Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #207564 > unrolled thread
| Started by | Celejar <celejar@gmail.com> |
|---|---|
| First post | 2019-04-16 17:10 +0200 |
| Last post | 2019-04-25 20:20 +0200 |
| Articles | 20 on this page of 37 — 10 participants |
Back to article view | Back to linux.debian.user
Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-16 17:10 +0200
Re: Accessing a host with variable IP addresses / connection types Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-04-16 20:50 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-16 21:30 +0200
Re: Accessing a host with variable IP addresses / connection types Richard Hector <richard@walnut.gen.nz> - 2019-04-17 03:50 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 04:20 +0200
Re: Accessing a host with variable IP addresses / connection types Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> - 2019-04-17 08:40 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 14:20 +0200
Re: Accessing a host with variable IP addresses / connection types Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> - 2019-04-17 15:40 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 18:00 +0200
Re: Accessing a host with variable IP addresses / connection types Joe <joe@jretrading.com> - 2019-04-17 16:10 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 18:00 +0200
Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-17 18:20 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 18:40 +0200
Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-17 18:50 +0200
[OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-04-17 21:40 +0200
Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Curt <curty@free.fr> - 2019-04-17 22:10 +0200
Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Michael Stone <mstone@debian.org> - 2019-04-18 15:00 +0200
Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-04-18 15:20 +0200
Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Michael Stone <mstone@debian.org> - 2019-04-18 15:30 +0200
Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-04-18 22:40 +0200
Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Dan Purgert <dan@djph.net> - 2019-04-18 17:10 +0200
Re: [OT] IP address collisions Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2019-04-19 03:40 +0200
Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) Michael Stone <mstone@debian.org> - 2019-04-18 15:00 +0200
Re: [OT] IP address collisions Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-04-18 20:50 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 00:20 +0200
Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 00:50 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 02:50 +0200
Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 15:00 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 16:10 +0200
Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 16:20 +0200
Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 16:50 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-05-03 23:00 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 16:50 +0200
Re: Accessing a host with variable IP addresses / connection types Richard Hector <richard@walnut.gen.nz> - 2019-04-17 19:00 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 19:40 +0200
Re: Accessing a host with variable IP addresses / connection types Richard Hector <richard@walnut.gen.nz> - 2019-04-20 20:30 +0200
Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-25 20:20 +0200
Page 1 of 2 [1] 2 Next page →
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2019-04-16 17:10 +0200 |
| Subject | Accessing a host with variable IP addresses / connection types |
| Message-ID | <xNxSF-2oL-7@gated-at.bofh.it> |
Hi, I've been bedeviled by this question for a while, but have been unable to figure out a clean, non-hackish solution. It may be an XY problem ... I have a system (laptop, running Debian) that is sometimes connected directly to my LAN, and sometimes connected via VPN (wireguard, to the local router, running OpenWrt). The LAN is 192.168.0.0/24, with the laptop having a fixed, static address in that range (although I'm certainly open to using DHCP, possibly with a fixed address reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed, static address in that range (and wireguard apparently doesn't work with dhcp). I currently have an entry in /etc/hosts on the various LAN hosts assigning a hostname to the laptop's fixed local address, and the LAN hosts can access the laptop via that hostname. [I could alternatively use dnsmasq, which is running on the router regardless.] This obviously doesn't work when the laptop is connected via VPN. [The laptop can access the LAN hosts fine via their hostnames, so I seem to have the routing correctly configured on the laptop and the router.] What I seem to want (but maybe XY?) is some way to adjust the host files (or dnsmasq's information) so that the hostname will resolve to the LAN address when the laptop is connected to the LAN, and the VPN address when it's connected via VPN. If everything was using DHCP, this would be straightforward enough, but as I said, the VPN apparently needs to be configured statically, and not via DHCP. I could obviously use some custom script (using, say, ageas, to modify host files) but this seems hackish. What is a standard, 'correct' way to do this, or more generally, to enable the LAN hosts to access the laptop seamlessly regardless of its IP address and connection type? Celejar
[toc] | [next] | [standalone]
| From | Pascal Hambourg <pascal@plouf.fr.eu.org> |
|---|---|
| Date | 2019-04-16 20:50 +0200 |
| Message-ID | <xNBjA-4lB-7@gated-at.bofh.it> |
| In reply to | #207564 |
Le 16/04/2019 à 17:03, Celejar a écrit : > > What I seem to want (but maybe XY?) is some way to adjust the host > files (or dnsmasq's information) so that the hostname will resolve to > the LAN address when the laptop is connected to the LAN, and the VPN > address when it's connected via VPN. [...] > What is a standard, 'correct' way to do this, or > more generally, to enable the LAN hosts to access the laptop > seamlessly regardless of its IP address and connection type? Dynamic DNS.
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2019-04-16 21:30 +0200 |
| Message-ID | <xNBWh-4Ph-7@gated-at.bofh.it> |
| In reply to | #207582 |
On Tue, 16 Apr 2019 20:45:54 +0200 Pascal Hambourg <pascal@plouf.fr.eu.org> wrote: > Le 16/04/2019 à 17:03, Celejar a écrit : > > > > What I seem to want (but maybe XY?) is some way to adjust the host > > files (or dnsmasq's information) so that the hostname will resolve to > > the LAN address when the laptop is connected to the LAN, and the VPN > > address when it's connected via VPN. [...] > > What is a standard, 'correct' way to do this, or > > more generally, to enable the LAN hosts to access the laptop > > seamlessly regardless of its IP address and connection type? > > Dynamic DNS. Thanks. I thought of that, but I'm going to need more explanation and help. I understand that I can use something like nsupdate to update DNS records, but then I'd need to install and configure a compatible DNS server - the one I currently use, dnsmasq, apparently doesn't support RFC 2136 updates. Is there something I'm missing? Additionally, I'm using simple hostnames, not FQDN names. Will that still work with dynamic DNS? Celejar
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2019-04-17 03:50 +0200 |
| Message-ID | <xNHS1-8nV-3@gated-at.bofh.it> |
| In reply to | #207564 |
[Multipart message — attachments visible in raw view] — view raw
On 17/04/19 3:03 AM, Celejar wrote: > Hi, > > I've been bedeviled by this question for a while, but have been unable > to figure out a clean, non-hackish solution. It may be an XY problem ... > > I have a system (laptop, running Debian) that is sometimes connected > directly to my LAN, and sometimes connected via VPN (wireguard, to the > local router, running OpenWrt). The LAN is 192.168.0.0/24, with the > laptop having a fixed, static address in that range (although I'm > certainly open to using DHCP, possibly with a fixed address > reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed, > static address in that range (and wireguard apparently doesn't work > with dhcp). > > I currently have an entry in /etc/hosts on the various LAN hosts > assigning a hostname to the laptop's fixed local address, and the LAN > hosts can access the laptop via that hostname. [I could alternatively > use dnsmasq, which is running on the router regardless.] This obviously > doesn't work when the laptop is connected via VPN. [The laptop can > access the LAN hosts fine via their hostnames, so I seem to have the > routing correctly configured on the laptop and the router.] > > What I seem to want (but maybe XY?) is some way to adjust the host > files (or dnsmasq's information) so that the hostname will resolve to > the LAN address when the laptop is connected to the LAN, and the VPN > address when it's connected via VPN. If everything was using DHCP, this > would be straightforward enough, but as I said, the VPN apparently > needs to be configured statically, and not via DHCP. I could obviously > use some custom script (using, say, ageas, to modify host files) but > this seems hackish. What is a standard, 'correct' way to do this, or > more generally, to enable the LAN hosts to access the laptop > seamlessly regardless of its IP address and connection type? What about connecting to the VPN even from the LAN? So the VPN address is always available. Another thought I've had in the past, but probably won't work in this case (because one of the locations is on the same side of the router as the other machines) is to give the laptop its own block (on the loopback or maybe a dummy device), and adjust the routing tables (which the wireguard server will probably do). Richard
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2019-04-17 04:20 +0200 |
| Message-ID | <xNIl3-rG-1@gated-at.bofh.it> |
| In reply to | #207605 |
On Wed, 17 Apr 2019 13:45:05 +1200 Richard Hector <richard@walnut.gen.nz> wrote: > On 17/04/19 3:03 AM, Celejar wrote: ... > > What I seem to want (but maybe XY?) is some way to adjust the host > > files (or dnsmasq's information) so that the hostname will resolve to > > the LAN address when the laptop is connected to the LAN, and the VPN > > address when it's connected via VPN. If everything was using DHCP, this > > would be straightforward enough, but as I said, the VPN apparently > > needs to be configured statically, and not via DHCP. I could obviously > > use some custom script (using, say, ageas, to modify host files) but > > this seems hackish. What is a standard, 'correct' way to do this, or > > more generally, to enable the LAN hosts to access the laptop > > seamlessly regardless of its IP address and connection type? > > What about connecting to the VPN even from the LAN? So the VPN address > is always available. I suppose that's an option, but it just seems so terribly inefficient, although I suppose that I likely wouldn't even notice during normal work. > Another thought I've had in the past, but probably won't work in this > case (because one of the locations is on the same side of the router as > the other machines) is to give the laptop its own block (on the loopback > or maybe a dummy device), and adjust the routing tables (which the > wireguard server will probably do). Thanks, Celejar
[toc] | [prev] | [next] | [standalone]
| From | Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> |
|---|---|
| Date | 2019-04-17 08:40 +0200 |
| Message-ID | <xNMoF-2UL-3@gated-at.bofh.it> |
| In reply to | #207564 |
[Multipart message — attachments visible in raw view] — view raw
> Hi, > > I've been bedeviled by this question for a while, but have been unable > to figure out a clean, non-hackish solution. It may be an XY problem ... > > I have a system (laptop, running Debian) that is sometimes connected > directly to my LAN, and sometimes connected via VPN (wireguard, to the > local router, running OpenWrt). The LAN is 192.168.0.0/24, with the > laptop having a fixed, static address in that range (although I'm > certainly open to using DHCP, possibly with a fixed address > reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed, > static address in that range (and wireguard apparently doesn't work > with dhcp). > > I currently have an entry in /etc/hosts on the various LAN hosts > assigning a hostname to the laptop's fixed local address, and the LAN > hosts can access the laptop via that hostname. [I could alternatively > use dnsmasq, which is running on the router regardless.] This obviously > doesn't work when the laptop is connected via VPN. [The laptop can > access the LAN hosts fine via their hostnames, so I seem to have the > routing correctly configured on the laptop and the router.] > > What I seem to want (but maybe XY?) is some way to adjust the host > files (or dnsmasq's information) so that the hostname will resolve to > the LAN address when the laptop is connected to the LAN, and the VPN > address when it's connected via VPN. If everything was using DHCP, this > would be straightforward enough, but as I said, the VPN apparently > needs to be configured statically, and not via DHCP. I could obviously > use some custom script (using, say, ageas, to modify host files) but > this seems hackish. What is a standard, 'correct' way to do this, or > more generally, to enable the LAN hosts to access the laptop > seamlessly regardless of its IP address and connection type? > > Celejar > Hi, A possible solution is to use a bridged VPN, in this case, your laptop will always have the same IP. Kevin
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2019-04-17 14:20 +0200 |
| Message-ID | <xNRHH-6ex-1@gated-at.bofh.it> |
| In reply to | #207618 |
On Wed, 17 Apr 2019 08:37:20 +0200 Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote: > > > Hi, > > > > I've been bedeviled by this question for a while, but have been unable > > to figure out a clean, non-hackish solution. It may be an XY problem ... > > > > I have a system (laptop, running Debian) that is sometimes connected > > directly to my LAN, and sometimes connected via VPN (wireguard, to the > > local router, running OpenWrt). The LAN is 192.168.0.0/24, with the > > laptop having a fixed, static address in that range (although I'm > > certainly open to using DHCP, possibly with a fixed address > > reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed, > > static address in that range (and wireguard apparently doesn't work > > with dhcp). > > > > I currently have an entry in /etc/hosts on the various LAN hosts > > assigning a hostname to the laptop's fixed local address, and the LAN > > hosts can access the laptop via that hostname. [I could alternatively > > use dnsmasq, which is running on the router regardless.] This obviously > > doesn't work when the laptop is connected via VPN. [The laptop can > > access the LAN hosts fine via their hostnames, so I seem to have the > > routing correctly configured on the laptop and the router.] > > > > What I seem to want (but maybe XY?) is some way to adjust the host > > files (or dnsmasq's information) so that the hostname will resolve to > > the LAN address when the laptop is connected to the LAN, and the VPN > > address when it's connected via VPN. If everything was using DHCP, this > > would be straightforward enough, but as I said, the VPN apparently > > needs to be configured statically, and not via DHCP. I could obviously > > use some custom script (using, say, ageas, to modify host files) but > > this seems hackish. What is a standard, 'correct' way to do this, or > > more generally, to enable the LAN hosts to access the laptop > > seamlessly regardless of its IP address and connection type? > > > > Celejar > > > Hi, > > A possible solution is to use a bridged VPN, in this case, your laptop > will always have the same IP. Thanks. I can't seem to find much information about this - can you elaborate, or point me to a link? [I'm not a networking expert.] Currently, my LAN is 192.168.0.0/24, which is also the addressing scheme of some of the networks out of my control that I'm setting up a VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid address collisions with these other networks. It did occur to me to consider using a different address space, for the VPN or perhaps for the whole home LAN, but I'd rather not take that step just to solve what seems a relatively simple problem unless absolutely necessary Celejar
[toc] | [prev] | [next] | [standalone]
| From | Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> |
|---|---|
| Date | 2019-04-17 15:40 +0200 |
| Message-ID | <xNSX7-6Tk-1@gated-at.bofh.it> |
| In reply to | #207635 |
[Multipart message — attachments visible in raw view] — view raw
Le 17/04/2019 à 14:15, Celejar a écrit : > On Wed, 17 Apr 2019 08:37:20 +0200 > Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote: > >>> Hi, >>> >>> I've been bedeviled by this question for a while, but have been unable >>> to figure out a clean, non-hackish solution. It may be an XY problem ... >>> >>> I have a system (laptop, running Debian) that is sometimes connected >>> directly to my LAN, and sometimes connected via VPN (wireguard, to the >>> local router, running OpenWrt). The LAN is 192.168.0.0/24, with the >>> laptop having a fixed, static address in that range (although I'm >>> certainly open to using DHCP, possibly with a fixed address >>> reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed, >>> static address in that range (and wireguard apparently doesn't work >>> with dhcp). >>> >>> I currently have an entry in /etc/hosts on the various LAN hosts >>> assigning a hostname to the laptop's fixed local address, and the LAN >>> hosts can access the laptop via that hostname. [I could alternatively >>> use dnsmasq, which is running on the router regardless.] This obviously >>> doesn't work when the laptop is connected via VPN. [The laptop can >>> access the LAN hosts fine via their hostnames, so I seem to have the >>> routing correctly configured on the laptop and the router.] >>> >>> What I seem to want (but maybe XY?) is some way to adjust the host >>> files (or dnsmasq's information) so that the hostname will resolve to >>> the LAN address when the laptop is connected to the LAN, and the VPN >>> address when it's connected via VPN. If everything was using DHCP, this >>> would be straightforward enough, but as I said, the VPN apparently >>> needs to be configured statically, and not via DHCP. I could obviously >>> use some custom script (using, say, ageas, to modify host files) but >>> this seems hackish. What is a standard, 'correct' way to do this, or >>> more generally, to enable the LAN hosts to access the laptop >>> seamlessly regardless of its IP address and connection type? >>> >>> Celejar >>> >> Hi, >> >> A possible solution is to use a bridged VPN, in this case, your laptop >> will always have the same IP. > Thanks. I can't seem to find much information about this - can you > elaborate, or point me to a link? [I'm not a networking expert.] > > Currently, my LAN is 192.168.0.0/24, which is also the addressing > scheme of some of the networks out of my control that I'm setting up a > VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid > address collisions with these other networks. It did occur to me to > consider using a different address space, for the VPN or perhaps for the > whole home LAN, but I'd rather not take that step just to solve what > seems a relatively simple problem unless absolutely necessary > > Celejar > Celjar, You can find some explaination at https://openvpn.net/community-resources/ethernet-bridging/ Using common network adressing will often give address collisions when using VPN (routed or bridged VPN), like if on your home network and remote network you have 2 machin with same IP, one of them will not be reachable (depending of your routing table). Kevin
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2019-04-17 18:00 +0200 |
| Message-ID | <xNV8B-87j-5@gated-at.bofh.it> |
| In reply to | #207637 |
On Wed, 17 Apr 2019 15:29:50 +0200 Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote: > > Le 17/04/2019 à 14:15, Celejar a écrit : > > On Wed, 17 Apr 2019 08:37:20 +0200 > > Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote: > > > >>> Hi, > >>> > >>> I've been bedeviled by this question for a while, but have been unable > >>> to figure out a clean, non-hackish solution. It may be an XY problem ... > >>> > >>> I have a system (laptop, running Debian) that is sometimes connected > >>> directly to my LAN, and sometimes connected via VPN (wireguard, to the > >>> local router, running OpenWrt). The LAN is 192.168.0.0/24, with the > >>> laptop having a fixed, static address in that range (although I'm > >>> certainly open to using DHCP, possibly with a fixed address > >>> reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed, > >>> static address in that range (and wireguard apparently doesn't work > >>> with dhcp). > >>> > >>> I currently have an entry in /etc/hosts on the various LAN hosts > >>> assigning a hostname to the laptop's fixed local address, and the LAN > >>> hosts can access the laptop via that hostname. [I could alternatively > >>> use dnsmasq, which is running on the router regardless.] This obviously > >>> doesn't work when the laptop is connected via VPN. [The laptop can > >>> access the LAN hosts fine via their hostnames, so I seem to have the > >>> routing correctly configured on the laptop and the router.] > >>> > >>> What I seem to want (but maybe XY?) is some way to adjust the host > >>> files (or dnsmasq's information) so that the hostname will resolve to > >>> the LAN address when the laptop is connected to the LAN, and the VPN > >>> address when it's connected via VPN. If everything was using DHCP, this > >>> would be straightforward enough, but as I said, the VPN apparently > >>> needs to be configured statically, and not via DHCP. I could obviously > >>> use some custom script (using, say, ageas, to modify host files) but > >>> this seems hackish. What is a standard, 'correct' way to do this, or > >>> more generally, to enable the LAN hosts to access the laptop > >>> seamlessly regardless of its IP address and connection type? > >>> > >>> Celejar > >>> > >> Hi, > >> > >> A possible solution is to use a bridged VPN, in this case, your laptop > >> will always have the same IP. > > Thanks. I can't seem to find much information about this - can you > > elaborate, or point me to a link? [I'm not a networking expert.] > > > > Currently, my LAN is 192.168.0.0/24, which is also the addressing > > scheme of some of the networks out of my control that I'm setting up a > > VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid > > address collisions with these other networks. It did occur to me to > > consider using a different address space, for the VPN or perhaps for the > > whole home LAN, but I'd rather not take that step just to solve what > > seems a relatively simple problem unless absolutely necessary > > > > Celejar > > > Celjar, > > You can find some explaination at > https://openvpn.net/community-resources/ethernet-bridging/ Thanks. I'm trying to figure out whether Wireguard, and OpenWrt's implementation of it in particular, supports bridging. > Using common network adressing will often give address collisions when > using VPN (routed or bridged VPN), like if on your home network and > remote network you have 2 machin with same IP, one of them will not be > reachable (depending of your routing table). I think that this won't be much of an issue - when I'm on remote networks, there typically aren't any hosts on those networks that I need to access. Celejar
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2019-04-17 16:10 +0200 |
| Message-ID | <xNTq9-7iL-5@gated-at.bofh.it> |
| In reply to | #207635 |
On Wed, 17 Apr 2019 08:15:09 -0400 Celejar <celejar@gmail.com> wrote: > Currently, my LAN is 192.168.0.0/24, which is also the addressing > scheme of some of the networks out of my control that I'm setting up a > VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid > address collisions with these other networks. It did occur to me to > consider using a different address space, for the VPN or perhaps for > the whole home LAN, but I'd rather not take that step just to solve > what seems a relatively simple problem unless absolutely necessary > If you do get pushed to doing that, there are a few commonly used networks that you should avoid. 10. is often used with a netmask of /24 or /8, and the latter precludes all 10. variants. Of the 192.168. groups, 0, 1, 8, 16 and 254 are often used, best use something quite random like 192.168.137.0/24. Probably better still is one of the 172.16-172.31 groups, which don't seem to be used as defaults very often. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2019-04-17 18:00 +0200 |
| Message-ID | <xNV8B-87j-7@gated-at.bofh.it> |
| In reply to | #207639 |
On Wed, 17 Apr 2019 14:59:53 +0100 Joe <joe@jretrading.com> wrote: > On Wed, 17 Apr 2019 08:15:09 -0400 > Celejar <celejar@gmail.com> wrote: > > > > Currently, my LAN is 192.168.0.0/24, which is also the addressing > > scheme of some of the networks out of my control that I'm setting up a > > VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid > > address collisions with these other networks. It did occur to me to > > consider using a different address space, for the VPN or perhaps for > > the whole home LAN, but I'd rather not take that step just to solve > > what seems a relatively simple problem unless absolutely necessary > > > > If you do get pushed to doing that, there are a few commonly used > networks that you should avoid. 10. is often used with a netmask of > /24 or /8, and the latter precludes all 10. variants. Of the 192.168. > groups, 0, 1, 8, 16 and 254 are often used, best use something quite > random like 192.168.137.0/24. > > Probably better still is one of the 172.16-172.31 groups, which don't > seem to be used as defaults very often. Thanks. When I first set up the VPN, I did some reading about this, and I was rather shocked to see that there was no definitive solution to avoid address collisions, just recommendations like yours to try to make a good guess about it ... Celejar
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2019-04-17 18:20 +0200 |
| Message-ID | <xNVrX-8tC-1@gated-at.bofh.it> |
| In reply to | #207645 |
On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote: >Thanks. When I first set up the VPN, I did some reading about this, and >I was rather shocked to see that there was no definitive solution to >avoid address collisions Sure there is--globally unique IPs.
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2019-04-17 18:40 +0200 |
| Message-ID | <xNVLj-8l-3@gated-at.bofh.it> |
| In reply to | #207648 |
On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> wrote: > On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote: > >Thanks. When I first set up the VPN, I did some reading about this, and > >I was rather shocked to see that there was no definitive solution to > >avoid address collisions > > Sure there is--globally unique IPs. I assume you're referring to IPv6? I was referring to IPv4. Celejar
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2019-04-17 18:50 +0200 |
| Message-ID | <xNVUZ-bL-5@gated-at.bofh.it> |
| In reply to | #207649 |
On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote: >On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> wrote: > >> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote: >> >Thanks. When I first set up the VPN, I did some reading about this, and >> >I was rather shocked to see that there was no definitive solution to >> >avoid address collisions >> >> Sure there is--globally unique IPs. > >I assume you're referring to IPv6? I was referring to IPv4. It applies to both, though we've run out of IPv4. There's no other way to guarantee the absence of network collisions.
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <pascal@plouf.fr.eu.org> |
|---|---|
| Date | 2019-04-17 21:40 +0200 |
| Subject | [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) |
| Message-ID | <xNYzv-1Qv-1@gated-at.bofh.it> |
| In reply to | #207650 |
Le 17/04/2019 à 18:42, Michael Stone a écrit : > On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote: >> On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> >> wrote: >> >>> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote: >>> >I was rather shocked to see that there was no definitive solution to >>> >avoid address collisions >>> >>> Sure there is--globally unique IPs. >> >> I assume you're referring to IPv6? I was referring to IPv4. > > It applies to both, though we've run out of IPv4. There's no other way > to guarantee the absence of network collisions. A properly generated IPv6 ULA (Unique Local Address) prefix is unlikely to have collisions.
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2019-04-17 22:10 +0200 |
| Subject | Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) |
| Message-ID | <xNZ2y-2jV-3@gated-at.bofh.it> |
| In reply to | #207658 |
On 2019-04-17, Pascal Hambourg <pascal@plouf.fr.eu.org> wrote: > Le 17/04/2019 à 18:42, Michael Stone a écrit : >> On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote: >>> On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> >>> wrote: >>> >>>> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote: >>>> >I was rather shocked to see that there was no definitive solution to >>>> >avoid address collisions >>>> >>>> Sure there is--globally unique IPs. >>> >>> I assume you're referring to IPv6? I was referring to IPv4. >> >> It applies to both, though we've run out of IPv4. There's no other way >> to guarantee the absence of network collisions. > > A properly generated IPv6 ULA (Unique Local Address) prefix is unlikely > to have collisions. > I thought that was exactly what he was saying.
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2019-04-18 15:00 +0200 |
| Subject | Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) |
| Message-ID | <xOeNY-3qv-3@gated-at.bofh.it> |
| In reply to | #207659 |
On Wed, Apr 17, 2019 at 08:06:05PM -0000, Curt wrote: >On 2019-04-17, Pascal Hambourg <pascal@plouf.fr.eu.org> wrote: >> Le 17/04/2019 à 18:42, Michael Stone a écrit : >>> On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote: >>>> On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> >>>> wrote: >>>> >>>>> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote: >>>>> >I was rather shocked to see that there was no definitive solution to >>>>> >avoid address collisions >>>>> >>>>> Sure there is--globally unique IPs. >>>> >>>> I assume you're referring to IPv6? I was referring to IPv4. >>> >>> It applies to both, though we've run out of IPv4. There's no other way >>> to guarantee the absence of network collisions. >> >> A properly generated IPv6 ULA (Unique Local Address) prefix is unlikely >> to have collisions. >> > >I thought that was exactly what he was saying. No, the ULA is the IPv6 equivalent of RFC1918 space--you can use it internally without central registration by choosing a subnet from fd00::/8. The space is so much larger that it's much less likely that two sites would pick the same prefix, but there are no guarantees.
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2019-04-18 15:20 +0200 |
| Subject | Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) |
| Message-ID | <xOf7j-3N1-1@gated-at.bofh.it> |
| In reply to | #207669 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Apr 18, 2019 at 7:57 AM Michael Stone <mstone@debian.org> wrote: > > No, the ULA is the IPv6 equivalent of RFC1918 space--you can use it > internally without central registration by choosing a subnet from > fd00::/8. The space is so much larger that it's much less likely that > two sites would pick the same prefix, but there are no guarantees. > > But isn't it irrelevant whether they pick the same prefix or not? Routers that respect ULA and RFC1918 shouldn't route any traffic destined to them off the logical subnet. Right?
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2019-04-18 15:30 +0200 |
| Subject | Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) |
| Message-ID | <xOfh0-3Qf-1@gated-at.bofh.it> |
| In reply to | #207671 |
On Thu, Apr 18, 2019 at 08:12:04AM -0500, Nicholas Geovanis wrote: >But isn't it irrelevant whether they pick the same prefix or not? Routers that >respect ULA and RFC1918 shouldn't route any traffic destined to them off the >logical subnet. Right? If it didn't matter, people wouldn't keep looking for solutions, right? In theory, you're right. In the real world, companies merge, etc., and stuff that started independently gets VPN'd together and things break.
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2019-04-18 22:40 +0200 |
| Subject | Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types) |
| Message-ID | <xOlZ8-7Qi-3@gated-at.bofh.it> |
| In reply to | #207672 |
[Multipart message — attachments visible in raw view] — view raw
On Thu, Apr 18, 2019, 8:29 AM Michael Stone <mstone@debian.org> wrote: > On Thu, Apr 18, 2019 at 08:12:04AM -0500, Nicholas Geovanis wrote: > >But isn't it irrelevant whether they pick the same prefix or not? Routers > that > >respect ULA and RFC1918 shouldn't route any traffic destined to them off > the > >logical subnet. Right? > > If it didn't matter, people wouldn't keep looking for solutions, right? > In theory, you're right. In the real world, companies merge, etc., and > stuff that started independently gets VPN'd together and things break. > This is correct as far as it goes. If corps merge and their internal IP addresses overlap, they sort it out. There is no addressing based solution other than creative routing. >
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web