Hello;
The Canadian Coordinator (Luc) setup the reverse DNS for a few IP's, but
still having the same issue.
On my 44.135.100.64 box (
alpha.va3ian.ampr.org), I ping 8.8.8.8:
# tcpdump -vvv -i ens160 -s0 -n proto ipencap
tcpdump: listening on ens160, link-type EN10MB (Ethernet), capture size
262144 bytes
04:06:20.335949 IP (tos 0x0, ttl 64, id 35897, offset 0, flags [DF], proto
IPIP (4), length 104)
209.249.157.70 > 169.228.34.84: IP (tos 0x0, ttl 63, id 11140, offset
0, flags [DF], proto ICMP (1), length 84)
44.135.100.64 > 8.8.8.8: ICMP echo request, id 2198, seq 4, length 64
04:06:21.359937 IP (tos 0x0, ttl 64, id 35904, offset 0, flags [DF], proto
IPIP (4), length 104)
209.249.157.70 > 169.228.34.84: IP (tos 0x0, ttl 63, id 11371, offset
0, flags [DF], proto ICMP (1), length 84)
44.135.100.64 > 8.8.8.8: ICMP echo request, id 2198, seq 5, length 64
04:06:22.383955 IP (tos 0x0, ttl 64, id 36075, offset 0, flags [DF], proto
IPIP (4), length 104)
209.249.157.70 > 169.228.34.84: IP (tos 0x0, ttl 63, id 11534, offset
0, flags [DF], proto ICMP (1), length 84)
44.135.100.64 > 8.8.8.8: ICMP echo request, id 2198, seq 6, length 64
04:06:23.407933 IP (tos 0x0, ttl 64, id 36281, offset 0, flags [DF], proto
IPIP (4), length 104)
209.249.157.70 > 169.228.34.84: IP (tos 0x0, ttl 63, id 11621, offset
0, flags [DF], proto ICMP (1), length 84)
44.135.100.64 > 8.8.8.8: ICMP echo request, id 2198, seq 7, length 64
Something is still blocking the communication coming back... no ICMP echo
reply.
Same, but to 44.135.87.1:
# tcpdump -vvv -i ens160 -s0 -n proto ipencap
tcpdump: listening on ens160, link-type EN10MB (Ethernet), capture size
262144 bytes
04:08:08.874899 IP (tos 0x0, ttl 64, id 64044, offset 0, flags [DF], proto
IPIP (4), length 104)
209.249.157.70 > 216.46.157.231: IP (tos 0x0, ttl 63, id 10835, offset
0, flags [DF], proto ICMP (1), length 84)
44.135.100.64 > 44.135.87.1: ICMP echo request, id 2200, seq 6, length
64
04:08:08.900877 IP (tos 0x0, ttl 52, id 35798, offset 0, flags [DF], proto
IPIP (4), length 104)
216.46.157.231 > 209.249.157.70: IP (tos 0x0, ttl 64, id 53707, offset
0, flags [none], proto ICMP (1), length 84)
44.135.87.1 > 44.135.100.64: ICMP echo reply, id 2200, seq 6, length 64
04:08:09.876445 IP (tos 0x0, ttl 64, id 64228, offset 0, flags [DF], proto
IPIP (4), length 104)
209.249.157.70 > 216.46.157.231: IP (tos 0x0, ttl 63, id 10977, offset
0, flags [DF], proto ICMP (1), length 84)
44.135.100.64 > 44.135.87.1: ICMP echo request, id 2200, seq 7, length
64
04:08:09.902369 IP (tos 0x0, ttl 52, id 36030, offset 0, flags [DF], proto
IPIP (4), length 104)
216.46.157.231 > 209.249.157.70: IP (tos 0x0, ttl 64, id 53800, offset
0, flags [none], proto ICMP (1), length 84)
44.135.87.1 > 44.135.100.64: ICMP echo reply, id 2200, seq 7, length 64
04:08:10.877958 IP (tos 0x0, ttl 64, id 64382, offset 0, flags [DF], proto
IPIP (4), length 104)
209.249.157.70 > 216.46.157.231: IP (tos 0x0, ttl 63, id 11074, offset
0, flags [DF], proto ICMP (1), length 84)
44.135.100.64 > 44.135.87.1: ICMP echo request, id 2200, seq 8, length
64
04:08:10.903853 IP (tos 0x0, ttl 52, id 36106, offset 0, flags [DF], proto
IPIP (4), length 104)
216.46.157.231 > 209.249.157.70: IP (tos 0x0, ttl 64, id 53971, offset
0, flags [none], proto ICMP (1), length 84)
44.135.87.1 > 44.135.100.64: ICMP echo reply, id 2200, seq 8, length 64
Any help is greatly appreciated.
Ian.
On Sun, Jul 5, 2020 at 2:47 AM Ian Redden <iredden(a)gmail.com> wrote:
Hi Everyone!
I have a Ubuntu 20.04 LTS box installed with the following network
configuration:
*Internet/ISP*
ens160: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 209.249.157.70 netmask 255.255.255.248 broadcast
209.249.157.71
inet6 fe80::250:56ff:feb7:eeb6 prefixlen 64 scopeid 0x20<link>
ether 00:50:56:b7:ee:b6 txqueuelen 1000 (Ethernet)
RX packets 7916 bytes 544678 (544.6 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 975 bytes 184556 (184.5 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
*HAM Network*
ens192: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 44.135.100.10 netmask 255.255.255.248 broadcast
44.135.100.15
inet6 fe80::250:56ff:feb7:57ba prefixlen 64 scopeid 0x20<link>
ether 00:50:56:b7:57:ba txqueuelen 1000 (Ethernet)
RX packets 35 bytes 2558 (2.5 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 37 bytes 3152 (3.1 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
inet6 ::1 prefixlen 128 scopeid 0x10<host>
loop txqueuelen 1000 (Local Loopback)
RX packets 104 bytes 8024 (8.0 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 104 bytes 8024 (8.0 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
*AMPRNet IPIP*
tunl0: flags=4289<UP,RUNNING,NOARP,MULTICAST> mtu 1480
inet 44.135.100.9 netmask 255.255.255.255
tunnel txqueuelen 1000 (IPIP Tunnel)
RX packets 37 bytes 17484 (17.4 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 5 bytes 260 (260.0 B)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
Machines on my "ham" network (44.135.100.8/29 - interface ens192) can
only communicate within the routes I receive via rip44. Is this normal?
For example, from a machine on the ham network (ens192), I can connect to
va3emt-1.ampr.org (44.135.87.1) but cannot ping 8.8.8.8 (google dns). A
tcpdump shows its going out the wrong interface (ens160).
Also, from my ISP, I can ping 44.135.87.1 (and retrieve the web page) but
I cannot ping or access 44.135.100.9,10,11,etc ....
Here are my commands I'm using to connect:
ip tunnel add tunl0 mode ipip local 209.249.157.70 ttl 255
ip link set dev tunl0 up
ifconfig tunl0 up 44.135.100.9 netmask 255.255.255.255 multicast
ip rule add to 44.0.0.0/9 table 44 priority 44
ip rule add to 44.128.0.0/10 table 44 priority 44
ip rule add from 44.135.100.8/29 table 44 priority 45
ip route add default dev tunl0 via 169.228.34.84 onlink table 44
ip route add 44.135.100.8/29 dev ens192 table 44
/usr/sbin/ampr-ripd -s -r -t 44 -i tunl0 -a 44.135.100.8/29 -d -v
Any ideas?
Ian.
Some debug:
root@ampr-router:~# ip rule
0: from all lookup local
44: from all to 44.0.0.0/9 lookup 44
44: from all to 44.128.0.0/10 lookup 44
45: from 44.135.100.8/29 lookup 44
32766: from all lookup main
32767: from all lookup default
root@ampr-router:~# ip route show
default via 209.249.157.65 dev ens160 proto static
44.135.100.8/29 dev ens192 proto kernel scope link src 44.135.100.10
209.249.157.64/29 dev ens160 proto kernel scope link src 209.249.157.70
root@ampr-router:~# ip route show table 44 | more
default via 169.228.34.84 dev tunl0 onlink
44.0.0.1 via 169.228.34.84 dev tunl0 proto 44 onlink window 840
44.2.0.1 via 191.183.136.1 dev tunl0 proto 44 onlink window 840
44.2.0.2 via 98.20.210.138 dev tunl0 proto 44 onlink window 840
44.2.0.3 via 36.83.94.245 dev tunl0 proto 44 onlink window 840
44.2.2.0/24 via 216.218.207.198 dev tunl0 proto 44 onlink window 840
44.2.7.0/30 via 73.116.117.178 dev tunl0 proto 44 onlink window 840
44.2.10.0/29 via 104.49.12.130 dev tunl0 proto 44 onlink window 840
44.2.11.8/29 via 47.33.29.119 dev tunl0 proto 44 onlink window 840
44.2.50.0/29 via 50.63.202.93 dev tunl0 proto 44 onlink window 840
44.4.0.48/28 via 107.3.166.19 dev tunl0 proto 44 onlink window 840
44.4.2.152/29 via 173.167.109.217 dev tunl0 proto 44 onlink window 840
..... alot of routes here .....
44.185.66.0/24 via 89.106.108.151 dev tunl0 proto 44 onlink window 840
44.185.69.0/24 via 80.80.140.38 dev tunl0 proto 44 onlink window 840
44.185.80.0/24 via 213.91.190.32 dev tunl0 proto 44 onlink window 840
44.185.92.0/24 via 213.91.190.32 dev tunl0 proto 44 onlink window 840
44.185.96.0/24 via 213.91.190.32 dev tunl0 proto 44 onlink window 840
44.185.103.0/24 via 89.190.200.249 dev tunl0 proto 44 onlink window 840
44.185.104.0/24 via 178.254.198.205 dev tunl0 proto 44 onlink window 840
44.185.105.0/24 via 91.139.210.119 dev tunl0 proto 44 onlink window 840
44.185.106.0/24 via 95.158.166.222 dev tunl0 proto 44 onlink window 840
44.185.107.0/24 via 77.70.122.201 dev tunl0 proto 44 onlink window 840
44.185.108.0/27 via 78.83.56.107 dev tunl0 proto 44 onlink window 840
44.185.109.0/24 via 91.92.93.15 dev tunl0 proto 44 onlink window 840
44.188.1.1 via 70.80.196.6 dev tunl0 proto 44 onlink window 840
44.188.192.222 via 176.67.24.190 dev tunl0 proto 44 onlink window 840
44.224.0.0/15 via 141.75.245.225 dev tunl0 proto 44 onlink window 840