Welcome to the { mindfrost82.com } forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-22-2008, 11:56 AM
Alessandro Topo Galileo
 
Posts: n/a
Routing problem

Hello all. I have a routing problem.
I have a linux machine (OpenSuSE) that acts as a gateway for the LAN and
is connected to internet using two different internet providers.
I want to ping this linux machine from the lan and from outside, using
both public ip (even from the lan, I have to call linux using external
public ip and not the internal lan ip).

Let's call:
$IP1 = linux ip on first provider's net
$P1_NET = first provider's net
$P1 = default gateway ip on first provider's net
$IF1 = ethernet interface wired with first provider's net

I have tried these commands:
ip route add $P1_NET dev $IF1 src $IP1 table 1
ip route add default via $P1 table 1
ip route add $P2_NET dev $IF2 src $IP2 table 2
ip route add default via $P2 table 2
ip route del default
ip route add default via $P1
ip rule add from $IP1 table 1
ip rule add from $IP2 table 2

Now, if I ping $IP1 or ping $IP2 I get correct answer from outside but
not from the LAN.

If I substitute the 7th line with this line:
ip rule add from $IP1 to 82.0.0.0/8 lookup 2

than ping works from LAN and from outside but obviously it works only
from external ip like 82.a.b.c.
Extending this for all valid addresses I would have to write a lot of rules:
ip rule add from $IP1 to 1.0.0.0/8 lookup 2
ip rule add from $IP1 to 2.0.0.0/8 lookup 2
ip rule add from $IP1 to 3.0.0.0/8 lookup 2
....
excluding 192.168.0.0/16, and than the same for $IP2. It seems me not
very good. :-)

Have you got any suggestion to solve the problem?
Thank you very much.
Reply With Quote
  #2 (permalink)  
Old 07-22-2008, 03:07 PM
Ashish Shukla =?utf-8?B?4KSG4KS24KWA4KS3IOCktg==?==?utf-8?B?4KWB4KSV4KWN4KSy?=
 
Posts: n/a
Re: Routing problem

Alessandro Topo Galileo writes:
> Hello all. I have a routing problem.
> I have a linux machine (OpenSuSE) that acts as a gateway for the LAN
> and is connected to internet using two different internet providers.
> I want to ping this linux machine from the lan and from outside, using
> both public ip (even from the lan, I have to call linux using external
> public ip and not the internal lan ip).


> Let's call:
> $IP1 = linux ip on first provider's net
> $P1_NET = first provider's net
> $P1 = default gateway ip on first provider's net
> $IF1 = ethernet interface wired with first provider's net


> I have tried these commands:
> ip route add $P1_NET dev $IF1 src $IP1 table 1
> ip route add default via $P1 table 1
> ip route add $P2_NET dev $IF2 src $IP2 table 2
> ip route add default via $P2 table 2
> ip route del default
> ip route add default via $P1
> ip rule add from $IP1 table 1
> ip rule add from $IP2 table 2


If you try to ping $IP1 from LAN, the replies you get on your LAN box
will be from $IP1. But since you specified a rule for all packets from
$IP1, the table 1 is considered which doesn't contain any routing rule
for your LAN :) .

> Now, if I ping $IP1 or ping $IP2 I get correct answer from outside but
> not from the LAN.


> If I substitute the 7th line with this line:
> ip rule add from $IP1 to 82.0.0.0/8 lookup 2


So adding above rule, restricts the rule to packets going to
82.0.0.0/8 :) .

HTH
--
·-- ·- ···· ·--- ·- ···- ·- ·--·-· --· -- ·- ·· ·-·· ·-·-·- -·-· --- --

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (FreeBSD)

iEYEARECAAYFAkiF6Z0ACgkQHy+EEHYuXnTmSQCgt2hAlcHhyM r9HBE2eSWmmRgI
JWgAoO3jdGEcuCXOz07ylG4oSSvmEfjM
=oCGf
-----END PGP SIGNATURE-----
Reply With Quote
  #3 (permalink)  
Old 07-22-2008, 03:27 PM
Alessandro Topo Galileo
 
Posts: n/a
Re: Routing problem

Il 22/07/2008 16.07, Ashish Shukla आशीष शुक्ल ha scritto:

> If you try to ping $IP1 from LAN, the replies you get on your LAN box
> will be from $IP1. But since you specified a rule for all packets from
> $IP1, the table 1 is considered which doesn't contain any routing rule
> for your LAN :) .


I understant this, but I don't know how to solve.
This does not solve:

route add 192.168.1.0/24 dev eth1 src $IP1 table 1

> So adding above rule, restricts the rule to packets going to
> 82.0.0.0/8 :) .


Yes, so I understant I have to write 254 rules to cover all X.0.0.0/8
for X<>192 (not considering 192.Y.0.0 for Y<>168).
It is not quite good...
Reply With Quote
  #4 (permalink)  
Old 07-22-2008, 03:36 PM
Ashish Shukla =?utf-8?B?4KSG4KS24KWA4KS3IOCktg==?==?utf-8?B?4KWB4KSV4KWN4KSy?=
 
Posts: n/a
Re: Routing problem

Alessandro Topo Galileo writes:
> Il 22/07/2008 16.07, Ashish Shukla आशीष शुक्ल ha scritto:


>> If you try to ping $IP1 from LAN, the replies you get on your LAN box
>> will be from $IP1. But since you specified a rule for all packets from
>> $IP1, the table 1 is considered which doesn't contain any routing rule
>> for your LAN :) .


> I understant this, but I don't know how to solve.
> This does not solve:


You can solve this by a rules like this:

ip rule add from $IP1 to $LAN_NETWORK table main
ip rule add from $IP2 to $LAN_NETWORK table main

Now where to place these rules, is what you've to decide :).

HTH
--
·-- ·- ···· ·--- ·- ···- ·- ·--·-· --· -- ·- ·· ·-·· ·-·-·- -·-· --- --

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)

iEYEARECAAYFAkiF8GYACgkQHy+EEHYuXnT/3wCZAdWclRg1Kd+iQGbm1w2A/098
dDYAni0c0FcuKme1IQYJVRApf5qw/d+p
=ma35
-----END PGP SIGNATURE-----
Reply With Quote
  #5 (permalink)  
Old 07-22-2008, 04:29 PM
Unruh
 
Posts: n/a
Re: Routing problem

Alessandro Topo Galileo <toglituttofinoalpunto.alextg@email.it> writes:

>Hello all. I have a routing problem.
>I have a linux machine (OpenSuSE) that acts as a gateway for the LAN and
>is connected to internet using two different internet providers.
>I want to ping this linux machine from the lan and from outside, using
>both public ip (even from the lan, I have to call linux using external
>public ip and not the internal lan ip).


>Let's call:
>$IP1 = linux ip on first provider's net
>$P1_NET = first provider's net
>$P1 = default gateway ip on first provider's net
>$IF1 = ethernet interface wired with first provider's net


Could you not have found a still more confusing set of symbols?

It is not clear what you want.



>I have tried these commands:
>ip route add $P1_NET dev $IF1 src $IP1 table 1
>ip route add default via $P1 table 1
>ip route add $P2_NET dev $IF2 src $IP2 table 2
>ip route add default via $P2 table 2
>ip route del default
>ip route add default via $P1
>ip rule add from $IP1 table 1
>ip rule add from $IP2 table 2


>Now, if I ping $IP1 or ping $IP2 I get correct answer from outside but
>not from the LAN.


And you want them from the lan why? The lan has its own interface and you
want the return packet to get to you inside, but the lan addresses are
probably non-routable and get thrown away.


>If I substitute the 7th line with this line:
>ip rule add from $IP1 to 82.0.0.0/8 lookup 2


>than ping works from LAN and from outside but obviously it works only
>from external ip like 82.a.b.c.
>Extending this for all valid addresses I would have to write a lot of rules:
>ip rule add from $IP1 to 1.0.0.0/8 lookup 2
>ip rule add from $IP1 to 2.0.0.0/8 lookup 2
>ip rule add from $IP1 to 3.0.0.0/8 lookup 2
>...
>excluding 192.168.0.0/16, and than the same for $IP2. It seems me not
>very good. :-)


>Have you got any suggestion to solve the problem?


It is hard to knw what the problem is.


>Thank you very much.

Reply With Quote
  #6 (permalink)  
Old 07-22-2008, 05:22 PM
Alessandro Topo Galileo
 
Posts: n/a
Re: Routing problem

Il 22/07/2008 16.36, Ashish Shukla आशीष शुक्ल ha scritto:

> ip rule add from $IP1 to $LAN_NETWORK table main
> ip rule add from $IP2 to $LAN_NETWORK table main


Great!
It works (but I added "pref" at the end of these lines to put them
before the other rules, otherwise it doesn't work).
The last days I have tried something similar but without "table main".
Thank you!
Reply With Quote
  #7 (permalink)  
Old 07-22-2008, 05:27 PM
Alessandro Topo Galileo
 
Posts: n/a
Re: Routing problem

Il 22/07/2008 17.29, Unruh ha scritto:

> And you want them from the lan why? The lan has its own interface and you
> want the return packet to get to you inside, but the lan addresses are
> probably non-routable and get thrown away.


I know, but to reach that server, for example using a browser, the DNS
gives the external ip... anyway, the problem was solved as written in
this thread.
Thank you for the answer.
Reply With Quote
  #8 (permalink)  
Old 07-22-2008, 06:31 PM
Ashish Shukla =?utf-8?B?4KSG4KS24KWA4KS3IOCktg==?==?utf-8?B?4KWB4KSV4KWN4KSy?=
 
Posts: n/a
Re: Routing problem

Alessandro Topo Galileo writes:
> Il 22/07/2008 16.36, Ashish Shukla आशीष शुक्ल ha scritto:


>> ip rule add from $IP1 to $LAN_NETWORK table main
>> ip rule add from $IP2 to $LAN_NETWORK table main


> Great!
> It works (but I added "pref" at the end of these lines to put them
> before the other rules, otherwise it doesn't work).


Cool :)

> The last days I have tried something similar but without "table main".
> Thank you!


You're welcome.
--
·-- ·- ···· ·--- ·- ···- ·- ·--·-· --· -- ·- ·· ·-·· ·-·-·- -·-· --- --

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)

iEYEARECAAYFAkiGGVoACgkQHy+EEHYuXnQZ1QCdGqbxIaU0bK 8UYe9I33ZMSAcE
hfsAnio3q+8WowUw1Temog4cXzKjGxpn
=jjy+
-----END PGP SIGNATURE-----
Reply With Quote
  #9 (permalink)  
Old 07-22-2008, 09:17 PM
Unruh
 
Posts: n/a
Re: Routing problem

Alessandro Topo Galileo <toglituttofinoalpunto.alextg@email.it> writes:

>Il 22/07/2008 17.29, Unruh ha scritto:


>> And you want them from the lan why? The lan has its own interface and you
>> want the return packet to get to you inside, but the lan addresses are
>> probably non-routable and get thrown away.


>I know, but to reach that server, for example using a browser, the DNS
>gives the external ip... anyway, the problem was solved as written in
>this thread.


On the internal net put your server into /etc/hosts. Then that internal
address will be used.

>Thank you for the answer.

Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Linux Networking


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:56 AM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0


Sponsors:
Loans | Advertising | Credit Card | Xbox Mod Chip | Credit Report



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114