Re: "Hiding" a "chatty" bridge link

Fernando Rodriguez <frod-Y20lP/[email protected]> Wed, 11 Jun 2014 08:36:34 -0500
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
--===============0508976232437216029==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_CE06F255-0F91-4EBE-AB39-263201B27331"


--Apple-Mail=_CE06F255-0F91-4EBE-AB39-263201B27331
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

Hello,



1.- Layer 2 tunnel

You can do a Layer 2 tunnel to pass the traffic from one side to the =
other transparently read on l2tpv3 this will work as if you where =
directly connected to the other side of the network.


2.- A simple proxy.

You can use a ssh to create a proxy to the lan of the equipment you want =
to monitor so if the equipment is on lan B you can ssh -D and make a =
tunnel as if you where ARM B so you can read the traffic directly.

=20

On Jun 10, 2014, at 10:30 AM, Cunningham, Robert =
<[email protected]> wrote:

> Hi,
> =20
> I have a test LAN that I needed to extend to another building, so I =
got a point-to-point RF link (non-WiFi) that does the job nicely.  =
Unfortunately, that link generates lots of miscellaneous traffic (STP, =
ARP, etc.) and also hosts a web-based management interface on each end =
that I can=92t disable (though I can set its address, but not the port). =
  I like my test LAN to be very, very clean: I mainly use it to =
Wireshark various instrumentation products (networked sensors and data =
relays) to check for correct data packet content, spurious traffic, and =
to gather traffic stats under various operational conditions.   Devices =
under test may use any valid IPv4 address, and the test LAN presently =
has no direct connection to a WAN or any other company LAN (but it may =
in the future).
> =20
> I thought it would be a =93simple=94 task to take a pair of ARM-Ubuntu =
boards I had available (similar to Beagle/Panda, running 12.04 LTS) and =
put one between each end of the RF link and the test LAN to hide the =
chatter.  But for the life of me I can=92t come up with a workable =
configuration.  I=92ve fallen into ebtables and I can=92t get up!
> =20
> Here=92s the hardware picture:
>                   |- ARM-A -|    |- RF-A -|    |- RF-B -|    |- ARM-B =
-|
> Local Test LAN -- eth0   eth1 -- wired   RF -- RF   wired -- eth1   =
eth0 -=96 Remote Test LAN
> =20
> My goal is to make the two eth0 interfaces be transparent, like a =
cable or a 2-port switch: Packets arriving on one eth0 depart on the =
other, and vice-versa.  ARP requests (and all other non-IP traffic) are =
passed cleanly through.  All traffic originated by RF-A and RF-B is =
dropped before exiting either eth0.  Neither eth0 will have an IP =
address.  There should be no need for STP.  If possible, I=92d even like =
the MAC addresses to be unchanged by the link (so I don=92t have to =
think too hard while using Wireshark).
> =20
> But I would like the RF management interfaces to be visible within the =
ARM boards (e.g., if I add another interface via USB).  So I don=92t =
want to drop their packets on ingress to eth1, but certainly not let =
them egress eth0.  I=92d also like to be able to be able temporarily =
expose an SSH interface for each ARM board on eth0 to make board =
configuration easier (and always have SSH on eth1, so I can configure =
over the RF link).
> =20
> Here=92s my progress so far (though it may only show my ignorance).  =
The addressing can be anything it needs to be.
> =20
> ARM-A:
>   eth0 ---- br0 ------- dummy0 --------- gre0                      =
eth1
> (no IP)   (no IP)  (192.168.1.254/24)   (to ARM-B: 192.168.2.254)  =
(172.10.10.10)
> =20
> ARM-B:
>   eth0 ---- br0 ------- dummy0 -------- gre0                       =
eth1
> (no IP)   (no IP)  (192.168.2.254/24)   (to ARM-A: 192.168.1.245)  =
(172.10.10.11)
> =20
> To provide temporary access to services on eth0, I=92m thinking I =
could dynamically create eth0:0 with an IP address, then delete it when =
no longer needed.  But will it interfere with the passing of all other =
traffic over the tunnel?
> =20
> I haven=92t yet been able to get a ping through the link, and I am way =
too ashamed to share the tangled mess of buggy ebtables rules I=92ve =
been trying to write (I=92m certain I=92m putting bad rules into the =
wrong tables, etc.).
> =20
> Any clues to get me going in the right direction?  I can=92t imagine =
that this kind of =93device wrapping and tunneling=94 is all that rare, =
but many net searches have failed to turn up relevant examples (or =
examples I understood to be relevant), and endless reading of the =
ebtables/iptables documentation has left me bleary-eyed.  Perhaps it=92s =
a vocabulary thing?  I=92m obviously not any kind of network engineer (I =
mainly work with TCP/UDP payloads).
> =20
> I=92ve tried asking on various StackExchange forums, but with no =
responses so far.  Help?
> =20
> TIA,
> =20
> -BobC
> =20
> =
--------------------------------------------------------------------------=
----
> HPCC Systems Open Source Big Data Platform from LexisNexis Risk =
Solutions
> Find What Matters Most in Your Big Data with HPCC Systems
> Open Source. Fast. Scalable. Simple. Ideal for Dirty Data.
> Leverages Graph Analysis for Fast Processing & Easy Data Exploration
> =
http://p.sf.net/sfu/hpccsystems___________________________________________=
____
> Ebtables-user mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/ebtables-user


--Apple-Mail=_CE06F255-0F91-4EBE-AB39-263201B27331
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=windows-1252

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dwindows-1252"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><div =
apple-content-edited=3D"true"><div style=3D"color: rgb(0, 0, 0); =
font-family: Helvetica;  font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: =
none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div =
style=3D"orphans: auto; widows: auto;"><span style=3D"text-align: =
-webkit-auto;">Hello,</span></div><div style=3D"orphans: auto; widows: =
auto;"><span style=3D"text-align: -webkit-auto;"><br></span></div><div =
style=3D"orphans: auto; widows: auto;"><span style=3D"text-align: =
-webkit-auto;"><br></span></div><div style=3D"orphans: auto; widows: =
auto;"><span style=3D"text-align: -webkit-auto;"><br></span></div><div =
style=3D"orphans: auto; widows: auto;">1.- Layer 2 tunnel</div><div =
style=3D"orphans: auto; widows: auto;"><br></div><div style=3D"orphans: =
auto; widows: auto;">You can do a Layer 2 tunnel to pass the traffic =
from one side to the other transparently read on l2tpv3 this will work =
as if you where directly connected to the other side of the =
network.</div><div style=3D"orphans: auto; widows: auto;"><br></div><div =
style=3D"orphans: auto; widows: auto;"><br></div><div style=3D"orphans: =
auto; widows: auto;">2.- A simple proxy.</div><div style=3D"orphans: =
auto; widows: auto;"><br></div><div style=3D"orphans: auto; widows: =
auto;">You can use a ssh to create a proxy to the lan of the equipment =
you want to monitor so if the equipment is on lan B you can ssh -D and =
make a tunnel as if you where ARM B so you can read the traffic =
directly.</div><div style=3D"orphans: auto; widows: =
auto;"><br></div><div style=3D"margin: 0cm 0cm 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span =
lang=3D"EN-US">&nbsp;</span></div></div>
</div>
<br><div><div>On Jun 10, 2014, at 10:30 AM, Cunningham, Robert &lt;<a =
href=3D"mailto:[email protected]">RCunningham@nsmsurveillanc=
e.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><blockquote type=3D"cite"><div =
lang=3D"EN-US" link=3D"blue" vlink=3D"purple" style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;"><div class=3D"WordSection1" =
style=3D"page: WordSection1;"><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">Hi,<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I have a =
test LAN that I needed to extend to another building, so I got a =
point-to-point RF link (non-WiFi) that does the job nicely.&nbsp; =
Unfortunately, that link generates lots of miscellaneous traffic (STP, =
ARP, etc.) and also hosts a web-based management interface on each end =
that I can=92t disable (though I can set its address, but not the =
port).&nbsp; &nbsp;I like my test LAN to be very, very clean: I mainly =
use it to Wireshark various instrumentation products (networked sensors =
and data relays) to check for correct data packet content, spurious =
traffic, and to gather traffic stats under various operational =
conditions. &nbsp;&nbsp;Devices under test may use any valid IPv4 =
address, and the test LAN presently has no direct connection to a WAN or =
any other company LAN (but it may in the future).<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I =
thought it would be a =93simple=94 task to take a pair of ARM-Ubuntu =
boards I had available (similar to Beagle/Panda, running 12.04 LTS) and =
put one between each end of the RF link and the test LAN to hide the =
chatter.&nbsp; But for the life of me I can=92t come up with a workable =
configuration.&nbsp; I=92ve fallen into ebtables and I can=92t get =
up!<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;"><o:p>&nbsp;</o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">Here=92s the hardware =
picture:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;"><span =
style=3D"font-family: 'Courier =
New';">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;|- ARM-A -|&nbsp;&nbsp;&nbsp; |- =
RF-A -|&nbsp;&nbsp;&nbsp; |- RF-B -|&nbsp;&nbsp;&nbsp; |- ARM-B =
-|<o:p></o:p></span></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;"><span =
style=3D"font-family: 'Courier New';">Local Test LAN -- eth0&nbsp;&nbsp; =
eth1 -- wired&nbsp;&nbsp; RF -- RF &nbsp;&nbsp;wired -- eth1&nbsp; =
&nbsp;eth0 -=96 Remote Test LAN<o:p></o:p></span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><span style=3D"font-family: 'Courier =
New';">&nbsp;</span></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;">My goal is to make =
the two eth0 interfaces be transparent, like a cable or a 2-port switch: =
Packets arriving on one eth0 depart on the other, and vice-versa.&nbsp; =
ARP requests (and all other non-IP traffic) are passed cleanly =
through.&nbsp; All traffic originated by RF-A and RF-B is dropped before =
exiting either eth0.&nbsp; Neither eth0 will have an IP address.&nbsp; =
There should be no need for STP.&nbsp; If possible, I=92d even like the =
MAC addresses to be unchanged by the link (so I don=92t have to think =
too hard while using Wireshark).<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">But I =
would like the RF management interfaces to be visible within the ARM =
boards (e.g., if I add another interface via USB).&nbsp; So I don=92t =
want to drop their packets on ingress to eth1, but certainly not let =
them egress eth0.&nbsp; I=92d also like to be able to be able =
temporarily expose an SSH interface for each ARM board on eth0 to make =
board configuration easier (and always have SSH on eth1, so I can =
configure over the RF link).<o:p></o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">Here=92s =
my progress so far (though it may only show my ignorance).&nbsp; The =
addressing can be anything it needs to be.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;"><span =
style=3D"font-family: 'Courier New';">ARM-A:<o:p></o:p></span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><span style=3D"font-family: 'Courier New';">&nbsp; =
eth0 ---- br0 ------- dummy0 --------- =
gre0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;eth1<o:p></o:p></span></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;"><span =
style=3D"font-family: 'Courier New';">(no IP)&nbsp;&nbsp; (no IP)&nbsp; =
(192.168.1.254/24)&nbsp;&nbsp; (to ARM-B: 192.168.2.254) =
&nbsp;(172.10.10.10)<o:p></o:p></span></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;"><span =
style=3D"font-family: 'Courier New';">&nbsp;</span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><span style=3D"font-family: 'Courier =
New';">ARM-B:<o:p></o:p></span></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;"><span =
style=3D"font-family: 'Courier New';">&nbsp; eth0 ---- br0 ------- =
dummy0 -------- gre0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;eth1<o:p></o:p></span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><span style=3D"font-family: 'Courier New';">(no =
IP)&nbsp;&nbsp; (no IP)&nbsp; (192.168.2.254/24)&nbsp;&nbsp; (to ARM-A: =
192.168.1.245)&nbsp; (172.10.10.11)<o:p></o:p></span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><span style=3D"font-family: 'Courier =
New';">&nbsp;</span></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;">To provide temporary =
access to services on eth0, I=92m thinking I could dynamically create =
eth0:0 with an IP address, then delete it when no longer needed.&nbsp; =
But will it interfere with the passing of all other traffic over the =
tunnel?<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I haven=92t =
yet been able to get a ping through the link, and I am way too ashamed =
to share the tangled mess of buggy ebtables rules I=92ve been trying to =
write (I=92m certain I=92m putting bad rules into the wrong tables, =
etc.).<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">Any clues =
to get me going in the right direction?&nbsp; I can=92t imagine that =
this kind of =93device wrapping and tunneling=94 is all that rare, but =
many net searches have failed to turn up relevant examples (or examples =
I understood to be relevant), and endless reading of the =
ebtables/iptables documentation has left me bleary-eyed.&nbsp; Perhaps =
it=92s a vocabulary thing?&nbsp; I=92m obviously not any kind of network =
engineer (I mainly work with TCP/UDP payloads).<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I=92ve =
tried asking on various StackExchange forums, but with no responses so =
far.&nbsp; Help?<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">TIA,<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">-BobC<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div></div>--------------------------------=
----------------------------------------------<br>HPCC Systems Open =
Source Big Data Platform from LexisNexis Risk Solutions<br>Find What =
Matters Most in Your Big Data with HPCC Systems<br>Open Source. Fast. =
Scalable. Simple. Ideal for Dirty Data.<br>Leverages Graph Analysis for =
Fast Processing &amp; Easy Data Exploration<br><a =
href=3D"http://p.sf.net/sfu/hpccsystems___________________________________=
____________" style=3D"color: purple; text-decoration: =
underline;">http://p.sf.net/sfu/hpccsystems_______________________________=
________________</a><br>Ebtables-user mailing list<br><a =
href=3D"mailto:[email protected]" style=3D"color: =
purple; text-decoration: =
underline;">[email protected]</a><br><a =
href=3D"https://lists.sourceforge.net/lists/listinfo/ebtables-user" =
style=3D"color: purple; text-decoration: =
underline;">https://lists.sourceforge.net/lists/listinfo/ebtables-user</a>=
</div></blockquote></div><br></body></html>=

--Apple-Mail=_CE06F255-0F91-4EBE-AB39-263201B27331--


--===============0508976232437216029==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
HPCC Systems Open Source Big Data Platform from LexisNexis Risk Solutions
Find What Matters Most in Your Big Data with HPCC Systems
Open Source. Fast. Scalable. Simple. Ideal for Dirty Data.
Leverages Graph Analysis for Fast Processing & Easy Data Exploration
http://p.sf.net/sfu/hpccsystems
--===============0508976232437216029==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Ebtables-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/ebtables-user

--===============0508976232437216029==--