gheskett@shentel.net> - 2018-03-09 18:40 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-15 03:30 +0100
Re: Help needed with home network configuration Gene Heskett <gheskett@shentel.net> - 2018-03-15 06:20 +0100
Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-15 18:20 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 02:50 +0100
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 04:30 +0100
Re: Help needed with home network configuration Joe <joe@jretrading.com> - 2018-03-16 09:50 +0100
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 14:00 +0100
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-03-16 14:10 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-16 14:30 +0100
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-03-31 00:30 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-03 13:50 +0200
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-05 19:40 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-06 12:20 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-06 16:50 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-06 18:40 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-07 16:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-07 22:30 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-08 02:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-08 02:50 +0200
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-08 14:10 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-09 12:40 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-04-13 16:20 +0200
Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-04-14 10:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-15 13:40 +0200
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-04-15 14:10 +0200
Re: Help needed with home network configuration Reco <recoverym4n@gmail.com> - 2018-04-15 18:50 +0200
Re: Help needed with home network configuration rhkramer@gmail.com - 2018-04-16 00:50 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-15 13:30 +0200
Re: Help needed with home network configuration Celejar <celejar@gmail.com> - 2018-04-08 14:00 +0200
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-04-09 12:30 +0200
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 17:20 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 15:40 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-16 14:20 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 17:10 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-19 12:00 +0100
Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-16 18:30 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-16 20:20 +0100
Re: Help needed with home network configuration Don Armstrong <don@debian.org> - 2018-03-16 21:00 +0100
Re: Help needed with home network configuration David Wright <deblis@lionunicorn.co.uk> - 2018-03-17 00:50 +0100
Re: Help needed with home network configuration Dan Purgert <dan@djph.net> - 2018-03-09 17:30 +0100
Re: Help needed with home network configuration john doe <johndoe65534@mail.com> - 2018-03-09 20:30 +0100
Re: Help needed with home network configuration Johann Spies <johann.spies@gmail.com> - 2018-03-10 10:10 +0100
Re: Help needed with home network configuration <tomas@tuxteam.de> - 2018-03-10 10:20 +0100
Page 3 of 3 — ← Prev page 1 2 [3]
| From | Don Armstrong <don@debian.org> |
|---|---|
| Date | 2018-03-16 21:00 +0100 |
| Message-ID | <vu3G9-w9-1@gated-at.bofh.it> |
| In reply to | #193870 |
On Fri, 16 Mar 2018, David Wright wrote: > On Fri 16 Mar 2018 at 10:24:36 (-0700), Don Armstrong wrote: > > The software might not support it, but if openwrt or ddwrt can run > > on the hardware, they should support bridging. > > I can make sure the router I buy can run openwrt or ddwrt, but it > would be handy to know if I need to buy two or whether the current one > can at least do the job at one end of the diagram. It's likely that they can run ddwrt or openwrt, but you'd have to check. > > I suggest that you instead run the second router as a switch with an > > attached wireless AP instead, > > So you're saying that a router can run as a switch. This is presumably > by just ignoring the WAN port and using just the LANs?¹ Yes, assuming you disable the dhcp server on the second router. [Or you could bridging the WAN port into the lan bridge, and use all of the ports. You'll need openwrt to do that; most router firmware doesn't support that setup.] > And what does buying a WAP do that the wireless on the router can't > cope with? Nothing; my point was just that's what you should do with your existing equipment. [IE, totally ignore the router functionality of the second router.] > Let's just imagine there's a wireless-proof gauze screen between the > two halves of the house. One router in each half is up to the task of > covering its half but no more. At the moment, one half of the house > (ironically the side with the modem) has next to no coverage. > ¹ ie what's outlined in this one > http://smallbusiness.chron.com/setting-up-wireless-routers-same-ssid-68675.html Right; this is basically how you cover areas where a single AP won't cut it. -- Don Armstrong https://www.donarmstrong.com I would like to be the air that inhabits you for a moment only. I would like to be that unnoticed & that necessary. -- Margaret Atwood "Poetry in Motion" p140
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2018-03-17 00:50 +0100 |
| Message-ID | <vu7gK-2VT-11@gated-at.bofh.it> |
| In reply to | #193871 |
On Fri 16 Mar 2018 at 12:49:16 (-0700), Don Armstrong wrote: > On Fri, 16 Mar 2018, David Wright wrote: > > On Fri 16 Mar 2018 at 10:24:36 (-0700), Don Armstrong wrote: > > > The software might not support it, but if openwrt or ddwrt can run > > > on the hardware, they should support bridging. > > > > I can make sure the router I buy can run openwrt or ddwrt, but it > > would be handy to know if I need to buy two or whether the current one > > can at least do the job at one end of the diagram. > > It's likely that they can run ddwrt or openwrt, but you'd have to check. > > > > I suggest that you instead run the second router as a switch with an > > > attached wireless AP instead, > > > > So you're saying that a router can run as a switch. This is presumably > > by just ignoring the WAN port and using just the LANs?¹ > > Yes, assuming you disable the dhcp server on the second router. [Or you > could bridging the WAN port into the lan bridge, and use all of the > ports. You'll need openwrt to do that; most router firmware doesn't > support that setup.] > > > And what does buying a WAP do that the wireless on the router can't > > cope with? > > Nothing; my point was just that's what you should do with your existing > equipment. [IE, totally ignore the router functionality of the second > router.] > > > Let's just imagine there's a wireless-proof gauze screen between the > > two halves of the house. One router in each half is up to the task of > > covering its half but no more. At the moment, one half of the house > > (ironically the side with the modem) has next to no coverage. > > > ¹ ie what's outlined in this one > > http://smallbusiness.chron.com/setting-up-wireless-routers-same-ssid-68675.html > > Right; this is basically how you cover areas where a single AP won't cut > it. That's all been a great help, thanks. I think I can see paths forward. I'm going to be reading a lot of specs. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Dan Purgert <dan@djph.net> |
|---|---|
| Date | 2018-03-09 17:30 +0100 |
| Message-ID | <vrt46-7r9-11@gated-at.bofh.it> |
| In reply to | #193556 |
Johann Spies wrote: > For many years I have used my desktp as a network/firewall server with > two interfaces one facing the internet (through ADSL) and the other the > local network. > > Now I have a fibre connection and for a month both connections will be > available in parallel. > > I have decided to use my Raspberry Pi3 as the firewall/network server in > future but have after many hours failed to do so successfully. > > [...] > > I really do not know the way forward from here. Help will be > appreciated. > > Regards > Johann The rpi is a little anemic (especially given "fiber" connectivity). If you're looking for a debian-based box, why not something like a Ubiquiti EdgeRouter? I've used them all over the place - quite solid little units, most of them are a steal at twice the price. Granted, they're somewhat geared towards "businesses", and so don't come with wifi built in. You could add a UniFi access point, or if having an "all-in-one" solution is desired, their more "consumer-oriented" AmpliFi line may be a good fit. -- |_|O|_| Registered Linux user #585947 |_|_|O| Github: https://github.com/dpurgert |O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5 4AEE 8E11 DDF3 1279 A281
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2018-03-09 20:30 +0100 |
| Message-ID | <vrvSi-Xf-11@gated-at.bofh.it> |
| In reply to | #193556 |
On 3/9/2018 3:30 PM, Johann Spies wrote: > For many years I have used my desktp as a network/firewall server with > two interfaces one facing the internet (through ADSL) and the other the > local network. > > Now I have a fibre connection and for a month both connections will be > available in parallel. > > I have decided to use my Raspberry Pi3 as the firewall/network server in > future but have after many hours failed to do so successfully. > > First I have tried a similar Shorewall setup that I have on my desktop > and after failing successful connections I tried ufw with no success. > > My shorewall configuration: > > Zones > > #ZONE TYPE OPTIONS IN OUT > # OPTIONS OPTIONS > fw firewall > net ipv4 > loc ipv4 > > Interfaces > #ZONE INTERFACE BROADCAST OPTIONS > loc eth0 detect > tcpflags,nosmurfs,routefilter,logmartians > net eth1 detect > tcpflags,nosmurfs,routefilter,logmartians > > Policy > > #SOURCE DEST POLICY LOG LEVEL LIMIT:BURST > > loc $FW ACCEPT > $FW loc ACCEPT > $FW net ACCEPT > loc net ACCEPT > net all DROP info > # THE FOLLOWING POLICY MUST BE LAST > all all REJECT info > > snat > > #ACTION SOURCE DEST PROTO PORT IPSEC > MARK USER SWITCH ORIGDEST PROBABILITY > # > # Rules generated from masq file /etc/shorewall/masq by Shorewall > 5.0.15.2 - Fri Feb 24 08:52:03 SAST 2017 > # > MASQUERADE 192.168.0.0/24 eth1 > > Rules > > DNS(ACCEPT) $FW net > SSH(ACCEPT) loc $FW > SSH(ACCEPT) $FW loc > SSH(ACCEPT) $FW net > SSH(ACCEPT) loc net > HTTP(ACCEPT) $FW net > HTTPS(ACCEPT) $FW net > FTP(ACCEPT) $FW net > FTP(ACCEPT) loc $FW > SMTP(ACCEPT) loc $FW > SMTP(ACCEPT) $FW net:195.190.146.50 > DNS(ACCEPT) loc $FW > Ping(DROP) net $FW > Ping(ACCEPT) loc $FW > ACCEPT loc net icmp > ACCEPT $FW net icmp > ACCEPT $FW loc icmp > Given your policies your rules file is almost not needed. > In sysctl.conf I have > > net.ipv4.ip_forward=1 > net.ipv4.conf.all.log_martians = 1 > Shorewall takes care of this. You need to set 'IP_FORWARDING=Yes' in /etc/shorewall/shorewall.conf and logmartians is properly set in /etc/shorewall/interfaces. If your willing to play with multiple ISP configuration you should look on shorewall.org and for the corresponding examples provided with the Shorewall. > $ sudo ifconfig > eth0 Link encap:Ethernet HWaddr b8:27:eb:63:94:ea > inet addr:192.168.0.9 Bcast:192.168.0.255 Mask:255.255.255.0 > inet6 addr: fe80::dbe4:63c:a02b:cb1e/64 Scope:Link > UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 > RX packets:11223527 errors:0 dropped:0 overruns:0 frame:0 > TX packets:4414187 errors:0 dropped:0 overruns:0 carrier:0 > collisions:0 txqueuelen:1000 > RX bytes:3648814410 (3.3 GiB) TX bytes:381642127 (363.9 MiB) > > eth1 Link encap:Ethernet HWaddr 00:e0:4c:20:bf:5d > inet addr:192.168.1.249 Bcast:192.168.1.255 Mask:255.255.255.0 > inet6 addr: fe80::9d48:f754:2113:9a80/64 Scope:Link > UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 > RX packets:103887 errors:0 dropped:0 overruns:0 frame:0 > TX packets:91137 errors:0 dropped:0 overruns:0 carrier:0 > collisions:0 txqueuelen:1000 > RX bytes:124760139 (118.9 MiB) TX bytes:13325394 (12.7 MiB) > > $ ip route ls > default via 192.168.1.1 dev eth1 > default via 192.168.1.1 dev eth1 metric 204 > 192.168.0.0/24 dev eth0 proto kernel scope link src 192.168.0.9 > 192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.249 > 192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.249 metric 204 > > > I really do not know the way forward from here. Help will be > appreciated. > If your interfaces are not configured by dhcp in your shorewall config you should use SNAT() and not MASQUERATE in /etc/shorewall/snat. Do you want to buy some new hardware or can you elaborate on what you would like to have? -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | Johann Spies <johann.spies@gmail.com> |
|---|---|
| Date | 2018-03-10 10:10 +0100 |
| Message-ID | <vrIFQ-3Rx-7@gated-at.bofh.it> |
| In reply to | #193556 |
I see I have broken the thread by adding [SOLVED] to the subject.
Just to keep it in this thread:
I have tried a third option: arno-iptables-firewall.
Now I can reach the internet from the local network. I still don't
understand why I could not
get it working with Shorewall which I have used for many years.
Johann
On 10 March 2018 at 11:04, Johann Spies <johann.spies@gmail.com> wrote:
> Thanks Bob.
>
> Regards
> Johann
>
> On 9 March 2018 at 23:50, Bob Weber <bobrweber@gmail.com> wrote:
>> On 3/9/18 2:52 PM, Johann Spies wrote:
>>
>> On 9 March 2018 at 17:31, Bob Weber <bobrweber@gmail.com> wrote:
>>
>> There are other things that you can do once you get the basics working. I
>> have a caching DNS (with dns crypt to opendns to keep dns querys from being
>> forged) and ntp server on my router and I use the shorewall redirect command
>> to force all internal machines to use these servers instead of going outside
>> to the internet for each inside machine.
>>
>> Bob, can you share your dns setup please. My bind9 now gives me problems:
>> e.g. named[25623]: error (network unreachable) resolving
>> 'activity-stream-icons.services.mozilla.com...'
>> but I can ping the outside world.
>>
>> Regards
>> Johann
>>
>> Answers from previous messages also.
>>
>> The eth0 port needs to be static. If it wasn't and dchp changed the address
>> then all the local net machines couldn't connect to it to use it as a router
>> since they need to know its exact address. My interfaces file is as
>> follows:
>>
>> #This file describes the network interfaces available on your system
>> # and how to activate them. For more information, see interfaces(5).
>>
>> # The loopback network interface
>> auto lo
>> iface lo inet loopback
>>
>> auto eth0
>> iface eth0 inet static
>> address 172.16.0.1
>> netmask 255.255.0.0
>> network 172.16.0.0
>> broadcast 172.16.255.255
>> dns-nameservers 127.0.0.1
>> dns-search weberhome.net
>>
>> # auto eth1 -- dont need auto since using netplug
>> iface eth1 inet dhcp
>>
>> ----------------
>> My internal net is 172.16.0.0/16 and is from the days I worked as net admin
>> for a local school so you will have to change these to 192.168.... if you
>> use them (or keep the 172 net for your system). Notice eth1 is DHCP since
>> it has to connect to the ISP via the ISP's routers and addresses. I have a
>> pi3 that I have played with. At one point I had a second ethernet port
>> attached through a usb adapter and I don't remember it being slow or the
>> main port being slow. I even installed KDE and played with a 7" touch
>> display. The only reservation I have about the pi is the flash drive. I
>> just don't trust them... especially for something that just needs to work
>> all the time (that is why I use raid).
>>
>> I'll first post the pertinent lines in my shorewall files (bingo is my
>> firewall machine .. a small form factor intel atom board running debian
>> testing with 2 sata drives in raid1 configuration):
>>
>> ---- interfaces
>> ###############################################################################
>> ?FORMAT 2
>> ###############################################################################
>> #ZONE INTERFACE OPTIONS
>> Ex eth1
>> dhcp,tcpflags,nosmurfs,routefilter,logmartians,sourceroute=0
>>
>> Loc eth0 dhcp,tcpflags,nosmurfs,routefilter,logmartians
>>
>> ---- zones
>> ###############################################################################
>> #ZONE TYPE OPTIONS IN OUT
>> # OPTIONS OPTIONS
>> Bingo firewall # Bingo
>> Loc ipv4 # Local 172 network
>> Ex ipv4 # The Internet
>>
>>
>> ---- policy
>> ###############################################################################
>> #SOURCE><------>DEST<--><------>POLICY<><------>LOG LEVEL<----->LIMIT:BURST
>> Bingo Loc ACCEPT
>> Bingo Ex ACCEPT
>> Loc Ex ACCEPT
>> Ex all DROP info
>>
>> # THE FOLLOWING POLICY MUST BE LAST
>> all all REJECT info
>>
>>
>> --- rules
>> ############################################################################################################################
>> #ACTION><------>SOURCE<><------>
>> DEST<-->PROTO<->DEST<-->SOURCE<><------>ORIGINAL<------>RATE<--><------>USER/<->MARK
>> #<-----><------><------><------><------><------>
>> PORT<-->PORT(S)><------>DEST<--><------>LIMIT<-><------>GROUP
>> #
>> #SECTION ESTABLISHED
>> #
>> #SECTION RELATED
>> #
>> #
>> ?SECTION NEW
>> Ping/ACCEPT Loc all
>> #
>> allowBcast Loc Bingo all
>> HTTP/ACCEPT Loc:172.16.0.0/16 Bingo
>> ACCEPT Loc:172.16.0.0/16 Bingo tcp 3128
>> POP3/ACCEPT Loc:172.16.0.0/16 Bingo
>> SMTP/ACCEPT Loc:172.16.0.0/16 Bingo
>> DNS/ACCEPT Loc:172.16.0.0/16 Bingo
>> Rdate/ACCEPT Loc:172.16.0.0/16 Bingo
>> Auth/ACCEPT Loc:172.16.0.0/16 Bingo
>> SSH/ACCEPT Loc:172.16.0.0/16 Bingo
>> FTP/ACCEPT Loc:172.16.0.0/16 Bingo
>> FTP/ACCEPT Loc:172.16.0.0/16 Ex
>> NTP/ACCEPT Loc:172.16.0.1/16 Bingo
>>
>> REDIRECT Loc 53 tcp,udp 53 -
>>
>> REDIRECT Loc 123 tcp,udp 123 -
>>
>>
>> ----------------------
>> note that the redirect commands above allow me to capture all dns and ntp
>> calls and answer them from my firewall no matter what server the local
>> machine )in loc zone) asks for.
>>
>>
>> ---- snat
>> ###################################################################################################################
>> #ACTION SOURCE DEST PROTO PORT IPSEC MARK
>> USER SWITCH ORIGDEST PROBABILITY
>> #
>> # Rules generated from masq file /etc/shorewall/masq by Shorewall 5.0.15.6 -
>> Fri May 5 14:33:33 EDT 2017
>> #
>> MASQUERADE 172.16.0.1/16 eth1
>>
>> ----------------------------------
>> I wouldn't worry about the iptables -L output except to see that shorewall
>> is working.
>>
>> As far as bind goes the config is split up into several files most of which
>> don't need changing. I have commented out the lines that connect to opendns
>> via dns crypt since I suppose you won't need that. dnscrypt makes a secure
>> (like https) connection to opendns (or others as configured) so that dns
>> queries can't be spoofed and uses the local (to the firewall machine)
>> address 127.0.2.1 which bind can connect to.
>>
>> ---- named.conf.options
>>
>> acl "trusted" {
>> 172.16.0.0/16;
>> 192.168.0.0/16;
>> localhost;
>> };
>>
>>
>> options {
>> directory "/var/cache/bind";
>>
>> // If there is a firewall between you and nameservers you want
>> // to talk to, you may need to fix the firewall to allow multiple
>> // ports to talk. See http://www.kb.cert.org/vuls/id/800113
>>
>> // If your ISP provided one or more IP addresses for stable
>> // nameservers, you probably want to use them as forwarders.
>> // Uncomment the following block, and insert the addresses replacing
>> // the all-0's placeholder.
>>
>> forwarders {
>> // opendns
>> 208.67.222.222;
>> 208.67.220.220;
>> // 127.0.2.1;
>> };
>> forward only;
>>
>>
>> recursion yes;
>>
>> allow-query { any; };
>> allow-recursion { trusted; };
>> allow-query-cache { trusted; };
>>
>> auth-nxdomain no; # conform to RFC1035
>>
>> listen-on { 127.0.0.1; };
>> listen-on { 172.16.0.1; };
>> };
>>
>> The next file is where I set up for my local machines to have a domain
>> called weberhome.net and my bind will serve as master for that domain.
>>
>> ---- named.conf.local
>> /
>> // Do any local configuration here
>> //
>>
>> // Consider adding the 1918 zones here, if they are not used in your
>> // organization
>> //include "/etc/bind/zones.rfc1918";
>>
>> # You can insert further zone records for your own domains below.
>>
>>
>> zone "weberhome.net" in {
>> type master;
>> file "/etc/bind/db.weberhome.net";
>> notify no;
>> };
>>
>> zone "0.16.172.IN-ADDR.ARPA" in {
>> type master;
>> notify no;
>> file "/etc/bind/db.172.16.0";
>> };
>>
>> ---------------------
>> The file /etc/bind/db.weberhome.net has lines like:
>>
>> $TTL 1W
>> @ IN SOA bingo.weberhome.net. postmaster.bingo.weberhome.net.
>> (
>> 2006112600
>> 10800
>> 3600
>> 3600000
>> 86400 )
>> ;
>> bingo IN A 172.16.0.1
>> bob IN A 172.16.0.3
>>
>> So that access to the firewall machine can be just the name bingo (like ping
>> bingo).
>>
>> The file /etc/bind/db.172.16.0 looks like this:
>> $TTL 1W
>> @ IN SOA bingo.weberhome.net. postmaster.bingo.weberhome.net.
>> (
>> 2006112600
>> 10800
>> 3600
>> 3600000
>> 86400 )
>> ;
>> 1 PTR bingo.weberhome.net.
>> 3 PTR bob.weberhome.net.
>>
>> Which allows for reverse dns (the command "host 172.16.0.1" gives back
>> bingo.weberhome.net.
>>
>> Now for the local dhcp server. The file /etc/dhcp/dhcpd.conf looks like
>> this:
>>
>> #
>> # Sample configuration file for ISC dhcpd for Debian
>> #
>> #
>>
>> # The ddns-updates-style parameter controls whether or not the server will
>> # attempt to do a DNS update when a lease is confirmed. We default to the
>> # behavior of the version 2 packages ('none', since DHCP v2 didn't
>> # have support for DDNS.)
>> ddns-update-style none;
>>
>> # option definitions common to all supported networks...
>> #option domain-name "example.org";
>> #option domain-name-servers ns1.example.org, ns2.example.org;
>>
>> option routers 172.16.0.1;
>> option subnet-mask 255.255.0.0;
>>
>> option domain-name "weberhome.net";
>> option domain-name-servers 172.16.0.1;
>> option domain-search "weberhome.net";
>>
>> option time-offset -5; # Eastern Standard Time
>>
>>
>>
>> default-lease-time 600;
>> max-lease-time 7200;
>>
>> # If this DHCP server is the official DHCP server for the local
>> # network, the authoritative directive should be uncommented.
>> authoritative;
>>
>> # Fixed IP addresses can also be specified for hosts.
>>
>> host bob {
>> hardware ethernet 48:5b:39:29:c3:ae;
>> fixed-address 172.16.0.3;
>> }
>>
>> ---------------
>> So that is the setup for firewall, dns and dhcpd. I also use openntpd for
>> the time server on the firewall machine. As for bind if you don't want a
>> local domain then you should only need to change the named.conf.options
>> file.
>>
>> Remember ping is your friend. You need to be able to ping to the outside
>> and inside from the firewall machine. So "ping 208.67.222.222" has to work
>> if you have any chance of getting bind to work.
>>
>> One last thing... the output of my "route -n" command:
>>
>> Kernel IP routing table
>> Destination Gateway Genmask Flags Metric Ref Use
>> Iface
>> 0.0.0.0 24.153.63.1 0.0.0.0 UG 0 0 0 eth1
>> 24.153.63.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1
>> 172.16.0.0 0.0.0.0 255.255.0.0 U 0 0 0 eth0
>>
>> So the first two entries are set up by the ISP (on eth1) and the third
>> should be set up by the firewall's networking ifup configuration run at boot
>> using the static entry in the interfaces file.
>>
>> WOW that's a lot to go through. I hope I haven't forgotten anything.
>>
>> ...Bob
>
>
>
> --
> Because experiencing your loyal love is better than life itself,
> my lips will praise you. (Psalm 63:3)
--
Because experiencing your loyal love is better than life itself,
my lips will praise you. (Psalm 63:3)
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2018-03-10 10:20 +0100 |
| Message-ID | <vrIPv-3WN-3@gated-at.bofh.it> |
| In reply to | #193570 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, Mar 10, 2018 at 11:06:12AM +0200, Johann Spies wrote: > I see I have broken the thread by adding [SOLVED] to the subject. But only because gmail is a broken mail user agent: it seems to have dropped the In-Reply-To header. The change of subject shouldn't be a problem. Cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlqjouwACgkQBcgs9XrR2kbI1gCfQ4BHqBySnJceooezmZfvp5if S8cAmwQpiqhvXniIW/BOVUOocIVUODr5 =qfds -----END PGP SIGNATURE-----
[toc] | [prev] | [standalone]
Page 3 of 3 — ← Prev page 1 2 [3]
Back to top | Article view | linux.debian.user
csiph-web