Linux Newbie help
 help / color / mirror / Atom feed
* Samba as DC
@ 2003-04-28  2:12 Chris Rose
  2003-04-28  6:34 ` Ray Olszewski
  0 siblings, 1 reply; 4+ messages in thread
From: Chris Rose @ 2003-04-28  2:12 UTC (permalink / raw)
  To: Linux-Newbie (Linux Newbie)

 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

First off, i'll confess that i know very little about exactly what a domain controller does, so i might be barking up the wrong tree, here, and there may be a much simpler solution.

I have a firewall (Clarkconnect - they're really good) that acts as a router for my home network/cable internet.  It currently provides DHCP services and NAT.

I just bought a wireless router, though, and now i have a problem.  My laptop is now on the router's subnet (192.168.0.*) while the rest of the systems are on the firewall's internal subnet, along with the WAN side of the wireless router (192.168.1.*)

What i want is to get filesharing working again between all these systems...  Is it as simple as changing the subnet masks from 255.255.255.0 to 255.255.0.0?  Or do i have to set up DC services on the firewall?  And if i do, how do i do it?

Thanks in advance...

Chris R.
=======
http://offline.pointclark.net/

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0

iQA/AwUBPqyN/sFBXq9qNmWaEQIdtQCg8UQQlciDALhY+umt3s+IETsf4oQAoI5t
hCXNA4GT+gAmMMOT87ZqQyf3
=vxfO
-----END PGP SIGNATURE-----

-
To unsubscribe from this list: send the line "unsubscribe linux-newbie" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.linux-learn.org/faqs

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Samba as DC
  2003-04-28  2:12 Chris Rose
@ 2003-04-28  6:34 ` Ray Olszewski
  0 siblings, 0 replies; 4+ messages in thread
From: Ray Olszewski @ 2003-04-28  6:34 UTC (permalink / raw)
  To: linux-newbie

I cannot fully answer your question, becauswe a full answer requires that 
someone instruct you about how to configure a WiFi router of unknown make 
and model. Even *we* aren't that good.

It is likely, though, that your WiFi WAP/router is like mine ... it is a 
NAT'ing router. That means that there is no straightforward way to combine 
the WiFi network and the wireline network on the other side of it. To 
confirm my guess, see if a host on the wireline LAN can ping your laptop 
... if I'm guessing correctly, it will fail (either with "host unreachable" 
or silently ... depends on the routing table of your wireline router).

In any case, unless the WiFi router has a bridging mode (not implausible, 
but you've told us nothing about this device), just changing the netmasks 
from /24 to /16 won't fix your problem, and trying it will probably make a 
mess (the WiFi router won't route to the wireline LAN properly, most likely).

Figuring out the best way to solve this gets us way down the road of WiFi 
security ... even if you can use a bridging mode, do you want to? Is WEP 
adequate to secure your LAN (assuming you're even using WEP on the WiFi LAN)?

At 08:12 PM 4/27/2003 -0600, Chris Rose wrote:
>
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>First off, i'll confess that i know very little about exactly what a 
>domain controller does, so i might be barking up the wrong tree, here, and 
>there may be a much simpler solution.
>
>I have a firewall (Clarkconnect - they're really good) that acts as a 
>router for my home network/cable internet.  It currently provides DHCP 
>services and NAT.
>
>I just bought a wireless router, though, and now i have a problem.  My 
>laptop is now on the router's subnet (192.168.0.*) while the rest of the 
>systems are on the firewall's internal subnet, along with the WAN side of 
>the wireless router (192.168.1.*)
>
>What i want is to get filesharing working again between all these 
>systems...  Is it as simple as changing the subnet masks from 
>255.255.255.0 to 255.255.0.0?  Or do i have to set up DC services on the 
>firewall?  And if i do, how do i do it?
>
>Thanks in advance...



-
To unsubscribe from this list: send the line "unsubscribe linux-newbie" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.linux-learn.org/faqs

^ permalink raw reply	[flat|nested] 4+ messages in thread

* RE: Samba as DC
       [not found] <5.1.0.14.1.20030428075323.01fa99b8@celine>
@ 2003-04-28 17:18 ` Chris Rose
  2003-04-28 17:47   ` Ray Olszewski
  0 siblings, 1 reply; 4+ messages in thread
From: Chris Rose @ 2003-04-28 17:18 UTC (permalink / raw)
  To: 'Ray Olszewski'; +Cc: Linux-Newbie (Linux Newbie)

 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sorry about that - i keep forgetting that for this one list i have to reply to all instead of the usual way.

Anyway, i am currently trying your suggestion, and it seems to be working.  Not perfectly, but well enough to suit me.  The one single problem with it that i can see is that since the router is no longer handling any of the clients, none of them seem to be able to connect to it in order to administer it - I'm not sure why this would be, but there it is.  Hopefully this won't be critical, but i've run into problems with this router already, where i'll lose the wireless network every couple of days and have to manually change the channel that it uses.  If that happens, there's gonna be problems, but other than that we should be alright.

Thanks, Ray.  This is one of the better kludges i've ever seen :)

Chris R.
=======
http://offline.pointclark.net/

- -----Original Message-----
From: Ray Olszewski [mailto:ray@comarre.com] 
Sent: April 28, 2003 9:03 AM
To: Chris Rose
Subject: RE: Samba as DC


At 01:38 AM 4/28/2003 -0600, Chris Rose wrote:
>
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>Well, you've already taught me more in that message than i expected to 
>find out :)
>
>Yes, the router is performing NAT on the laptop.  Damn, i kind of forgot 
>that'd be a problem.
>
>Pinging does fail, as expected, and i guess that leaves me kind of at a 
>dead end here.  I have a few ideas, but certainly nothing solid.
>
>The WiFi router is a d-link DI-614+.  I don't see anything in the config 
>screens about a 'bridging' mode, possibly because they're kind of dumbed 
>down, and i'm not a networking guru to start with (I guess that means 
>they're geared at folks like me, then, doesn't it?)  I may have to resign 
>myself to grabbing files by scp over the internal network as needed, 
>then.  So be it.  Alternately, the router has a 4-port switch in it, which 
>i guess i could use...  Assuming i'm not too lazy to re-org all the port 
>forwards etc... :)
>
>Thanks, boss, i appreciate the answer.

OK. I have a 713P, which also has both a WiFi WAP and a 4-port switch (or 
maybe hub, I didn't check and don't recall). What you can TRY is this:

1. In the router, WiFi WAP/router, turn DHCP off. (You should be able to do 
this from the Web config interface.)
2. Use one of the 4 switch ports (not the external interface) to connect 
the device to the wireline LAN.
3. Use the WiFI WAP to connect your laptop.
4. Expect your laptop to get its IP Address the same way your wireline 
machines do. For example, if you use DHCP on the wireline LAN,  expect this 
setup to cause your laptop to get a lease from the regular DHCP server, on 
the 192.168.1.0/24 network. If you assign addresses statically, do so for 
the laptop as well.
5. Now see if the laptop can access LAN shares.

If this works, then the WiFi WAP is acting as an ordinary WAP on the LAN, 
rather than a NAT'd one. This is not bridging (bridging would involve 
changes in the settings of the external interface), but it functions in an 
analogous way. It is an undocumented feature of at least some WiFi 
WAP/routers ... whether it works for the one you have, that I don't know. 
(It worked with mine, but unreliably ... but I was having WiFi problems on 
the Linux end at the time, and I haven't retested since I corrected them).

Oh ... I just noticed that this was a private message to me. If you try 
this and it works, I'd appreciate your posting a message to the list 
telling people so, as surely you are not the only person who has, or will 
have, this requirement.




-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0

iQA/AwUBPq1iZ8FBXq9qNmWaEQJ4RgCg5R7F1WFuPffutWUB6R+iJWEyC/wAoN9e
EtQM5X+6GWW1gaB+9LExFGgJ
=mChC
-----END PGP SIGNATURE-----

-
To unsubscribe from this list: send the line "unsubscribe linux-newbie" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.linux-learn.org/faqs

^ permalink raw reply	[flat|nested] 4+ messages in thread

* RE: Samba as DC
  2003-04-28 17:18 ` Samba as DC Chris Rose
@ 2003-04-28 17:47   ` Ray Olszewski
  0 siblings, 0 replies; 4+ messages in thread
From: Ray Olszewski @ 2003-04-28 17:47 UTC (permalink / raw)
  To: Chris Rose; +Cc: Linux-Newbie (Linux Newbie)

See below.

At 11:18 AM 4/28/2003 -0600, Chris Rose wrote:
>
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>Sorry about that - i keep forgetting that for this one list i have to 
>reply to all instead of the usual way.
>
>Anyway, i am currently trying your suggestion, and it seems to be 
>working.  Not perfectly, but well enough to suit me.  The one single 
>problem with it that i can see is that since the router is no longer 
>handling any of the clients, none of them seem to be able to connect to it 
>in order to administer it - I'm not sure why this would be, but there it 
>is.  Hopefully this won't be critical, but i've run into problems with 
>this router already, where i'll lose the wireless network every couple of 
>days and have to manually change the channel that it uses.  If that 
>happens, there's gonna be problems, but other than that we should be alright.
>
>Thanks, Ray.  This is one of the better kludges i've ever seen :)

Yes, especially because there combo wouter/switch/WAP boxes -- or at least 
some of them -- are going cheap to get them out of the way for new models 
that are not limited to 802.11b. I got my D-Link on closeout locally for $40.

I haven't retried this, as I said, but I *suspect* that the problem 
connecting is that with this setup, your workstations simply have no route 
to the WiFi WAP/router's setup address, and it has no route back to the 
workstations. As an experiment, you might try changing both netmasks to /23 
(that is, 255.255.254.0), which should let the "local" route cover both 
192.168.1.0/24 and 192.168.0.0/24. See if that lets you connect. (Remember, 
you have to do this on the WiFi WAP/router as well as the workstations.)

Alternately, you might see if the WiFi WAP/router's network settings can be 
changed and saved. If they can, set the internal network address to 
192.168.1.0/24, and use some out-of-the-way IP address (something outside 
the DHCP range) for the WiFi WAP/router itself.



-
To unsubscribe from this list: send the line "unsubscribe linux-newbie" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.linux-learn.org/faqs

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2003-04-28 17:47 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <5.1.0.14.1.20030428075323.01fa99b8@celine>
2003-04-28 17:18 ` Samba as DC Chris Rose
2003-04-28 17:47   ` Ray Olszewski
2003-04-28  2:12 Chris Rose
2003-04-28  6:34 ` Ray Olszewski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox