LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-09-2012, 04:43 AM   #1
KatrinAlec
Member
 
Registered: Feb 2012
Posts: 116

Rep: Reputation: 13
wrong subnet from ipsec?


Hello,

I've got a wrong routing in my routing table.
I'm not sure how it got there.
80.0.0.0/8 dev ipsec0 proto kernel scope link src 80.x.x.x
where 80.x.x.x is the ip address of the ADSL

A trace of what's happening with rtmon showed that it reappears every time the ADSL-connection is reconnected.
That's when the IPSec interfaces are added, because the ADSL is also used for IPSec connections.

rtmon trace says:
broadcast 80.0.0.0 dev ipsec0 table local kernel scope link src 80.x.x.x
(where 80.x.x.x is the ip address of the ADSL).

/var/log/messages says at the same timestamp:
adding interface ipsec0/ppp3 80.x.x.x:500
adding interface ipsec0/ppp3 80.x.x.x:4500
(where 80.x.x.x is the ip address of the ADSL).

I guess the adding of those interfaces is what adds the routing,
but I think it ought to be with a subnet /32, at least not /8.

How can I influence that?
In which files could those settings be?

We are using webmin to change all the settings, so I can't see what I'm really doing.

Any help would be greatly appreciated.

Katrin
 
Old 03-12-2012, 10:59 AM   #2
verigoth
Member
 
Registered: May 2002
Posts: 179

Rep: Reputation: Disabled
Is this something that is not working properly? Or does it just "not look right" to you? 80.x is in the class A (/8) range..so unless it has been further subnetted that is correct. Does the interface receive it's address via DHCP or is it static? If it is given via DHCP and it's not working properly you will need to take it up with the telco. If it is static what is the subnet mask supposed to be? Certainly not 255.255.255.255 (/32). I don't know what you mean by it being configured by webmin..is it a router or server or what? What distribution is it running? What services is it running? Can you connect TO it from the outside? Can you connect FROM it to the outside? I guess I don't understand what issues you're having..if any at all.
 
Old 03-13-2012, 03:23 AM   #3
KatrinAlec
Member
 
Registered: Feb 2012
Posts: 116

Original Poster
Rep: Reputation: 13
Thanks for your answer.

The problem is the following:
That router has an IP-Sec connection via ppp3 AND it needs to be reached from the "normal" Internet via ppp3.
If one of those "normal" Internet- Addresses happens to start with 80 it's not routed back to ppp3, but to ipsec0. So the SynAck never reaches it's destination.
Everything works normally if the internet-addresses start with a different number, that's why we hadn't noticed the problem up to now.

The 80.x.x.x IP-Address is from the provider, it's assigned when the PPPoE is connected. Since it's a DSL connection, it only has that one IP-Address.

Webmin is a kind of GUI, which we're using instead of editing the .conf-Files themselves.
I could also edit the .conf files, but I don't have the proper knowledge yet.

We're buying those routers from a company which basically tells us how to set up the routers, but they don't have an answer for me either.
The OS is Linux 2.6.32.45

Do you know how I can find out which of the programs is responsible to add that routing?
If the problem is in one of the scripts that company uses, I might not have a chance to find out.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Unable to ping local subnet behind peer in IPSEC tusharsharma43 Linux - Networking 2 12-05-2011 05:50 AM
[SOLVED] VLAN with 2 Router and 2 Subnet - Is device in different subnet works? velusawme Linux - Networking 2 07-23-2011 10:16 AM
why is this subnet wrong? molossus Linux - Networking 4 11-23-2010 06:17 AM
[SOLVED] DHCP client in wrong subnet AchimRS Linux - Networking 3 07-20-2010 01:29 PM
vpn-ipsec : Failed to parse config setup portion of ipsec.conf hari85 Linux - Newbie 1 07-17-2010 08:12 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration