Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #207564 > unrolled thread

Accessing a host with variable IP addresses / connection types

Started byCelejar <celejar@gmail.com>
First post2019-04-16 17:10 +0200
Last post2019-04-25 20:20 +0200
Articles 20 on this page of 37 — 10 participants

Back to article view | Back to linux.debian.user


Contents

  Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-16 17:10 +0200
    Re: Accessing a host with variable IP addresses / connection types Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-04-16 20:50 +0200
      Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-16 21:30 +0200
    Re: Accessing a host with variable IP addresses / connection types Richard Hector <richard@walnut.gen.nz> - 2019-04-17 03:50 +0200
      Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 04:20 +0200
    Re: Accessing a host with variable IP addresses / connection types Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> - 2019-04-17 08:40 +0200
      Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 14:20 +0200
        Re: Accessing a host with variable IP addresses / connection types Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> - 2019-04-17 15:40 +0200
          Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 18:00 +0200
        Re: Accessing a host with variable IP addresses / connection types Joe <joe@jretrading.com> - 2019-04-17 16:10 +0200
          Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 18:00 +0200
            Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-17 18:20 +0200
              Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 18:40 +0200
                Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-17 18:50 +0200
                  [OT] IP address collisions (was: Accessing a host with variable IP  addresses / connection types) Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-04-17 21:40 +0200
                    Re: [OT] IP address collisions (was: Accessing a host with variable  IP addresses / connection types) Curt <curty@free.fr> - 2019-04-17 22:10 +0200
                      Re: [OT] IP address collisions (was: Accessing a host with variable  IP addresses / connection types) Michael Stone <mstone@debian.org> - 2019-04-18 15:00 +0200
                        Re: [OT] IP address collisions (was: Accessing a host with variable  IP addresses / connection types) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-04-18 15:20 +0200
                          Re: [OT] IP address collisions (was: Accessing a host with variable  IP addresses / connection types) Michael Stone <mstone@debian.org> - 2019-04-18 15:30 +0200
                            Re: [OT] IP address collisions (was: Accessing a host with variable  IP addresses / connection types) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-04-18 22:40 +0200
                          Re: [OT] IP address collisions (was: Accessing a host with variable   IP addresses / connection types) Dan Purgert <dan@djph.net> - 2019-04-18 17:10 +0200
                            Re: [OT] IP address collisions Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2019-04-19 03:40 +0200
                    Re: [OT] IP address collisions (was: Accessing a host with variable  IP addresses / connection types) Michael Stone <mstone@debian.org> - 2019-04-18 15:00 +0200
                      Re: [OT] IP address collisions Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-04-18 20:50 +0200
                  Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 00:20 +0200
                    Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 00:50 +0200
                      Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 02:50 +0200
                        Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 15:00 +0200
                          Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 16:10 +0200
                            Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 16:20 +0200
                              Re: Accessing a host with variable IP addresses / connection types Michael Stone <mstone@debian.org> - 2019-04-18 16:50 +0200
                                Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-05-03 23:00 +0200
                              Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-18 16:50 +0200
        Re: Accessing a host with variable IP addresses / connection types Richard Hector <richard@walnut.gen.nz> - 2019-04-17 19:00 +0200
          Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-17 19:40 +0200
            Re: Accessing a host with variable IP addresses / connection types Richard Hector <richard@walnut.gen.nz> - 2019-04-20 20:30 +0200
              Re: Accessing a host with variable IP addresses / connection types Celejar <celejar@gmail.com> - 2019-04-25 20:20 +0200

Page 1 of 2  [1] 2  Next page →


#207564 — Accessing a host with variable IP addresses / connection types

FromCelejar <celejar@gmail.com>
Date2019-04-16 17:10 +0200
SubjectAccessing a host with variable IP addresses / connection types
Message-ID<xNxSF-2oL-7@gated-at.bofh.it>
Hi,

I've been bedeviled by this question for a while, but have been unable
to figure out a clean, non-hackish solution. It may be an XY problem ...

I have a system (laptop, running Debian) that is sometimes connected
directly to my LAN, and sometimes connected via VPN (wireguard, to the
local router, running OpenWrt). The LAN is 192.168.0.0/24, with the
laptop having a fixed, static address in that range (although I'm
certainly open to using DHCP, possibly with a fixed address
reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed,
static address in that range (and wireguard apparently doesn't work
with dhcp).

I currently have an entry in /etc/hosts on the various LAN hosts
assigning a hostname to the laptop's fixed local address, and the LAN
hosts can access the laptop via that hostname. [I could alternatively
use dnsmasq, which is running on the router regardless.] This obviously
doesn't work when the laptop is connected via VPN. [The laptop can
access the LAN hosts fine via their hostnames, so I seem to have the
routing correctly configured on the laptop and the router.]

What I seem to want (but maybe XY?) is some way to adjust the host
files (or dnsmasq's information) so that the hostname will resolve to
the LAN address when the laptop is connected to the LAN, and the VPN
address when it's connected via VPN. If everything was using DHCP, this
would be straightforward enough, but as I said, the VPN apparently
needs to be configured statically, and not via DHCP. I could obviously
use some custom script (using, say, ageas, to modify host files) but
this seems hackish. What is a standard, 'correct' way to do this, or
more generally, to enable the LAN hosts to access the laptop
seamlessly regardless of its IP address and connection type?

Celejar

[toc] | [next] | [standalone]


#207582

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2019-04-16 20:50 +0200
Message-ID<xNBjA-4lB-7@gated-at.bofh.it>
In reply to#207564
Le 16/04/2019 à 17:03, Celejar a écrit :
> 
> What I seem to want (but maybe XY?) is some way to adjust the host
> files (or dnsmasq's information) so that the hostname will resolve to
> the LAN address when the laptop is connected to the LAN, and the VPN
> address when it's connected via VPN. [...]
> What is a standard, 'correct' way to do this, or
> more generally, to enable the LAN hosts to access the laptop
> seamlessly regardless of its IP address and connection type?

Dynamic DNS.

[toc] | [prev] | [next] | [standalone]


#207593

FromCelejar <celejar@gmail.com>
Date2019-04-16 21:30 +0200
Message-ID<xNBWh-4Ph-7@gated-at.bofh.it>
In reply to#207582
On Tue, 16 Apr 2019 20:45:54 +0200
Pascal Hambourg <pascal@plouf.fr.eu.org> wrote:

> Le 16/04/2019 à 17:03, Celejar a écrit :
> > 
> > What I seem to want (but maybe XY?) is some way to adjust the host
> > files (or dnsmasq's information) so that the hostname will resolve to
> > the LAN address when the laptop is connected to the LAN, and the VPN
> > address when it's connected via VPN. [...]
> > What is a standard, 'correct' way to do this, or
> > more generally, to enable the LAN hosts to access the laptop
> > seamlessly regardless of its IP address and connection type?
> 
> Dynamic DNS.

Thanks. I thought of that, but I'm going to need more explanation and
help. I understand that I can use something like nsupdate to update DNS
records, but then I'd need to install and configure a compatible DNS
server - the one I currently use, dnsmasq, apparently doesn't support
RFC 2136 updates. Is there something I'm missing?

Additionally, I'm using simple hostnames, not FQDN names. Will that
still work with dynamic DNS?

Celejar

[toc] | [prev] | [next] | [standalone]


#207605

FromRichard Hector <richard@walnut.gen.nz>
Date2019-04-17 03:50 +0200
Message-ID<xNHS1-8nV-3@gated-at.bofh.it>
In reply to#207564

