Re: route to separate network through different gateway onlocal network

"David Henry" <[email protected]>
Newsgroups gmane.network.nocat
Organization Nautical Landings LLC
Message-ID <001b01c59d13$bd3984d0$9601a8c0@an1x>
Hi Jeremy,

So basically what you need to do is set up routing on the NoCat gateway.

This way you can define a standard route to the NoCat gateway and hand that 
out to your machines.   Then once a machine sends traffic over to a specific 
network you can use NoCat to forward that traffic to another router such as 
the 192.168.1.1 etc.

For example, if you know what networks you need to go to (Vonage,iConnect 
Here etc) then you could just forward call traffic out the other device from 
the NoCat box.

I believe this is how you want to do it correct?

Let me know.

Best regards,
David


----- Original Message ----- 
From: "Campbell, Jeremy" <[email protected]>
To: "David Henry" <[email protected]>; <[email protected]>
Sent: Tuesday, August 09, 2005 2:32 PM
Subject: RE: [NoCat] route to separate network through different gateway 
onlocal network


Thanks for the reply David.

First, the topology:

The wireless network is 172.16.1.0/24.  My nocat box, 172.16.1.1, is the
default gateway on the network.  The gateway to the other network,
192.168.1.0/24, is through a different device on the local subnet.  That
gateway has two nics at 192.168.1.2 and 172.16.1.2.

The fact that I'm using VoIP is not really all that relevant.  I can
configure all of that as long as I can pass packets.

Now, the problem:

There is no problem passing data to the other network if a route is
defined on the localhost.  My nocat box has no problem getting traffic
to the other network.  Normally, I would just define a new static route
on my default gateway specifying the gateway for the other network, and
the default gateway would then take care of getting the data directed at
the other gateway.  However, it's not happening in this case.  Defining
static routes on a bunch of machines can be a real pain, though.  It's
not something I want to have to do if I need to deploy 10 IP phones
during a festival (which I would probably only learn about 45 minutes in
advance, anyway).

My current workaround and why I don't like it:

Currently, I'm working around the problem by handing out routes via
DHCP.  I don't like this approach though as it gives away more info than
I want to give out.  Basically, anyone who obtains an IP on the network
is immediately cued that there is something worth discovering on the
other network by the existence of the route I just handed them.

I would rather the default gateway hold that knowledge regarding the
route until the client device needs it.  It puts the onus of discovery
on the unfriendly users instead of just telling them when they get their
DHCP info.  I can define static TFTP options on my IP phones, and put
them on the wireless network (using one of a number of wifi-to-wired
devices).  If the default took care of getting the information to the
other gateway, the phones would find their way home without problem.

Please help:

I should have prefaced all of this with a warning that I don't know much
about iptables.  The last time I knowledgeably manipulated admission
control in linux, it was ipchains.  I know they're similar, but it's not
in my body of current working knowledge.  We otherwise have a Cisco
infrastructure and that's what I know these days.  My guess is that I
simply need a rule in iptables telling it that everything is okay.  If
that's the case, what's that rule and where do I put it?

Also, I am doing admission control on the gateway to the 192.168.1.0
network.  They're not wide open.

Thanks for your help and patience,
Jeremy

________________________________________
Jeremy P. Campbell
Information Systems Director
Town of Davidson, NC
704-940-9632 - voice, direct
704-892-7591 ext. 248 - voice, main
704-892-3971 - fax

-----Original Message-----
From: David Henry [mailto:[email protected]]
Sent: Tuesday, August 09, 2005 3:04 PM
To: Campbell, Jeremy; [email protected]
Subject: Re: [NoCat] route to separate network through different gateway
onlocal network

Hi Jeremy,

You really haven't given us enough information.

Do you want to make the VOIP devices authenticate before connecting?

Do you want to have a free pass through for VOIP?

Have you added the VOIP hosts to the "Allowed Networks" section of your
config.

Let us know so we can help.

Thanks,
David


----- Original Message ----- 
From: "Campbell, Jeremy" <[email protected]>
To: <[email protected]>
Sent: Monday, August 08, 2005 2:47 PM
Subject: [NoCat] route to separate network through different gateway
onlocal
network


I have a 172.16.1.0/24 network behind a linux/nocat box at 172.16.1.1.
Everything works wonderfully.  I have added a gateway (i.e., another
linux box with nics at 172.16.1.2 and 192.168.1.1) on the same subnet to
a different network (192.168.1.0/24) so I can put some VoIP out on the
municipal wireless network for city events.  I have added routes to my
linux/nocat box configuration with the network/gateway information.
Yet, the linux/nocat box doesn't do what it should.  Do I need to modify
my nocat configuration to make this work?  If so, what sort of mods do I
need to make?



Thanks,

Jeremy



________________________________________
Jeremy P. Campbell
Information Systems Director
Town of Davidson, NC
704-940-9632 - voice, direct
704-892-7591 ext. 248 - voice, main
704-892-3971 - fax



_______________________________________________
NoCat mailing list
[email protected]
http://lists.nocat.net/mailman/listinfo/nocat
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.