* Quick Routing question
@ 2003-03-04 20:10 David Ruggles
2003-03-04 20:47 ` Maciej Soltysiak
2003-03-05 0:07 ` Arnt Karlsen
0 siblings, 2 replies; 9+ messages in thread
From: David Ruggles @ 2003-03-04 20:10 UTC (permalink / raw)
To: netfilter
I'm trying to learn netfilter so I've got a very simple setup.
I've got a Linux box with three interfaces. (I'm not using eth0 currently)
I've got two networks (eth2: 172.22.0.0 & eth1: 10.0.0.0)
I entered the following on the Linux box:
iptables -t nat -A POSTROUTING -o eth1 -j SNAT --to 10.9.0.254 (eth1's IP
address)
I've got a machine on each network: machine A is on 172.22.0.0 and machine B
is on 10.0.0.0
I'm trying to ping from A to B.
I can ping all the interfaces on the router but I can't ping B
I would expect to see the POSTROUTING chain counter increment for each ping
packet, but it doesn't. (It will increment if I ping from the Linux box to
B)
Any suggestions?
Thanks,
David Ruggles
CCNA MCSE (NT) CNA A+
Network Engineer, Safe Data, Inc
910-285-7200 david@safedatausa.com
0100011101101111011001000110110001101111011101100110010101110011011110010110
111101110101
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: Quick Routing question
2003-03-04 20:10 Quick Routing question David Ruggles
@ 2003-03-04 20:47 ` Maciej Soltysiak
2003-03-05 0:07 ` Arnt Karlsen
1 sibling, 0 replies; 9+ messages in thread
From: Maciej Soltysiak @ 2003-03-04 20:47 UTC (permalink / raw)
To: David Ruggles; +Cc: netfilter
> I would expect to see the POSTROUTING chain counter increment for each ping
> packet, but it doesn't. (It will increment if I ping from the Linux box to
> B)
So maybe the router does not have
/proc/sys/net/ipv4/ip_forward turn on?
and /proc/sys/net/ipv4/conf/*/forwarding on.
> Any suggestions?
Doing NAT is here unnecesary, but i think you are playing with it to test
NAT. :)
Do you have ipt_conntrack loaded?
Check forwarding in sysctl.
Check the default routes on the boxes.
Tcpdump the traffic on the router once on eth1, then on eth2, you'll find
out where the problem is: is the router routing the packets, or maybe when
the replies come back, they do not get routed.
> David Ruggles
Maciej Soltysiak
-----BEGIN GEEK CODE BLOCK-----
VERSION: 3.1
GIT/MU d-- s:- a-- C++ UL++++$ P L++++ E- W- N- K- w--- O! M- V- PS+ PE++
Y+ PGP- t+ 5-- X+ R tv- b DI+ D---- G e++>+++ h! y?
-----END GEEK CODE BLOCK-----
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: Quick Routing Question
@ 2003-03-04 21:19 ImpulseFG
0 siblings, 0 replies; 9+ messages in thread
From: ImpulseFG @ 2003-03-04 21:19 UTC (permalink / raw)
To: netfilter
Hi,
I think I've had this problem. When you try to ping a computer on 10.9.0.254/255.255.225.0 from 172.22.0.0 it sends the requests through the Routing box which changes the sorce IP to 10.9.0.254 and then sends the packet on to the destination computer on the 10.9.0.254/255.255.255.0 network. This packet reaches the computer and then is sent back to 10.9.0.254 and stops. It never goes all the way back to the 172.22.0.0 computer because the computer on 10.9.0.254 thinks the ping came from 10.9.0.254 because of the SNAT translation.
To fix this problem you will have to do another nat function. DNAT. Someting like $iptables -t nat -A PREROUTING -d 10.9.0.254 -j DNAT --to 172.22.0.0-172.22.0.255
or you could use -i eth2 instead of -d , I think.
This should get the packet back to the originating computer but then all packets will be routed you won't be able to ping the router form off the network because all the pings will be routed to the network behind it. So it would be better to put a -p scp/udp line in the above command.
I hope this helps.
-Impulse
__________________________________________________________________
The NEW Netscape 7.0 browser is now available. Upgrade now! http://channels.netscape.com/ns/browsers/download.jsp
Get your own FREE, personal Netscape Mail account today at http://webmail.netscape.com/
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: Quick Routing question
2003-03-04 20:10 Quick Routing question David Ruggles
2003-03-04 20:47 ` Maciej Soltysiak
@ 2003-03-05 0:07 ` Arnt Karlsen
2003-03-05 14:30 ` David Ruggles
1 sibling, 1 reply; 9+ messages in thread
From: Arnt Karlsen @ 2003-03-05 0:07 UTC (permalink / raw)
To: netfilter
On Tue, 4 Mar 2003 15:10:43 -0500,
"David Ruggles" <david@safedatausa.com> wrote in message
<016701c2e28a$239fbab0$1f0016ac@daviddesktop>:
> I'm trying to learn netfilter so I've got a very simple setup.
>
> I've got a Linux box with three interfaces. (I'm not using eth0
> currently) I've got two networks (eth2: 172.22.0.0 & eth1: 10.0.0.0)
> I entered the following on the Linux box:
> iptables -t nat -A POSTROUTING -o eth1 -j SNAT --to 10.9.0.254 (eth1's
> IP address)
>
> I've got a machine on each network: machine A is on 172.22.0.0 and
/\/\/\
[arnt@lana z-bru]$ dig -x 172.22.0.0
; <<>> DiG 9.2.1 <<>> -x 172.22.0.0
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 57296
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;0.0.22.172.in-addr.arpa. IN PTR
;; AUTHORITY SECTION:
22.172.in-addr.arpa. 10800 IN SOA prisoner.iana.org.
hostmaster.root-servers.org. 2002040800 1800 900 604800 604800
;; Query time: 556 msec
;; SERVER: 192.168.1.1#53(192.168.1.1)
;; WHEN: Wed Mar 5 01:00:01 2003
;; MSG SIZE rcvd: 118
[arnt@lana z-bru]$ dig prisoner.iana.org
; <<>> DiG 9.2.1 <<>> prisoner.iana.org
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18283
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 7, ADDITIONAL: 3
;; QUESTION SECTION:
;prisoner.iana.org. IN A
;; ANSWER SECTION:
prisoner.iana.org. 3600 IN A 192.175.48.1
;; AUTHORITY SECTION:
iana.org. 172800 IN NS a.iana-servers.net.
iana.org. 172800 IN NS ns.isi.edu.
iana.org. 172800 IN NS ns.ripe.net.
iana.org. 172800 IN NS ns.apnic.net.
iana.org. 172800 IN NS ns.icann.org.
iana.org. 172800 IN NS rip.psg.com.
iana.org. 172800 IN NS svc00.apnic.net.
;; ADDITIONAL SECTION:
a.iana-servers.net. 10847 IN A 192.0.34.43
ns.isi.edu. 10847 IN A 128.9.128.127
ns.icann.org. 10847 IN A 192.0.34.126
;; Query time: 127 msec
;; SERVER: 192.168.1.1#53(192.168.1.1)
;; WHEN: Wed Mar 5 01:00:47 2003
;; MSG SIZE rcvd: 268
[arnt@lana z-bru]$
..you run a _root_ name server and come here asking us amateur newbies
with less than 25 yrs internet experience for netfilter advice????? ;-)
> machine B is on 10.0.0.0
> I'm trying to ping from A to B.
..try move your A net to, say, 10.22.0.0, and your A net boxes
accordingly.
> I can ping all the interfaces on the router but I can't ping B
>
> I would expect to see the POSTROUTING chain counter increment for each
> ping packet, but it doesn't. (It will increment if I ping from the
> Linux box to B)
>
> Any suggestions?
>
> Thanks,
> David Ruggles
>
> CCNA MCSE (NT) CNA A+
> Network Engineer, Safe Data, Inc
> 910-285-7200 david@safedatausa.com
> 010001110110111101100100011011000110111101110110011001010111001101111
> 0010110 111101110101
>
>
--
..med vennlig hilsen = with Kind Regards from Arnt... ;-)
...with a number of polar bear hunters in his ancestry...
Scenarios always come in sets of three:
best case, worst case, and just in case.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: Quick Routing question
2003-03-05 0:07 ` Arnt Karlsen
@ 2003-03-05 14:30 ` David Ruggles
2003-03-05 16:37 ` Arnt Karlsen
0 siblings, 1 reply; 9+ messages in thread
From: David Ruggles @ 2003-03-05 14:30 UTC (permalink / raw)
To: Arnt Karlsen, netfilter
----- Original Message -----
From: "Arnt Karlsen" <arnt@c2i.net>
Subject: Re: Quick Routing question
[Snipped Dig commands]
>
> ..you run a _root_ name server and come here asking us amateur newbies
> with less than 25 yrs internet experience for netfilter advice????? ;-)
>
I hope you're joking. 172.22.x.x is inside the Class B non-routable
addresses set aside by RFC 1918
Thanks,
David Ruggles
CCNA MCSE (NT) CNA A+
Network Engineer, Safe Data, Inc
910-285-7200 david@safedatausa.com
0100011101101111011001000110110001101111011101100110010101110011011110010110
111101110101
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: Quick Routing question
2003-03-05 14:30 ` David Ruggles
@ 2003-03-05 16:37 ` Arnt Karlsen
2003-03-05 18:14 ` David Ruggles
0 siblings, 1 reply; 9+ messages in thread
From: Arnt Karlsen @ 2003-03-05 16:37 UTC (permalink / raw)
To: David Ruggles; +Cc: netfilter
On Wed, 5 Mar 2003 09:30:35 -0500,
"David Ruggles" <david@safedatausa.com> wrote in message
<00ae01c2e323$ca9b6fa0$1f0016ac@daviddesktop>:
> ----- Original Message -----
> From: "Arnt Karlsen" <arnt@c2i.net>
> Subject: Re: Quick Routing question
>
> [Snipped Dig commands]
>
> >
> > ..you run a _root_ name server and come here asking us amateur
> > newbies with less than 25 yrs internet experience for netfilter
> > advice????? ;-)
> >
>
> I hope you're joking. 172.22.x.x is inside the Class B non-routable
> addresses set aside by RFC 1918
..got that right, only just _after_ posting. ;-)
..it's 172.22.0.0/what-netmask?
> Thanks,
> David Ruggles
>
> CCNA MCSE (NT) CNA A+
> Network Engineer, Safe Data, Inc
> 910-285-7200 david@safedatausa.com
> 010001110110111101100100011011000110111101110110011001010111001101111
> 0010110 111101110101
>
--
..med vennlig hilsen = with Kind Regards from Arnt... ;-)
...with a number of polar bear hunters in his ancestry...
Scenarios always come in sets of three:
best case, worst case, and just in case.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: Quick Routing question
2003-03-05 16:37 ` Arnt Karlsen
@ 2003-03-05 18:14 ` David Ruggles
2003-03-05 21:02 ` David Ruggles
0 siblings, 1 reply; 9+ messages in thread
From: David Ruggles @ 2003-03-05 18:14 UTC (permalink / raw)
To: Arnt Karlsen; +Cc: netfilter
I'm pretty sure my problem was I didn't have ip forwarding turned on. I've
enabled it but machine A is being used for something else right now so I
haven't tested it yet. I thought it might be something dumb, and that fits
the bill, but if I have any other problems I'll be sure to ask. ;)
On a side note, I'm reading the LARTC howto and it's impressive.
Thanks,
David Ruggles
CCNA MCSE (NT) CNA A+
Network Engineer, Safe Data, Inc
910-285-7200 david@safedatausa.com
0100011101101111011001000110110001101111011101100110010101110011011110010110
111101110101
----- Original Message -----
From: "Arnt Karlsen" <arnt@c2i.net>
To: "David Ruggles" <david@safedatausa.com>
Cc: <netfilter@lists.netfilter.org>
Sent: Wednesday, March 05, 2003 11:37 AM
Subject: Re: Quick Routing question
> On Wed, 5 Mar 2003 09:30:35 -0500,
> "David Ruggles" <david@safedatausa.com> wrote in message
> <00ae01c2e323$ca9b6fa0$1f0016ac@daviddesktop>:
>
> > ----- Original Message -----
> > From: "Arnt Karlsen" <arnt@c2i.net>
> > Subject: Re: Quick Routing question
> >
> > [Snipped Dig commands]
> >
> > >
> > > ..you run a _root_ name server and come here asking us amateur
> > > newbies with less than 25 yrs internet experience for netfilter
> > > advice????? ;-)
> > >
> >
> > I hope you're joking. 172.22.x.x is inside the Class B non-routable
> > addresses set aside by RFC 1918
>
> ..got that right, only just _after_ posting. ;-)
>
> ..it's 172.22.0.0/what-netmask?
>
> > Thanks,
> > David Ruggles
> >
> > CCNA MCSE (NT) CNA A+
> > Network Engineer, Safe Data, Inc
> > 910-285-7200 david@safedatausa.com
> > 010001110110111101100100011011000110111101110110011001010111001101111
> > 0010110 111101110101
> >
>
>
> --
> ..med vennlig hilsen = with Kind Regards from Arnt... ;-)
> ...with a number of polar bear hunters in his ancestry...
> Scenarios always come in sets of three:
> best case, worst case, and just in case.
>
>
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: Quick Routing question
2003-03-05 18:14 ` David Ruggles
@ 2003-03-05 21:02 ` David Ruggles
2003-03-05 21:36 ` A netfilter question David Ruggles
0 siblings, 1 reply; 9+ messages in thread
From: David Ruggles @ 2003-03-05 21:02 UTC (permalink / raw)
To: netfilter
That did the trick, it's working now with out a problem.
Thanks,
David Ruggles
CCNA MCSE (NT) CNA A+
Network Engineer, Safe Data, Inc
910-285-7200 david@safedatausa.com
0100011101101111011001000110110001101111011101100110010101110011011110010110
111101110101
----- Original Message -----
From: "David Ruggles" <david@safedatausa.com>
To: "Arnt Karlsen" <arnt@c2i.net>
Cc: <netfilter@lists.netfilter.org>
Sent: Wednesday, March 05, 2003 1:14 PM
Subject: Re: Quick Routing question
> I'm pretty sure my problem was I didn't have ip forwarding turned on. I've
> enabled it but machine A is being used for something else right now so I
> haven't tested it yet. I thought it might be something dumb, and that fits
> the bill, but if I have any other problems I'll be sure to ask. ;)
>
> On a side note, I'm reading the LARTC howto and it's impressive.
>
> Thanks,
> David Ruggles
>
> CCNA MCSE (NT) CNA A+
> Network Engineer, Safe Data, Inc
> 910-285-7200 david@safedatausa.com
>
0100011101101111011001000110110001101111011101100110010101110011011110010110
> 111101110101
> ----- Original Message -----
> From: "Arnt Karlsen" <arnt@c2i.net>
> To: "David Ruggles" <david@safedatausa.com>
> Cc: <netfilter@lists.netfilter.org>
> Sent: Wednesday, March 05, 2003 11:37 AM
> Subject: Re: Quick Routing question
>
>
> > On Wed, 5 Mar 2003 09:30:35 -0500,
> > "David Ruggles" <david@safedatausa.com> wrote in message
> > <00ae01c2e323$ca9b6fa0$1f0016ac@daviddesktop>:
> >
> > > ----- Original Message -----
> > > From: "Arnt Karlsen" <arnt@c2i.net>
> > > Subject: Re: Quick Routing question
> > >
> > > [Snipped Dig commands]
> > >
> > > >
> > > > ..you run a _root_ name server and come here asking us amateur
> > > > newbies with less than 25 yrs internet experience for netfilter
> > > > advice????? ;-)
> > > >
> > >
> > > I hope you're joking. 172.22.x.x is inside the Class B non-routable
> > > addresses set aside by RFC 1918
> >
> > ..got that right, only just _after_ posting. ;-)
> >
> > ..it's 172.22.0.0/what-netmask?
> >
> > > Thanks,
> > > David Ruggles
> > >
> > > CCNA MCSE (NT) CNA A+
> > > Network Engineer, Safe Data, Inc
> > > 910-285-7200 david@safedatausa.com
> > > 010001110110111101100100011011000110111101110110011001010111001101111
> > > 0010110 111101110101
> > >
> >
> >
> > --
> > ..med vennlig hilsen = with Kind Regards from Arnt... ;-)
> > ...with a number of polar bear hunters in his ancestry...
> > Scenarios always come in sets of three:
> > best case, worst case, and just in case.
> >
> >
>
>
^ permalink raw reply [flat|nested] 9+ messages in thread
* A netfilter question
2003-03-05 21:02 ` David Ruggles
@ 2003-03-05 21:36 ` David Ruggles
0 siblings, 0 replies; 9+ messages in thread
From: David Ruggles @ 2003-03-05 21:36 UTC (permalink / raw)
To: netfilter
How hard is it to do SNAT out the same interface the packet came in on? If
you look at my first question, I want to accomplish that using only one
interface. (i.e. one physical network, two logical networks)
Thanks,
David Ruggles
CCNA MCSE (NT) CNA A+
Network Engineer, Safe Data, Inc
910-285-7200 david@safedatausa.com
0100011101101111011001000110110001101111011101100110010101110011011110010110
111101110101
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2003-03-05 21:36 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-03-04 20:10 Quick Routing question David Ruggles
2003-03-04 20:47 ` Maciej Soltysiak
2003-03-05 0:07 ` Arnt Karlsen
2003-03-05 14:30 ` David Ruggles
2003-03-05 16:37 ` Arnt Karlsen
2003-03-05 18:14 ` David Ruggles
2003-03-05 21:02 ` David Ruggles
2003-03-05 21:36 ` A netfilter question David Ruggles
-- strict thread matches above, loose matches on Subject: below --
2003-03-04 21:19 Quick Routing Question ImpulseFG
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox