Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #198752 > unrolled thread

Debian 9 network management

Started byRemigio <linoreale@gmail.com>
First post2018-08-14 10:30 +0200
Last post2018-08-18 12:20 +0200
Articles 12 — 9 participants

Back to article view | Back to linux.debian.user


Contents

  Debian 9 network management Remigio <linoreale@gmail.com> - 2018-08-14 10:30 +0200
    Re: Debian 9 network management Dan Ritter <dsr@randomstring.org> - 2018-08-14 22:30 +0200
      Re: Debian 9 network management Jude DaShiell <jdashiel@panix.com> - 2018-08-15 05:20 +0200
      Re: Debian 9 network management Remigio <linoreale@gmail.com> - 2018-08-20 08:10 +0200
    Re: Debian 9 network management mick crane <mick.crane@gmail.com> - 2018-08-15 08:40 +0200
      Re: Debian 9 network management Alessandro Vesely <vesely@tana.it> - 2018-08-16 12:20 +0200
        Re: Debian 9 network management Zenaan Harkness <zenaan@freedbms.net> - 2018-08-16 12:30 +0200
          Re: Debian 9 network management <tomas@tuxteam.de> - 2018-08-16 12:30 +0200
        Re: Debian 9 network management Reco <recoverym4n@gmail.com> - 2018-08-16 14:10 +0200
          Re: Debian 9 network management Fekete Tamás <fektom@gmail.com> - 2018-08-16 20:10 +0200
          Re: Debian 9 network management Alessandro Vesely <vesely@tana.it> - 2018-08-18 11:30 +0200
            Re: Debian 9 network management Reco <recoverym4n@gmail.com> - 2018-08-18 12:20 +0200

#198752 — Debian 9 network management

FromRemigio <linoreale@gmail.com>
Date2018-08-14 10:30 +0200
SubjectDebian 9 network management
Message-ID<wmCSd-sQ-9@gated-at.bofh.it>
Hi there,
recently I installed Debian 9 Stretch and I noticed that the network configuration management method was substantially changed.
Infact the file /etc/network/interfaces is almost empty despite I've inserted the network parameters during the installation process and network works now.
I tried searching on the web about this topic but I found lots of different answers.
Could you help me please to understand where are network configuration files and how to manage them?
Thank you so much
Regards

-- 
Remigio

[toc] | [next] | [standalone]


#198790

FromDan Ritter <dsr@randomstring.org>
Date2018-08-14 22:30 +0200
Message-ID<wmO70-72a-7@gated-at.bofh.it>
In reply to#198752
On Tue, Aug 14, 2018 at 01:08:40AM -0700, Remigio wrote:
> Hi there,
> recently I installed Debian 9 Stretch and I noticed that the network configuration management method was substantially changed.
> Infact the file /etc/network/interfaces is almost empty despite I've inserted the network parameters during the installation process and network works now.
> I tried searching on the web about this topic but I found lots of different answers.
> Could you help me please to understand where are network configuration files and how to manage them?

/etc/network/interfaces will still work -- and if it does what
you need, it's the best solution in many ways.

However, the default is NetworkManager, which attempts to handle
every conceivable situation automatically.

You can kill the NetworkManager process, apt remove it, and
write up an /etc/network/interfaces (or interfaces.d/* ) file,
reboot and be happy.

-dsr-

[toc] | [prev] | [next] | [standalone]


#198796

FromJude DaShiell <jdashiel@panix.com>
Date2018-08-15 05:20 +0200
Message-ID<wmUvL-2n9-1@gated-at.bofh.it>
In reply to#198790
On Tue, 14 Aug 2018, Dan Ritter wrote:

> Date: Tue, 14 Aug 2018 16:27:03
> From: Dan Ritter <dsr@randomstring.org>
> To: Remigio <linoreale@gmail.com>
> Cc: debian-user@lists.debian.org
> Subject: Re: Debian 9 network management
> Resent-Date: Tue, 14 Aug 2018 20:27:28 +0000 (UTC)
> Resent-From: debian-user@lists.debian.org
>
> On Tue, Aug 14, 2018 at 01:08:40AM -0700, Remigio wrote:
> > Hi there,
> > recently I installed Debian 9 Stretch and I noticed that the network configuration management method was substantially changed.
> > Infact the file /etc/network/interfaces is almost empty despite I've inserted the network parameters during the installation process and network works now.
> > I tried searching on the web about this topic but I found lots of different answers.
> > Could you help me please to understand where are network configuration files and how to manage them?
>
> /etc/network/interfaces will still work -- and if it does what
> you need, it's the best solution in many ways.
>
> However, the default is NetworkManager, which attempts to handle
> every conceivable situation automatically.
>
> You can kill the NetworkManager process, apt remove it, and
> write up an /etc/network/interfaces (or interfaces.d/* ) file,
> reboot and be happy.
>
> -dsr-
>
Another possibility available to shell users is to run nmtui and activate
your chosen chosen connection.  For Wi-Fi instances you'll need to know
and use the password and if it works you'll have a choice to delete the
connection or you could simply exit out of the nmtui program at that
point.  In order to test the connection, the command:
ping -a -c 5 www.google.com
should perhaps generate some beeps and some packet transfer information
on the screen.  If it says something to the effect connection unknown,
you don't yet have network up yet.
Hope this helps.
>

-- 

[toc] | [prev] | [next] | [standalone]


#199053

FromRemigio <linoreale@gmail.com>
Date2018-08-20 08:10 +0200
Message-ID<woLy1-2IC-3@gated-at.bofh.it>
In reply to#198790
Many thanks to you all for your kind replies.
Regards

-- 
Remigio

[toc] | [prev] | [next] | [standalone]


#198802

Frommick crane <mick.crane@gmail.com>
Date2018-08-15 08:40 +0200
Message-ID<wmXDj-48r-1@gated-at.bofh.it>
In reply to#198752
On 2018-08-14 09:08, Remigio wrote:
> Hi there,
> recently I installed Debian 9 Stretch and I noticed that the network
> configuration management method was substantially changed.
> Infact the file /etc/network/interfaces is almost empty despite I've
> inserted the network parameters during the installation process and
> network works now.
> I tried searching on the web about this topic but I found lots of
> different answers.
> Could you help me please to understand where are network configuration
> files and how to manage them?
> Thank you so much
> Regards

I too have been wondering about this and the wiki seems clear.
https://wiki.debian.org/NetworkConfiguration#Setting_up_an_Ethernet_Interface

mick


-- 
Key ID    4BFEBB31

[toc] | [prev] | [next] | [standalone]


#198853

FromAlessandro Vesely <vesely@tana.it>
Date2018-08-16 12:20 +0200
Message-ID<wnnxL-2Bz-11@gated-at.bofh.it>
In reply to#198802
On Wed 15/Aug/2018 08:31:32 +0200 mick crane wrote:
> On 2018-08-14 09:08, Remigio wrote:
>> [...]
>> Could you help me please to understand where are network configuration
>> files and how to manage them?
> 
> I too have been wondering about this and the wiki seems clear.
> https://wiki.debian.org/NetworkConfiguration#Setting_up_an_Ethernet_Interface

However, that doesn't cover how to properly coordinate setting up IP links,
firewall, NAT, and netfilter daemons.  IIRC it is possible, but difficult to
make and maintain, and seemingly fragile.

IMHO, for servers/routers having known IP addresses, it is much easier to roll
a system's own script in /etc/init.d (well, if one uses sysvinit) and set
CONFIGURE_INTERFACES=no in /etc/default/networking.

Ale
-- 

[toc] | [prev] | [next] | [standalone]


#198854

FromZenaan Harkness <zenaan@freedbms.net>
Date2018-08-16 12:30 +0200
Message-ID<wnnHr-2Ew-3@gated-at.bofh.it>
In reply to#198853
On Thu, Aug 16, 2018 at 12:04:28PM +0200, Alessandro Vesely wrote:
> On Wed 15/Aug/2018 08:31:32 +0200 mick crane wrote:
> > On 2018-08-14 09:08, Remigio wrote:
> >> [...]
> >> Could you help me please to understand where are network configuration
> >> files and how to manage them?
> > 
> > I too have been wondering about this and the wiki seems clear.
> > https://wiki.debian.org/NetworkConfiguration#Setting_up_an_Ethernet_Interface
> 
> However, that doesn't cover how to properly coordinate setting up IP links,
> firewall, NAT, and netfilter daemons.  IIRC it is possible, but difficult to
> make and maintain, and seemingly fragile.
> 
> IMHO, for servers/routers having known IP addresses, it is much easier to roll
> a system's own script in /etc/init.d (well, if one uses sysvinit) and set
> CONFIGURE_INTERFACES=no in /etc/default/networking.

Very interesting. /etc/default/networking - something new in the land
of Debian networking to learn about :)

Thank you,

[toc] | [prev] | [next] | [standalone]


#198855

From<tomas@tuxteam.de>
Date2018-08-16 12:30 +0200
Message-ID<wnnHr-2Ew-1@gated-at.bofh.it>
In reply to#198854
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, Aug 16, 2018 at 08:22:34PM +1000, Zenaan Harkness wrote:

[...]

> Very interesting. /etc/default/networking - something new in the land
> of Debian networking to learn about :)

The whole /etc/default is always worth a visit (under Debian, at least).

Cheers
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlt1URkACgkQBcgs9XrR2kai1wCeIUDiiaKmuQWlFlEC6Grz7zH5
pk4An0NlyuMJ5puKeHt0ww/2RndBWKV6
=0AHh
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#198858

FromReco <recoverym4n@gmail.com>
Date2018-08-16 14:10 +0200
Message-ID<wnpgd-3DQ-1@gated-at.bofh.it>
In reply to#198853
	Hi.

On Thu, Aug 16, 2018 at 12:04:28PM +0200, Alessandro Vesely wrote:
> On Wed 15/Aug/2018 08:31:32 +0200 mick crane wrote:
> > On 2018-08-14 09:08, Remigio wrote:
> >> [...]
> >> Could you help me please to understand where are network configuration
> >> files and how to manage them?
> > 
> > I too have been wondering about this and the wiki seems clear.
> > https://wiki.debian.org/NetworkConfiguration#Setting_up_an_Ethernet_Interface
> 
> However, that doesn't cover how to properly coordinate setting up IP links,
> firewall, NAT, and netfilter daemons.

If you're using userspace daemons for netfilter then you're doing it
wrong. For instance, it has forced non-exsistent distinction between the
firewall, NAT and netfilter in your e-mail.

All these are merely the state of running kernel, and while you
certainly need userspace for configuring them, there's no need for any
userspace running for these things to function.

> IIRC it is possible, but difficult to make and maintain, and seemingly
> fragile.

A difficulty is in the eye of the beholder.

Reco

[toc] | [prev] | [next] | [standalone]


#198883

FromFekete Tamás <fektom@gmail.com>
Date2018-08-16 20:10 +0200
Message-ID<wnuSB-6TV-1@gated-at.bofh.it>
In reply to#198858

[Multipart message — attachments visible in raw view] — view raw

Dear Remigio,

your question was:
"Could you help me please to understand where are network configuration
files and how to manage them?"

You can find the configuration files in /etc/NetworkManager/system-connections
.
The files you can find here are profile files.
If you have one network card, and you use these in variable environments,
than each of the environment is going to have an own profile.
It is good, because if you want to use DHCP in an environment but would
like to have a static IP in another, you can have two profile files for the
same network card and you can activate and deactivate the profile when the
need raises with one easy move.

When you are not familiar with NetworkManager yet, you should use 'nmtui'
for configuration. It will fill up your profile files with the correct
syntax based on your settings. Just type in nmtui press enter, and you are
in the network manager configuration.

If you have already some experience, you can switch to nmcli.
It has a huge advance compared to many other commands in linux. nmcli can
use with TAB button. Just type in nmcli and you will get the options you
can continue with (I tried and it works only if you log in user is root. If
you su into root and try to use nmcli doesn't work. I think I will open my
ticket into Gnome team who develops it.)
Don't seeing this little problem, I think it is a phantastic tool.

And if you will become expert, you can edit the profiles by hand in
/etc/NetworkManager/system-connections.

The NetworkManager config lines used in profile files can be viewed in
https://wiki.gnome.org/Projects/NetworkManager in Settings Reference
section. Note, that the link which regards to Debian is nm-settings(5)
which points to
https://developer.gnome.org/NetworkManager/stable/nm-settings.html . Don't
try nm-settings-ifcfg-rh(5) description, because it works only with RedHat
and CentOS.

nm-settings(5) (the correct Debian description) is a bit buggie yet, I
recently opened a ticket to manage some problems I have seen, but I was
able already to find some solution when I really needed. So I encourage you
and anyone to use it.

Hope this answer was useful.

- Tamas Fekete



2018-08-16 14:02 GMT+02:00 Reco <recoverym4n@gmail.com>:

>         Hi.
>
> On Thu, Aug 16, 2018 at 12:04:28PM +0200, Alessandro Vesely wrote:
> > On Wed 15/Aug/2018 08:31:32 +0200 mick crane wrote:
> > > On 2018-08-14 09:08, Remigio wrote:
> > >> [...]
> > >> Could you help me please to understand where are network configuration
> > >> files and how to manage them?
> > >
> > > I too have been wondering about this and the wiki seems clear.
> > > https://wiki.debian.org/NetworkConfiguration#Setting_
> up_an_Ethernet_Interface
> >
> > However, that doesn't cover how to properly coordinate setting up IP
> links,
> > firewall, NAT, and netfilter daemons.
>
> If you're using userspace daemons for netfilter then you're doing it
> wrong. For instance, it has forced non-exsistent distinction between the
> firewall, NAT and netfilter in your e-mail.
>
> All these are merely the state of running kernel, and while you
> certainly need userspace for configuring them, there's no need for any
> userspace running for these things to function.
>
> > IIRC it is possible, but difficult to make and maintain, and seemingly
> > fragile.
>
> A difficulty is in the eye of the beholder.
>
> Reco
>
>

[toc] | [prev] | [next] | [standalone]


#198971

FromAlessandro Vesely <vesely@tana.it>
Date2018-08-18 11:30 +0200
Message-ID<wo5Iu-3eX-3@gated-at.bofh.it>
In reply to#198858
On Thu 16/Aug/2018 14:02:08 +0200 Reco wrote:
> On Thu, Aug 16, 2018 at 12:04:28PM +0200, Alessandro Vesely wrote:
>> On Wed 15/Aug/2018 08:31:32 +0200 mick crane wrote:
>>> 
>>> I too have been wondering about this and the wiki seems clear.
>>> https://wiki.debian.org/NetworkConfiguration#Setting_up_an_Ethernet_Interface
>> 
>> However, that doesn't cover how to properly coordinate setting up IP links,
>> firewall, NAT, and netfilter daemons.
> 
> If you're using userspace daemons for netfilter then you're doing it
> wrong. For instance, it has forced non-exsistent distinction between the
> firewall, NAT and netfilter in your e-mail.
> 
> All these are merely the state of running kernel, and while you
> certainly need userspace for configuring them, there's no need for any
> userspace running for these things to function.

A netfilter queue daemon runs in userspace, but that doesn't make much of a
difference.  The point is in what order things are configured/ enabled, and
which files do you have to edit to check or change the corresponding parameters.

>> IIRC it is possible, but difficult to make and maintain, and seemingly
>> fragile.
> 
> A difficulty is in the eye of the beholder.

So is his/ her learning curve, especially in a system where network management
leans toward casual laptop users rather than server admins —and rightly so.

In any case, a sysadmin has to learn the syntax of say, sysctl, ip, iptables,
vconfig, modprobe, and the like.  Hence, just running the right sequence of
(kernel configuration) commands is more straightforward than trying to discover
how to have them run in the same sequence indirectly, by properly setting a
number of configuration files, methinks.  In addition, the semantics of high
level configuration files seems to be more likely to change across releases
than that of lower level commands.

Best
Ale
-- 

[toc] | [prev] | [next] | [standalone]


#198973

FromReco <recoverym4n@gmail.com>
Date2018-08-18 12:20 +0200
Message-ID<wo6uR-3JP-3@gated-at.bofh.it>
In reply to#198971
	Hi.

On Sat, Aug 18, 2018 at 11:25:15AM +0200, Alessandro Vesely wrote:
> On Thu 16/Aug/2018 14:02:08 +0200 Reco wrote:
> > On Thu, Aug 16, 2018 at 12:04:28PM +0200, Alessandro Vesely wrote:
> >> On Wed 15/Aug/2018 08:31:32 +0200 mick crane wrote:
> >>> 
> >>> I too have been wondering about this and the wiki seems clear.
> >>> https://wiki.debian.org/NetworkConfiguration#Setting_up_an_Ethernet_Interface
> >> 
> >> However, that doesn't cover how to properly coordinate setting up IP links,
> >> firewall, NAT, and netfilter daemons.
> > 
> > If you're using userspace daemons for netfilter then you're doing it
> > wrong. For instance, it has forced non-exsistent distinction between the
> > firewall, NAT and netfilter in your e-mail.
> > 
> > All these are merely the state of running kernel, and while you
> > certainly need userspace for configuring them, there's no need for any
> > userspace running for these things to function.
> 
> A netfilter queue daemon runs in userspace, but that doesn't make much of a
> difference.

True. But said daemon (whenever it's used for NetFlow collection or L7
filtering) is not responsible for the netfilter rules themselves.


> The point is in what order things are configured/ enabled, and
> which files do you have to edit to check or change the corresponding parameters.

Also true. And this is where all userspace "firewall" daemons loose. Not
a single one of them is not able to stomach a single netfilter rules
that was not added by them. At best they ignore it.


> >> IIRC it is possible, but difficult to make and maintain, and seemingly
> >> fragile.
> > 
> > A difficulty is in the eye of the beholder.
> 
> So is his/ her learning curve, especially in a system where network management
> leans toward casual laptop users rather than server admins —and rightly so.

I agree that a server and desktop/laptop are configured differently.
One of the main differences boils down to the fact that one can expect a
netfilter rule set on a server, but it's a rare sight on a
desktop/laptop.
The reasons being - mDNS, SSDP, video casting, IPTV (multicast variant),
torrents etc. Is it possible to allow all this via netfilter? Yes. Would
end-user bother? Hardly, as it's easier to disable all netfilter rules
altogether (in the case of Debian - not to enable them at all).
And if security is wanted by end-user (which is rare in my experience),
there is always intermediate network hardware for that.


> In any case, a sysadmin has to learn the syntax of say, sysctl, ip, iptables,
> vconfig, modprobe, and the like.  Hence, just running the right sequence of
> (kernel configuration) commands is more straightforward than trying to discover
> how to have them run in the same sequence indirectly, by properly setting a
> number of configuration files, methinks.

You forgot to mention one crucial part - troubleshooting. For us, mere
mortals, writing a set of netfilter rules at first try without any
errors is hard if not impossible.
And all these high-level tools are hardly suited for the
troubleshooting.


> In addition, the semantics of high
> level configuration files seems to be more likely to change across releases
> than that of lower level commands.

There's answer for that, but it's hardly for anyone's liking.
RedHat's firewalld. It's tricky, with big 'S' for security in name, and
it's written in Python, but end-user interface is stable.

Reco

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web