[Multipart message — attachments visible in raw view] — view raw

On 17/04/19 3:03 AM, Celejar wrote:
> Hi,
> 
> I've been bedeviled by this question for a while, but have been unable
> to figure out a clean, non-hackish solution. It may be an XY problem ...
> 
> I have a system (laptop, running Debian) that is sometimes connected
> directly to my LAN, and sometimes connected via VPN (wireguard, to the
> local router, running OpenWrt). The LAN is 192.168.0.0/24, with the
> laptop having a fixed, static address in that range (although I'm
> certainly open to using DHCP, possibly with a fixed address
> reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed,
> static address in that range (and wireguard apparently doesn't work
> with dhcp).
> 
> I currently have an entry in /etc/hosts on the various LAN hosts
> assigning a hostname to the laptop's fixed local address, and the LAN
> hosts can access the laptop via that hostname. [I could alternatively
> use dnsmasq, which is running on the router regardless.] This obviously
> doesn't work when the laptop is connected via VPN. [The laptop can
> access the LAN hosts fine via their hostnames, so I seem to have the
> routing correctly configured on the laptop and the router.]
> 
> What I seem to want (but maybe XY?) is some way to adjust the host
> files (or dnsmasq's information) so that the hostname will resolve to
> the LAN address when the laptop is connected to the LAN, and the VPN
> address when it's connected via VPN. If everything was using DHCP, this
> would be straightforward enough, but as I said, the VPN apparently
> needs to be configured statically, and not via DHCP. I could obviously
> use some custom script (using, say, ageas, to modify host files) but
> this seems hackish. What is a standard, 'correct' way to do this, or
> more generally, to enable the LAN hosts to access the laptop
> seamlessly regardless of its IP address and connection type?

What about connecting to the VPN even from the LAN? So the VPN address
is always available.

Another thought I've had in the past, but probably won't work in this
case (because one of the locations is on the same side of the router as
the other machines) is to give the laptop its own block (on the loopback
or maybe a dummy device), and adjust the routing tables (which the
wireguard server will probably do).

Richard


[toc] | [prev] | [next] | [standalone]


#207607

FromCelejar <celejar@gmail.com>
Date2019-04-17 04:20 +0200
Message-ID<xNIl3-rG-1@gated-at.bofh.it>
In reply to#207605
On Wed, 17 Apr 2019 13:45:05 +1200
Richard Hector <richard@walnut.gen.nz> wrote:

> On 17/04/19 3:03 AM, Celejar wrote:

...

> > What I seem to want (but maybe XY?) is some way to adjust the host
> > files (or dnsmasq's information) so that the hostname will resolve to
> > the LAN address when the laptop is connected to the LAN, and the VPN
> > address when it's connected via VPN. If everything was using DHCP, this
> > would be straightforward enough, but as I said, the VPN apparently
> > needs to be configured statically, and not via DHCP. I could obviously
> > use some custom script (using, say, ageas, to modify host files) but
> > this seems hackish. What is a standard, 'correct' way to do this, or
> > more generally, to enable the LAN hosts to access the laptop
> > seamlessly regardless of its IP address and connection type?
> 
> What about connecting to the VPN even from the LAN? So the VPN address
> is always available.

I suppose that's an option, but it just seems so terribly inefficient,
although I suppose that I likely wouldn't even notice during normal work.

> Another thought I've had in the past, but probably won't work in this
> case (because one of the locations is on the same side of the router as
> the other machines) is to give the laptop its own block (on the loopback
> or maybe a dummy device), and adjust the routing tables (which the
> wireguard server will probably do).

Thanks,

Celejar

[toc] | [prev] | [next] | [standalone]


#207618

FromKevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr>
Date2019-04-17 08:40 +0200
Message-ID<xNMoF-2UL-3@gated-at.bofh.it>
In reply to#207564

[Multipart message — attachments visible in raw view] — view raw

> Hi,
>
> I've been bedeviled by this question for a while, but have been unable
> to figure out a clean, non-hackish solution. It may be an XY problem ...
>
> I have a system (laptop, running Debian) that is sometimes connected
> directly to my LAN, and sometimes connected via VPN (wireguard, to the
> local router, running OpenWrt). The LAN is 192.168.0.0/24, with the
> laptop having a fixed, static address in that range (although I'm
> certainly open to using DHCP, possibly with a fixed address
> reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed,
> static address in that range (and wireguard apparently doesn't work
> with dhcp).
>
> I currently have an entry in /etc/hosts on the various LAN hosts
> assigning a hostname to the laptop's fixed local address, and the LAN
> hosts can access the laptop via that hostname. [I could alternatively
> use dnsmasq, which is running on the router regardless.] This obviously
> doesn't work when the laptop is connected via VPN. [The laptop can
> access the LAN hosts fine via their hostnames, so I seem to have the
> routing correctly configured on the laptop and the router.]
>
> What I seem to want (but maybe XY?) is some way to adjust the host
> files (or dnsmasq's information) so that the hostname will resolve to
> the LAN address when the laptop is connected to the LAN, and the VPN
> address when it's connected via VPN. If everything was using DHCP, this
> would be straightforward enough, but as I said, the VPN apparently
> needs to be configured statically, and not via DHCP. I could obviously
> use some custom script (using, say, ageas, to modify host files) but
> this seems hackish. What is a standard, 'correct' way to do this, or
> more generally, to enable the LAN hosts to access the laptop
> seamlessly regardless of its IP address and connection type?
>
> Celejar
>
Hi,

A possible solution is to use a bridged VPN, in this case, your laptop 
will always have the same IP.

Kevin

[toc] | [prev] | [next] | [standalone]


#207635

FromCelejar <celejar@gmail.com>
Date2019-04-17 14:20 +0200
Message-ID<xNRHH-6ex-1@gated-at.bofh.it>
In reply to#207618
On Wed, 17 Apr 2019 08:37:20 +0200
Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote:

> 
> > Hi,
> >
> > I've been bedeviled by this question for a while, but have been unable
> > to figure out a clean, non-hackish solution. It may be an XY problem ...
> >
> > I have a system (laptop, running Debian) that is sometimes connected
> > directly to my LAN, and sometimes connected via VPN (wireguard, to the
> > local router, running OpenWrt). The LAN is 192.168.0.0/24, with the
> > laptop having a fixed, static address in that range (although I'm
> > certainly open to using DHCP, possibly with a fixed address
> > reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed,
> > static address in that range (and wireguard apparently doesn't work
> > with dhcp).
> >
> > I currently have an entry in /etc/hosts on the various LAN hosts
> > assigning a hostname to the laptop's fixed local address, and the LAN
> > hosts can access the laptop via that hostname. [I could alternatively
> > use dnsmasq, which is running on the router regardless.] This obviously
> > doesn't work when the laptop is connected via VPN. [The laptop can
> > access the LAN hosts fine via their hostnames, so I seem to have the
> > routing correctly configured on the laptop and the router.]
> >
> > What I seem to want (but maybe XY?) is some way to adjust the host
> > files (or dnsmasq's information) so that the hostname will resolve to
> > the LAN address when the laptop is connected to the LAN, and the VPN
> > address when it's connected via VPN. If everything was using DHCP, this
> > would be straightforward enough, but as I said, the VPN apparently
> > needs to be configured statically, and not via DHCP. I could obviously
> > use some custom script (using, say, ageas, to modify host files) but
> > this seems hackish. What is a standard, 'correct' way to do this, or
> > more generally, to enable the LAN hosts to access the laptop
> > seamlessly regardless of its IP address and connection type?
> >
> > Celejar
> >
> Hi,
> 
> A possible solution is to use a bridged VPN, in this case, your laptop 
> will always have the same IP.

Thanks. I can't seem to find much information about this - can you
elaborate, or point me to a link? [I'm not a networking expert.]

Currently, my LAN is 192.168.0.0/24, which is also the addressing
scheme of some of the networks out of my control that I'm setting up a
VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid
address collisions with these other networks. It did occur to me to
consider using a different address space, for the VPN or perhaps for the
whole home LAN, but I'd rather not take that step just to solve what
seems a relatively simple problem unless absolutely necessary

Celejar

[toc] | [prev] | [next] | [standalone]


#207637

FromKevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr>
Date2019-04-17 15:40 +0200
Message-ID<xNSX7-6Tk-1@gated-at.bofh.it>
In reply to#207635

[Multipart message — attachments visible in raw view] — view raw

Le 17/04/2019 à 14:15, Celejar a écrit :
> On Wed, 17 Apr 2019 08:37:20 +0200
> Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote:
>
>>> Hi,
>>>
>>> I've been bedeviled by this question for a while, but have been unable
>>> to figure out a clean, non-hackish solution. It may be an XY problem ...
>>>
>>> I have a system (laptop, running Debian) that is sometimes connected
>>> directly to my LAN, and sometimes connected via VPN (wireguard, to the
>>> local router, running OpenWrt). The LAN is 192.168.0.0/24, with the
>>> laptop having a fixed, static address in that range (although I'm
>>> certainly open to using DHCP, possibly with a fixed address
>>> reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed,
>>> static address in that range (and wireguard apparently doesn't work
>>> with dhcp).
>>>
>>> I currently have an entry in /etc/hosts on the various LAN hosts
>>> assigning a hostname to the laptop's fixed local address, and the LAN
>>> hosts can access the laptop via that hostname. [I could alternatively
>>> use dnsmasq, which is running on the router regardless.] This obviously
>>> doesn't work when the laptop is connected via VPN. [The laptop can
>>> access the LAN hosts fine via their hostnames, so I seem to have the
>>> routing correctly configured on the laptop and the router.]
>>>
>>> What I seem to want (but maybe XY?) is some way to adjust the host
>>> files (or dnsmasq's information) so that the hostname will resolve to
>>> the LAN address when the laptop is connected to the LAN, and the VPN
>>> address when it's connected via VPN. If everything was using DHCP, this
>>> would be straightforward enough, but as I said, the VPN apparently
>>> needs to be configured statically, and not via DHCP. I could obviously
>>> use some custom script (using, say, ageas, to modify host files) but
>>> this seems hackish. What is a standard, 'correct' way to do this, or
>>> more generally, to enable the LAN hosts to access the laptop
>>> seamlessly regardless of its IP address and connection type?
>>>
>>> Celejar
>>>
>> Hi,
>>
>> A possible solution is to use a bridged VPN, in this case, your laptop
>> will always have the same IP.
> Thanks. I can't seem to find much information about this - can you
> elaborate, or point me to a link? [I'm not a networking expert.]
>
> Currently, my LAN is 192.168.0.0/24, which is also the addressing
> scheme of some of the networks out of my control that I'm setting up a
> VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid
> address collisions with these other networks. It did occur to me to
> consider using a different address space, for the VPN or perhaps for the
> whole home LAN, but I'd rather not take that step just to solve what
> seems a relatively simple problem unless absolutely necessary
>
> Celejar
>
Celjar,

You can find some explaination at 
https://openvpn.net/community-resources/ethernet-bridging/

Using common network adressing will often give address collisions when 
using VPN (routed or bridged VPN), like if on your home network and 
remote network you have 2 machin with same IP, one of them will not be 
reachable (depending of your routing table).

Kevin

[toc] | [prev] | [next] | [standalone]


#207646

FromCelejar <celejar@gmail.com>
Date2019-04-17 18:00 +0200
Message-ID<xNV8B-87j-5@gated-at.bofh.it>
In reply to#207637
On Wed, 17 Apr 2019 15:29:50 +0200
Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote:

> 
> Le 17/04/2019 à 14:15, Celejar a écrit :
> > On Wed, 17 Apr 2019 08:37:20 +0200
> > Kevin DAGNEAUX <kevin.dagneaux@fiitelcom.fr> wrote:
> >
> >>> Hi,
> >>>
> >>> I've been bedeviled by this question for a while, but have been unable
> >>> to figure out a clean, non-hackish solution. It may be an XY problem ...
> >>>
> >>> I have a system (laptop, running Debian) that is sometimes connected
> >>> directly to my LAN, and sometimes connected via VPN (wireguard, to the
> >>> local router, running OpenWrt). The LAN is 192.168.0.0/24, with the
> >>> laptop having a fixed, static address in that range (although I'm
> >>> certainly open to using DHCP, possibly with a fixed address
> >>> reservation). The VPN is 10.0.0.0/24, with the laptop getting a fixed,
> >>> static address in that range (and wireguard apparently doesn't work
> >>> with dhcp).
> >>>
> >>> I currently have an entry in /etc/hosts on the various LAN hosts
> >>> assigning a hostname to the laptop's fixed local address, and the LAN
> >>> hosts can access the laptop via that hostname. [I could alternatively
> >>> use dnsmasq, which is running on the router regardless.] This obviously
> >>> doesn't work when the laptop is connected via VPN. [The laptop can
> >>> access the LAN hosts fine via their hostnames, so I seem to have the
> >>> routing correctly configured on the laptop and the router.]
> >>>
> >>> What I seem to want (but maybe XY?) is some way to adjust the host
> >>> files (or dnsmasq's information) so that the hostname will resolve to
> >>> the LAN address when the laptop is connected to the LAN, and the VPN
> >>> address when it's connected via VPN. If everything was using DHCP, this
> >>> would be straightforward enough, but as I said, the VPN apparently
> >>> needs to be configured statically, and not via DHCP. I could obviously
> >>> use some custom script (using, say, ageas, to modify host files) but
> >>> this seems hackish. What is a standard, 'correct' way to do this, or
> >>> more generally, to enable the LAN hosts to access the laptop
> >>> seamlessly regardless of its IP address and connection type?
> >>>
> >>> Celejar
> >>>
> >> Hi,
> >>
> >> A possible solution is to use a bridged VPN, in this case, your laptop
> >> will always have the same IP.
> > Thanks. I can't seem to find much information about this - can you
> > elaborate, or point me to a link? [I'm not a networking expert.]
> >
> > Currently, my LAN is 192.168.0.0/24, which is also the addressing
> > scheme of some of the networks out of my control that I'm setting up a
> > VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid
> > address collisions with these other networks. It did occur to me to
> > consider using a different address space, for the VPN or perhaps for the
> > whole home LAN, but I'd rather not take that step just to solve what
> > seems a relatively simple problem unless absolutely necessary
> >
> > Celejar
> >
> Celjar,
> 
> You can find some explaination at 
> https://openvpn.net/community-resources/ethernet-bridging/

Thanks. I'm trying to figure out whether Wireguard, and OpenWrt's
implementation of it in particular, supports bridging.

> Using common network adressing will often give address collisions when 
> using VPN (routed or bridged VPN), like if on your home network and 
> remote network you have 2 machin with same IP, one of them will not be 
> reachable (depending of your routing table).

I think that this won't be much of an issue - when I'm on remote
networks, there typically aren't any hosts on those networks that I need
to access.

Celejar

[toc] | [prev] | [next] | [standalone]


#207639

FromJoe <joe@jretrading.com>
Date2019-04-17 16:10 +0200
Message-ID<xNTq9-7iL-5@gated-at.bofh.it>
In reply to#207635
On Wed, 17 Apr 2019 08:15:09 -0400
Celejar <celejar@gmail.com> wrote:


> Currently, my LAN is 192.168.0.0/24, which is also the addressing
> scheme of some of the networks out of my control that I'm setting up a
> VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid
> address collisions with these other networks. It did occur to me to
> consider using a different address space, for the VPN or perhaps for
> the whole home LAN, but I'd rather not take that step just to solve
> what seems a relatively simple problem unless absolutely necessary
> 

If you do get pushed to doing that, there are a few commonly used
networks that you should avoid. 10. is often used with a netmask of
/24 or /8, and the latter precludes all 10. variants. Of the 192.168.
groups, 0, 1, 8, 16 and 254 are often used, best use something quite
random like 192.168.137.0/24.

Probably better still is one of the 172.16-172.31 groups, which don't
seem to be used as defaults very often.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#207645

FromCelejar <celejar@gmail.com>
Date2019-04-17 18:00 +0200
Message-ID<xNV8B-87j-7@gated-at.bofh.it>
In reply to#207639
On Wed, 17 Apr 2019 14:59:53 +0100
Joe <joe@jretrading.com> wrote:

> On Wed, 17 Apr 2019 08:15:09 -0400
> Celejar <celejar@gmail.com> wrote:
> 
> 
> > Currently, my LAN is 192.168.0.0/24, which is also the addressing
> > scheme of some of the networks out of my control that I'm setting up a
> > VPN link from. I deliberately used 10.0.0.0/24 for the VPN to avoid
> > address collisions with these other networks. It did occur to me to
> > consider using a different address space, for the VPN or perhaps for
> > the whole home LAN, but I'd rather not take that step just to solve
> > what seems a relatively simple problem unless absolutely necessary
> > 
> 
> If you do get pushed to doing that, there are a few commonly used
> networks that you should avoid. 10. is often used with a netmask of
> /24 or /8, and the latter precludes all 10. variants. Of the 192.168.
> groups, 0, 1, 8, 16 and 254 are often used, best use something quite
> random like 192.168.137.0/24.
> 
> Probably better still is one of the 172.16-172.31 groups, which don't
> seem to be used as defaults very often.

Thanks. When I first set up the VPN, I did some reading about this, and
I was rather shocked to see that there was no definitive solution to
avoid address collisions, just recommendations like yours to try to
make a good guess about it ...

Celejar

[toc] | [prev] | [next] | [standalone]


#207648

FromMichael Stone <mstone@debian.org>
Date2019-04-17 18:20 +0200
Message-ID<xNVrX-8tC-1@gated-at.bofh.it>
In reply to#207645
On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote:
>Thanks. When I first set up the VPN, I did some reading about this, and
>I was rather shocked to see that there was no definitive solution to
>avoid address collisions

Sure there is--globally unique IPs.

[toc] | [prev] | [next] | [standalone]


#207649

FromCelejar <celejar@gmail.com>
Date2019-04-17 18:40 +0200
Message-ID<xNVLj-8l-3@gated-at.bofh.it>
In reply to#207648
On Wed, 17 Apr 2019 12:10:56 -0400
Michael Stone <mstone@debian.org> wrote:

> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote:
> >Thanks. When I first set up the VPN, I did some reading about this, and
> >I was rather shocked to see that there was no definitive solution to
> >avoid address collisions
> 
> Sure there is--globally unique IPs.

I assume you're referring to IPv6? I was referring to IPv4.

Celejar

[toc] | [prev] | [next] | [standalone]


#207650

FromMichael Stone <mstone@debian.org>
Date2019-04-17 18:50 +0200
Message-ID<xNVUZ-bL-5@gated-at.bofh.it>
In reply to#207649
On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote:
>On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> wrote:
>
>> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote:
>> >Thanks. When I first set up the VPN, I did some reading about this, and
>> >I was rather shocked to see that there was no definitive solution to
>> >avoid address collisions
>>
>> Sure there is--globally unique IPs.
>
>I assume you're referring to IPv6? I was referring to IPv4.

It applies to both, though we've run out of IPv4. There's no other way 
to guarantee the absence of network collisions.

[toc] | [prev] | [next] | [standalone]


#207658 — [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2019-04-17 21:40 +0200
Subject[OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)
Message-ID<xNYzv-1Qv-1@gated-at.bofh.it>
In reply to#207650
Le 17/04/2019 à 18:42, Michael Stone a écrit :
> On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote:
>> On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> 
>> wrote:
>>
>>> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote:
>>> >I was rather shocked to see that there was no definitive solution to
>>> >avoid address collisions
>>>
>>> Sure there is--globally unique IPs.
>>
>> I assume you're referring to IPv6? I was referring to IPv4.
> 
> It applies to both, though we've run out of IPv4. There's no other way 
> to guarantee the absence of network collisions.

A properly generated IPv6 ULA (Unique Local Address) prefix is unlikely 
to have collisions.

[toc] | [prev] | [next] | [standalone]


#207659 — Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)

FromCurt <curty@free.fr>
Date2019-04-17 22:10 +0200
SubjectRe: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)
Message-ID<xNZ2y-2jV-3@gated-at.bofh.it>
In reply to#207658
On 2019-04-17, Pascal Hambourg <pascal@plouf.fr.eu.org> wrote:
> Le 17/04/2019 à 18:42, Michael Stone a écrit :
>> On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote:
>>> On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org> 
>>> wrote:
>>>
>>>> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote:
>>>> >I was rather shocked to see that there was no definitive solution to
>>>> >avoid address collisions
>>>>
>>>> Sure there is--globally unique IPs.
>>>
>>> I assume you're referring to IPv6? I was referring to IPv4.
>> 
>> It applies to both, though we've run out of IPv4. There's no other way 
>> to guarantee the absence of network collisions.
>
> A properly generated IPv6 ULA (Unique Local Address) prefix is unlikely 
> to have collisions.
>

I thought that was exactly what he was saying.

[toc] | [prev] | [next] | [standalone]


#207669 — Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)

FromMichael Stone <mstone@debian.org>
Date2019-04-18 15:00 +0200
SubjectRe: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)
Message-ID<xOeNY-3qv-3@gated-at.bofh.it>
In reply to#207659
On Wed, Apr 17, 2019 at 08:06:05PM -0000, Curt wrote:
>On 2019-04-17, Pascal Hambourg <pascal@plouf.fr.eu.org> wrote:
>> Le 17/04/2019 à 18:42, Michael Stone a écrit :
>>> On Wed, Apr 17, 2019 at 12:38:11PM -0400, Celejar wrote:
>>>> On Wed, 17 Apr 2019 12:10:56 -0400 Michael Stone <mstone@debian.org>
>>>> wrote:
>>>>
>>>>> On Wed, Apr 17, 2019 at 11:57:43AM -0400, Celejar wrote:
>>>>> >I was rather shocked to see that there was no definitive solution to
>>>>> >avoid address collisions
>>>>>
>>>>> Sure there is--globally unique IPs.
>>>>
>>>> I assume you're referring to IPv6? I was referring to IPv4.
>>>
>>> It applies to both, though we've run out of IPv4. There's no other way
>>> to guarantee the absence of network collisions.
>>
>> A properly generated IPv6 ULA (Unique Local Address) prefix is unlikely
>> to have collisions.
>>
>
>I thought that was exactly what he was saying.

No, the ULA is the IPv6 equivalent of RFC1918 space--you can use it 
internally without central registration by choosing a subnet from 
fd00::/8. The space is so much larger that it's much less likely that 
two sites would pick the same prefix, but there are no guarantees. 

[toc] | [prev] | [next] | [standalone]


#207671 — Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2019-04-18 15:20 +0200
SubjectRe: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)
Message-ID<xOf7j-3N1-1@gated-at.bofh.it>
In reply to#207669

[Multipart message — attachments visible in raw view] — view raw

On Thu, Apr 18, 2019 at 7:57 AM Michael Stone <mstone@debian.org> wrote:

>
> No, the ULA is the IPv6 equivalent of RFC1918 space--you can use it
> internally without central registration by choosing a subnet from
> fd00::/8. The space is so much larger that it's much less likely that
> two sites would pick the same prefix, but there are no guarantees.
>
> But isn't it irrelevant whether they pick the same prefix or not? Routers
that respect ULA and RFC1918 shouldn't route any traffic destined to them
off the logical subnet. Right?

[toc] | [prev] | [next] | [standalone]


#207672 — Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)

FromMichael Stone <mstone@debian.org>
Date2019-04-18 15:30 +0200
SubjectRe: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)
Message-ID<xOfh0-3Qf-1@gated-at.bofh.it>
In reply to#207671
On Thu, Apr 18, 2019 at 08:12:04AM -0500, Nicholas Geovanis wrote:
>But isn't it irrelevant whether they pick the same prefix or not? Routers that
>respect ULA and RFC1918 shouldn't route any traffic destined to them off the
>logical subnet. Right?

If it didn't matter, people wouldn't keep looking for solutions, right? 
In theory, you're right. In the real world, companies merge, etc., and 
stuff that started independently gets VPN'd together and things break.

[toc] | [prev] | [next] | [standalone]


#207682 — Re: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2019-04-18 22:40 +0200
SubjectRe: [OT] IP address collisions (was: Accessing a host with variable IP addresses / connection types)
Message-ID<xOlZ8-7Qi-3@gated-at.bofh.it>
In reply to#207672

[Multipart message — attachments visible in raw view] — view raw

On Thu, Apr 18, 2019, 8:29 AM Michael Stone <mstone@debian.org> wrote:

> On Thu, Apr 18, 2019 at 08:12:04AM -0500, Nicholas Geovanis wrote:
> >But isn't it irrelevant whether they pick the same prefix or not? Routers
> that
> >respect ULA and RFC1918 shouldn't route any traffic destined to them off
> the
> >logical subnet. Right?
>
> If it didn't matter, people wouldn't keep looking for solutions, right?
> In theory, you're right. In the real world, companies merge, etc., and
> stuff that started independently gets VPN'd together and things break.
>

This is correct as far as it goes. If corps merge and their internal IP
addresses overlap, they sort it out. There is no addressing based solution
other than creative routing.

>

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web