"Hiding" a "chatty" bridge link

"Cunningham, Robert" <[email protected]> Tue, 10 Jun 2014 15:30:30 +0000
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <8D5812289502B448AD36E6780A069B8D0138773811@ashexcmb01.corp.solutionpoint-intl.com>
--===============4677824223608653409==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_8D5812289502B448AD36E6780A069B8D0138773811ashexcmb01cor_"

--_000_8D5812289502B448AD36E6780A069B8D0138773811ashexcmb01cor_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi,

I have a test LAN that I needed to extend to another building, so I got a p=
oint-to-point RF link (non-WiFi) that does the job nicely.  Unfortunately, =
that link generates lots of miscellaneous traffic (STP, ARP, etc.) and also=
 hosts a web-based management interface on each end that I can't disable (t=
hough I can set its address, but not the port).   I like my test LAN to be =
very, very clean: I mainly use it to Wireshark various instrumentation prod=
ucts (networked sensors and data relays) to check for correct data packet c=
ontent, spurious traffic, and to gather traffic stats under various operati=
onal conditions.   Devices under test may use any valid IPv4 address, and t=
he test LAN presently has no direct connection to a WAN or any other compan=
y LAN (but it may in the future).

I thought it would be a "simple" task to take a pair of ARM-Ubuntu boards I=
 had available (similar to Beagle/Panda, running 12.04 LTS) and put one bet=
ween each end of the RF link and the test LAN to hide the chatter.  But for=
 the life of me I can't come up with a workable configuration.  I've fallen=
 into ebtables and I can't get up!

Here's the hardware picture:
                  |- ARM-A -|    |- RF-A -|    |- RF-B -|    |- ARM-B -|
Local Test LAN -- eth0   eth1 -- wired   RF -- RF   wired -- eth1   eth0 --=
 Remote Test LAN

My goal is to make the two eth0 interfaces be transparent, like a cable or =
a 2-port switch: Packets arriving on one eth0 depart on the other, and vice=
-versa.  ARP requests (and all other non-IP traffic) are passed cleanly thr=
ough.  All traffic originated by RF-A and RF-B is dropped before exiting ei=
ther eth0.  Neither eth0 will have an IP address.  There should be no need =
for STP.  If possible, I'd even like the MAC addresses to be unchanged by t=
he link (so I don't have to think too hard while using Wireshark).

But I would like the RF management interfaces to be visible within the ARM =
boards (e.g., if I add another interface via USB).  So I don't want to drop=
 their packets on ingress to eth1, but certainly not let them egress eth0. =
 I'd also like to be able to be able temporarily expose an SSH interface fo=
r each ARM board on eth0 to make board configuration easier (and always hav=
e SSH on eth1, so I can configure over the RF link).

Here's my progress so far (though it may only show my ignorance).  The addr=
essing can be anything it needs to be.

ARM-A:
  eth0 ---- br0 ------- dummy0 --------- gre0                      eth1
(no IP)   (no IP)  (192.168.1.254/24)   (to ARM-B: 192.168.2.254)  (172.10.=
10.10)

ARM-B:
  eth0 ---- br0 ------- dummy0 -------- gre0                       eth1
(no IP)   (no IP)  (192.168.2.254/24)   (to ARM-A: 192.168.1.245)  (172.10.=
10.11)

To provide temporary access to services on eth0, I'm thinking I could dynam=
ically create eth0:0 with an IP address, then delete it when no longer need=
ed.  But will it interfere with the passing of all other traffic over the t=
unnel?

I haven't yet been able to get a ping through the link, and I am way too as=
hamed to share the tangled mess of buggy ebtables rules I've been trying to=
 write (I'm certain I'm putting bad rules into the wrong tables, etc.).

Any clues to get me going in the right direction?  I can't imagine that thi=
s kind of "device wrapping and tunneling" is all that rare, but many net se=
arches have failed to turn up relevant examples (or examples I understood t=
o be relevant), and endless reading of the ebtables/iptables documentation =
has left me bleary-eyed.  Perhaps it's a vocabulary thing?  I'm obviously n=
ot any kind of network engineer (I mainly work with TCP/UDP payloads).

I've tried asking on various StackExchange forums, but with no responses so=
 far.  Help?

TIA,

-BobC


--_000_8D5812289502B448AD36E6780A069B8D0138773811ashexcmb01cor_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Hi,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I have a test LAN that I needed to extend to another=
 building, so I got a point-to-point RF link (non-WiFi) that does the job n=
icely.&nbsp; Unfortunately, that link generates lots of miscellaneous traff=
ic (STP, ARP, etc.) and also hosts a web-based
 management interface on each end that I can&#8217;t disable (though I can =
set its address, but not the port).&nbsp; &nbsp;I like my test LAN to be ve=
ry, very clean: I mainly use it to Wireshark various instrumentation produc=
ts (networked sensors and data relays) to check
 for correct data packet content, spurious traffic, and to gather traffic s=
tats under various operational conditions. &nbsp;&nbsp;Devices under test m=
ay use any valid IPv4 address, and the test LAN presently has no direct con=
nection to a WAN or any other company LAN
 (but it may in the future).<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I thought it would be a &#8220;simple&#8221; task to=
 take a pair of ARM-Ubuntu boards I had available (similar to Beagle/Panda,=
 running 12.04 LTS) and put one between each end of the RF link and the tes=
t LAN to hide the chatter.&nbsp; But for the life of
 me I can&#8217;t come up with a workable configuration.&nbsp; I&#8217;ve f=
allen into ebtables and I can&#8217;t get up!<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Here&#8217;s the hardware picture:<o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; &nbsp;&nbsp;&nbsp;|- ARM-A -|&nbsp;&nbsp;&nbsp; |- RF-A -|&nbsp;&=
nbsp;&nbsp; |- RF-B -|&nbsp;&nbsp;&nbsp; |- ARM-B -|<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
Local Test LAN -- eth0&nbsp;&nbsp; eth1 -- wired&nbsp;&nbsp; RF -- RF &nbsp=
;&nbsp;wired -- eth1&nbsp; &nbsp;eth0 -&#8211; Remote Test LAN<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
<o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal">My goal is to make the two eth0 interfaces be transp=
arent, like a cable or a 2-port switch: Packets arriving on one eth0 depart=
 on the other, and vice-versa.&nbsp; ARP requests (and all other non-IP tra=
ffic) are passed cleanly through.&nbsp; All
 traffic originated by RF-A and RF-B is dropped before exiting either eth0.=
&nbsp; Neither eth0 will have an IP address.&nbsp; There should be no need =
for STP.&nbsp; If possible, I&#8217;d even like the MAC addresses to be unc=
hanged by the link (so I don&#8217;t have to think too hard
 while using Wireshark).<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">But I would like the RF management interfaces to be =
visible within the ARM boards (e.g., if I add another interface via USB).&n=
bsp; So I don&#8217;t want to drop their packets on ingress to eth1, but ce=
rtainly not let them egress eth0.&nbsp; I&#8217;d also like
 to be able to be able temporarily expose an SSH interface for each ARM boa=
rd on eth0 to make board configuration easier (and always have SSH on eth1,=
 so I can configure over the RF link).<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Here&#8217;s my progress so far (though it may only =
show my ignorance).&nbsp; The addressing can be anything it needs to be.<o:=
p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
ARM-A:<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&nbsp; eth0 ---- br0 ------- dummy0 --------- gre0&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;eth1<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
(no IP)&nbsp;&nbsp; (no IP)&nbsp; (192.168.1.254/24)&nbsp;&nbsp; (to ARM-B:=
 192.168.2.254) &nbsp;(172.10.10.10)<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
<o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
ARM-B:<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
&nbsp; eth0 ---- br0 ------- dummy0 -------- gre0&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;eth1<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
(no IP)&nbsp;&nbsp; (no IP)&nbsp; (192.168.2.254/24)&nbsp;&nbsp; (to ARM-A:=
 192.168.1.245)&nbsp; (172.10.10.11)<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Courier New&quot;">=
<o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal">To provide temporary access to services on eth0, I&#=
8217;m thinking I could dynamically create eth0:0 with an IP address, then =
delete it when no longer needed.&nbsp; But will it interfere with the passi=
ng of all other traffic over the tunnel?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I haven&#8217;t yet been able to get a ping through =
the link, and I am way too ashamed to share the tangled mess of buggy ebtab=
les rules I&#8217;ve been trying to write (I&#8217;m certain I&#8217;m putt=
ing bad rules into the wrong tables, etc.).<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Any clues to get me going in the right direction?&nb=
sp; I can&#8217;t imagine that this kind of &#8220;device wrapping and tunn=
eling&#8221; is all that rare, but many net searches have failed to turn up=
 relevant examples (or examples I understood to be relevant),
 and endless reading of the ebtables/iptables documentation has left me ble=
ary-eyed.&nbsp; Perhaps it&#8217;s a vocabulary thing?&nbsp; I&#8217;m obvi=
ously not any kind of network engineer (I mainly work with TCP/UDP payloads=
).<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I&#8217;ve tried asking on various StackExchange for=
ums, but with no responses so far.&nbsp; Help?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">TIA,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">-BobC<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_8D5812289502B448AD36E6780A069B8D0138773811ashexcmb01cor_--


--===============4677824223608653409==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
HPCC Systems Open Source Big Data Platform from LexisNexis Risk Solutions
Find What Matters Most in Your Big Data with HPCC Systems
Open Source. Fast. Scalable. Simple. Ideal for Dirty Data.
Leverages Graph Analysis for Fast Processing & Easy Data Exploration
http://p.sf.net/sfu/hpccsystems
--===============4677824223608653409==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ebtables-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/ebtables-user

--===============4677824223608653409==--