Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
01-08-2014, 07:47 PM
|
#1
|
Member
Registered: Dec 2003
Location: Current Location: Colorado
Distribution: Ubuntu 14.10, Mint 17.1 Cinnamon and Mate
Posts: 101
Rep:
|
Installing 2 Netgear Switches - 1 is successful and 1 isn't
All my computers have their IP addresses manually assigned and are either Ubuntu 12.04 desktops or are a Ubuntu 12.04 serve. This is a hard wired network.
I have never worked with pure switches before. I am inserting two plug'n'play unmanaged 8-port Netgear GS-108 Gigabit Switches into an existing and working network. One is being used to create the star pattern network where only one computer existed before and the other is being used to replace a device which was already creating a star pattern network of computers.
So...I have two separate star-pattern networks. These two networks are situated behind a Dedicated Computer running Shorewall acting as a firewall-router, who's Ethernet interfaces looks like this:
eth0 <---> Internet Modem 192.0.1.x
eth1 <---> Private Network 192.0.2.x (many computers)
eth2 <---> DMZ Network 10.0.0.x (currently only has 1 hosting computer, but I intend to add untrusted Ethernet connections, such as my cable HDTV receiver, Wifi, etc.)
The DMZ network, although it currently has only 1 computer on it, has the Netgear Switch installed to create a future star-patterned network via the Switch's ports. This network has absolutely no problems at all. The single computer on this network can ping everything it should and be pinged by everything that it should, just as it did before I put the Netgear Switch was placed between it and the Dedicated Firewall-router Computer. (I count this as a win!)
My Private network had an old 100Mb/s WRT 54G Router, which was running dd-WRT, which was programmed to only act as a simple switch to also create a star-pattern network via it's 4 ports at the time I set up the Dedicated Firewall-Router computer in the past.....and that network worked great. So, the dedicated firewall computer and the two networks were all very very happy with each other and worked just fine. THEN I MADE IT BETTER--
My problem began when I replaced the above WRT 54G Router with the new Netgear GS-108 Gigabit Switch, like the one I use in my DMZ network, to speed up my Private network. After the swap out and when I brought everything back up, the DMZ network continued to work great despite the addition of the new switch on it's own network.... But, my Private Network didn't like the swap out of the old WRT 54g Router for the Netgear Switch!
Symptoms:
Private computers CAN ping through the new switch to Dedicated Firewall ethernet Card. (192.0.2.x)
The Dedicated Firewall CAN ping the Private Computers. (192.0.2.x)
Private computers CAN NOT ping each other. (192.0.2.x)
Private computers CAN NOT ping the Dedicated Firewall's Internet Interface Card. (192.0.1.x)
And of course, Private computers CAN NOT ping things out on the Internet.
(Test setup: I changed the Firewall rules so that DMZ IP addresses are allowed to ping Private IP addresses)
DMZ computers 10.0.0.x CAN ping the Private computers 192.0.2.x
Private computers 192.0.2.x CAN NOT ping DMZ computers 10.0.0.x
I asked myself: Is the New Netgear Switch defective?
Experiment: I swapped the two Netgear Switches for each other's positions.
Observation1: The DMZ network continued to operate perfectly using the other's Switch and the Private network continued with the same problem using the other's Switch.
Side Observation2: All computers in both networks are reporting their cards are operating at Full Duplex 1000Mb/s.
Conclusion: There's no difference between the two switches...they both are working correctly.
Question: Has something changed in my firewall rules???
Action: I re-swapped the WRT 54G Router back into the place of the Netgear Switch in the Private Network.
Observation: THE FIREWALL RULES WORK PERFECTLY! All Private Computers now have the Internet and can ping each other.
Conclusion: Nothing seems to have changed in the Firewall rules.
Question: What's the difference between the old WRT 54G Router that was working only as a simple switch and a the Netgear Switch (other than speed and number of ports)?
Answer: Unknown
Does anyone have any ideas about what is wrong here and how to troubleshoot this further?
|
|
|
01-09-2014, 02:43 PM
|
#2
|
Senior Member
Registered: Apr 2009
Posts: 1,900
Rep: 
|
The switch don't know how to route packet. It only forward packet based on MAC address. You can use the computer with Dedicated Firewall Ethernet card as new router.
|
|
|
01-09-2014, 11:09 PM
|
#3
|
Member
Registered: Dec 2003
Location: Current Location: Colorado
Distribution: Ubuntu 14.10, Mint 17.1 Cinnamon and Mate
Posts: 101
Original Poster
Rep:
|
Thanks nini09!
After I used the dd-WRT software to make my WRT54G Router into a simple switch, I forgot that my Private network computers were all still using it's IP address as their Gateway addresses, and when I replaced it with a real managed switch, suddenly my computers couldn't find the gateway. The instant I gave them the Firewall's Interface IP address on their network, they all became very very happy!
Some days it just doesn't pay to be blond...
|
|
|
All times are GMT -5. The time now is 12:37 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|