Re: dd-wrt and multiple subnets
fooler mail <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.philippine |
|---|---|
| Message-ID | <CAKPk3KSa7KjN7X5h2ZZRPjARi4QXUzYmi_4TKRDaAm1i89U0oQ@mail.gmail.com> |
hi andre, 255.255.248.0 is /21 and you have 2^(32-21) - 2 hosts available. hi mike, first things first.. when you are doing some troubleshooting try to disable your firewall first temporarily... I need your inputs first so that I can fix your network problem... your router default gateway is 192.168.100.2... where is NAT taking place? all hosts connected to 192.168.100.0/24 subnet.. their default gateway is vlan2 interface ip 192.168.100.227? all hosts connected to 10.10.10.0/21 subnet.. their default gateway is vlan2:0 interface ip 10.10.10.69? all hosts connected to 192.168.200.0/24 subnet.. their default gateway is vlan2:1 interface ip 192.168.200.227? all hosts connected to 10.20.30.0/24 subnet.. their default gateway is vlan2:2 interface ip 10.20.30.227? what is this bridge interface (br0) ip 192.168.1.1 for? I don't want to look at your firewall rules as we need to focus and troubleshoot first on the routing side when firewall is turn off.. once everything is ok, you turn on the firewall and there is a problem.. then that's the time for you to focus on the firewall rules.... fooler. On Thu, Feb 20, 2014 at 3:05 PM, andrelst <[email protected]> wrote: > Hi, > Subnet mask is 248? That's a maximum of 6 hosts in the subnet 10.10.10.0 > > Kernel IP routing table > Destination Gateway Genmask Flags Metric Ref Use > Iface > 10.20.30.0 0.0.0.0 255.255.255.0 U 0 0 0 > vlan2 > 192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br0 > 192.168.200.0 0.0.0.0 255.255.255.0 U 0 0 0 > vlan2 > 192.168.100.0 0.0.0.0 255.255.255.0 U 0 0 0 > vlan2 > 10.10.10.0 0.0.0.0 255.255.248.0 U 0 0 0 > vlan2 > 169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 br0 > 127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo > 0.0.0.0 192.168.100.2 0.0.0.0 UG 0 0 0 > vlan2 > > FYI, as a former both DD-WRT and RT-N16 user myself, In my opinion, below > are better than dd-wrt: > > * tomatousb. QoS simply works and broken with DD-WRT, and has been like > that for a couple of years(5?). Especially important for my voip phone > (priority) and torrents (low priority). > * Merlin Firmware. This is currently what i use for my RT-AC66u, and the > firmware is available for RT-n16 as well. Basically a customized version of > Asus firmware which includes bug fixes and enhancement. You will love the > dual WAN in either "fail over" or "load balance" just for starters. > > regards, > Andre | http://www.varon.ca > > On Thu, Feb 20, 2014 at 3:44 AM, Michael Tinsay <tinsami1-/[email protected]>wrote: > >> Hello everyone. >> >> I'm tinkering around with an ASUS RT-N16 router. I have flashed the >> firmware with DD-WRT v24-sp2 (06/08/12) mega - build 19342. Things are >> working fine for general use, but I seeing weird behavior in my more exotic >> setup here at the office. >> >> You see, I have 4 subnets in the office all accessible from anywhere in >> the LAN:' >> >> subnet 1 (192.168.100.0/24) for a few servers and specialized >> users. This is also my legacy subnet -- the original subnet of the office >> lan. >> subnet 2 (10.10.10.0/21) is the new office lan subnet, for the >> general use of the population and where most of the servers are. >> subnet 3 (192.168.200.0/24) is the subnet for the network printers >> (users print via a printserver visible in subnet 2) and a few kiosks. >> subnet 4 (10.20.30.0/24) is a sandbox subnet (where the fun stuff >> happens) >> >> The router is connected to the office lan via the WAN port. I configured >> the router to be on subnet 1 and added the other subnets via the Startup >> commands in DD-WRT's web-based admin. >> >> Here's the result of ifconfig: >> >> br0 Link encap:Ethernet HWaddr 10:BF:48:E7:24:65 >> inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> RX packets:81590 errors:0 dropped:0 overruns:0 frame:0 >> TX packets:45139 errors:0 dropped:0 overruns:0 carrier:0 >> collisions:0 txqueuelen:0 >> RX bytes:9140521 (8.7 MiB) TX bytes:30687125 (29.2 MiB) >> br0:0 Link encap:Ethernet HWaddr 10:BF:48:E7:24:65 >> inet addr:169.254.255.1 Bcast:169.254.255.255 Mask:255.255.0.0 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> eth0 Link encap:Ethernet HWaddr 10:BF:48:E7:24:65 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> RX packets:156473 errors:18 dropped:0 overruns:0 frame:9 >> TX packets:24758 errors:0 dropped:0 overruns:0 carrier:0 >> collisions:0 txqueuelen:1000 >> RX bytes:51222413 (48.8 MiB) TX bytes:7835838 (7.4 MiB) >> Interrupt:4 Base address:0x2000 >> eth1 Link encap:Ethernet HWaddr 10:BF:48:E7:24:67 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> RX packets:32926 errors:0 dropped:0 overruns:0 frame:133764 >> TX packets:43089 errors:7 dropped:0 overruns:0 carrier:0 >> collisions:0 txqueuelen:1000 >> RX bytes:3864980 (3.6 MiB) TX bytes:28792724 (27.4 MiB) >> Interrupt:3 Base address:0x1000 >> lo Link encap:Local Loopback >> inet addr:127.0.0.1 Mask:255.0.0.0 >> UP LOOPBACK RUNNING MULTICAST MTU:16436 Metric:1 >> RX packets:16 errors:0 dropped:0 overruns:0 frame:0 >> TX packets:16 errors:0 dropped:0 overruns:0 carrier:0 >> collisions:0 txqueuelen:0 >> RX bytes:1671 (1.6 KiB) TX bytes:1671 (1.6 KiB) >> vlan1 Link encap:Ethernet HWaddr 10:BF:48:E7:24:65 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> RX packets:1951 errors:0 dropped:0 overruns:0 frame:0 >> TX packets:11623 errors:0 dropped:0 overruns:0 carrier:0 >> collisions:0 txqueuelen:0 >> RX bytes:125148 (122.2 KiB) TX bytes:6007973 (5.7 MiB) >> vlan2 Link encap:Ethernet HWaddr 10:BF:48:E7:24:66 >> inet addr:192.168.100.227 Bcast:192.168.100.255 >> Mask:255.255.255.0 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> RX packets:154463 errors:0 dropped:0 overruns:0 frame:0 >> TX packets:13135 errors:0 dropped:0 overruns:0 carrier:0 >> collisions:0 txqueuelen:0 >> RX bytes:48272967 (46.0 MiB) TX bytes:1827865 (1.7 MiB) >> vlan2:0 Link encap:Ethernet HWaddr 10:BF:48:E7:24:66 >> inet addr:10.10.10.69 Bcast:10.10.17.255 Mask:255.255.248.0 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> vlan2:1 Link encap:Ethernet HWaddr 10:BF:48:E7:24:66 >> inet addr:192.168.200.227 Bcast:192.168.200.255 >> Mask:255.255.255.0 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> vlan2:2 Link encap:Ethernet HWaddr 10:BF:48:E7:24:66 >> inet addr:10.20.30.227 Bcast:10.20.30.255 Mask:255.255.255.0 >> UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 >> >> And the route -n shows: >> >> Kernel IP routing table >> Destination Gateway Genmask Flags Metric Ref Use >> Iface >> 10.20.30.0 0.0.0.0 255.255.255.0 U 0 0 0 >> vlan2 >> 192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 >> br0 >> 192.168.200.0 0.0.0.0 255.255.255.0 U 0 0 0 >> vlan2 >> 192.168.100.0 0.0.0.0 255.255.255.0 U 0 0 0 >> vlan2 >> 10.10.10.0 0.0.0.0 255.255.248.0 U 0 0 0 >> vlan2 >> 169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 >> br0 >> 127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo >> 0.0.0.0 192.168.100.2 0.0.0.0 UG 0 0 0 >> vlan2 >> >> Here's the weird behavior I'm experiencing: >> >> From my devices (a laptop connected via LAN cable with a static ip; >> another laptop, an iPad, and an android phone connected via WiFi with >> dynamic ip) behind the router, Internet browsing, SSH to servers, ping, >> and everything else works great on subnet 1 (192.168.100.0/24) -- no >> problem here. I can print to a network printer directly via subnet 3 ( >> 192.168.200.0/24). I can ping only a few of the servers in subnet 2 ( >> 10.10.10.0/21) and browsing a web server on subnet 2 doesn't work, >> neither does SSH. The same is true for subnet 4. >> >> From the router (via ssh) I can ping the machines in subnets 2 and 4. >> I'm able to connect to servers in subnets 3 and 4 via ssh tunneling. >> >> Anybody have any idea on what/where to look at? >> >> Just in case, iptables -nxvL shows: >> >> Chain INPUT (policy ACCEPT 0 packets, 0 bytes) >> pkts bytes target prot opt in out source >> destination >> 34580 15774302 logaccept 0 -- * * 0.0.0.0/0 >> 0.0.0.0/0 state RELATED,ESTABLISHED >> 0 0 logdrop udp -- vlan2 * 0.0.0.0/0 >> 0.0.0.0/0 udp dpt:520 >> 0 0 logdrop udp -- br0 * 0.0.0.0/0 >> 0.0.0.0/0 udp dpt:520 >> 0 0 ACCEPT udp -- * * 0.0.0.0/0 >> 0.0.0.0/0 udp dpt:520 >> 2294 137640 logaccept tcp -- * * 0.0.0.0/0 >> 192.168.1.1 tcp dpt:443 >> 0 0 ACCEPT icmp -- vlan2 * 0.0.0.0/0 >> 0.0.0.0/0 >> 435 13920 ACCEPT 2 -- * * 0.0.0.0/0 >> 0.0.0.0/0 >> 0 0 ACCEPT tcp -- * * 0.0.0.0/0 >> 0.0.0.0/0 tcp dpt:113 >> 2 109 ACCEPT 0 -- lo * 0.0.0.0/0 >> 0.0.0.0/0 state NEW >> 6 1438 logaccept 0 -- br0 * 0.0.0.0/0 >> 0.0.0.0/0 state NEW >> 99070 21162373 logdrop 0 -- * * 0.0.0.0/0 >> 0.0.0.0/0 >> Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) >> pkts bytes target prot opt in out source >> destination >> 0 0 logaccept 47 -- * vlan2 192.168.1.0/24 >> 0.0.0.0/0 >> 0 0 logaccept tcp -- * vlan2 192.168.1.0/24 >> 0.0.0.0/0 tcp dpt:1723 >> 0 0 logaccept 0 -- br0 br0 0.0.0.0/0 >> 0.0.0.0/0 >> 645 38180 TCPMSS tcp -- * * 0.0.0.0/0 >> 0.0.0.0/0 tcp flags:0x06/0x02 TCPMSS clamp to PMTU >> 36727 18426680 lan2wan 0 -- * * 0.0.0.0/0 >> 0.0.0.0/0 >> 23540 13704724 logaccept 0 -- * * 0.0.0.0/0 >> 0.0.0.0/0 state RELATED,ESTABLISHED >> 12600 4684259 logaccept udp -- vlan2 * 0.0.0.0/0 >> 224.0.0.0/4 >> 0 0 logaccept tcp -- * * 0.0.0.0/0 >> 192.168.1.22 tcp dpt:22 >> 0 0 logaccept tcp -- * * 0.0.0.0/0 >> 192.168.1.22 tcp dpt:22 >> 0 0 TRIGGER 0 -- vlan2 br0 0.0.0.0/0 >> 0.0.0.0/0 TRIGGER type:in match:0 relate:0 >> 587 37697 trigger_out 0 -- br0 * 0.0.0.0/0 >> 0.0.0.0/0 >> 585 37605 logaccept 0 -- br0 * 0.0.0.0/0 >> 0.0.0.0/0 state NEW >> 2 92 logdrop 0 -- * * 0.0.0.0/0 >> 0.0.0.0/0 >> Chain OUTPUT (policy ACCEPT 29813 packets, 16957527 bytes) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_1 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_10 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_2 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_3 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_4 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_5 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_6 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_7 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_8 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain advgrp_9 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_1 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_10 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_2 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_3 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_4 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_5 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_6 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_7 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_8 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain grp_9 (0 references) >> pkts bytes target prot opt in out source >> destination >> Chain lan2wan (1 references) >> pkts bytes target prot opt in out source >> destination >> Chain logaccept (11 references) >> pkts bytes target prot opt in out source >> destination >> 73605 34339968 ACCEPT 0 -- * * 0.0.0.0/0 >> 0.0.0.0/0 >> Chain logdrop (4 references) >> pkts bytes target prot opt in out source >> destination >> 99072 21162465 DROP 0 -- * * 0.0.0.0/0 >> 0.0.0.0/0 >> Chain logreject (0 references) >> pkts bytes target prot opt in out source >> destination >> 0 0 REJECT tcp -- * * 0.0.0.0/0 >> 0.0.0.0/0 reject-with tcp-reset >> Chain trigger_out (1 references) >> pkts bytes target prot opt in out source >> destination >> >> >> Any help is appreciated. >> >> >> --- mike t. >> >> >> _________________________________________________ >> Philippine Linux Users' Group (PLUG) Mailing List >> http://lists.linux.org.ph/mailman/listinfo/plug >> Searchable Archives: http://archives.free.net.ph >> > > > _________________________________________________ > Philippine Linux Users' Group (PLUG) Mailing List > http://lists.linux.org.ph/mailman/listinfo/plug > Searchable Archives: http://archives.free.net.ph > _________________________________________________ Philippine Linux Users' Group (PLUG) Mailing List http://lists.linux.org.ph/mailman/listinfo/plug Searchable Archives: http://archives.free.net.ph