1
24.7 Production Series / Re: How can we nat a remote network using vxlan wireguard ?
« on: November 25, 2024, 04:09:23 pm »
Got it.
I'll try to correct the weirdness
I'll try to correct the weirdness
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
[code]bridge0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1370
description: PONT (opt5)
options=0
ether 58:9c:fc:10:81:3d
inet 10.28.79.1 netmask 0xfffffffc broadcast 10.28.79.3
id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200
root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
member: vxlan1 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
ifmaxaddr 0 port 19 priority 128 path cost 55
member: igb3 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
ifmaxaddr 0 port 4 priority 128 path cost 20000
groups: bridge
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
bridge0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1370
description: PONT (opt5)
options=0
ether 58:9c:fc:10:ff:8a
inet 10.28.79.2 netmask 0xfffffffc broadcast 10.28.79.3
id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200
root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
member: vxlan1 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
ifmaxaddr 0 port 23 priority 128 path cost 55
member: igc3 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
ifmaxaddr 0 port 4 priority 128 path cost 8000
groups: bridge
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
------------------------------------------------------
NAT works on vlan50's for local host
--------------------------------------------------------
VLAN50Free
vlan0.50 2024-11-22
09:55:03.071020 0c:b2:b7:cf:da:8e a8:b8:e0:01:ef:b3 ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 50629, offset 0, flags [DF], proto ICMP (1), length 84)
192.168.50.44 > 8.8.8.8: ICMP echo request, id 27503, seq 1, length 64
InternetWAN
igc0 2024-11-22
09:55:03.071099 a8:b8:e0:01:ef:b1 20:66:cf:60:32:31 ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 63, id 50629, offset 0, flags [DF], proto ICMP (1), length 84)
[b]82.XX.XX.64 > 8.8.8.8[/b]: ICMP echo request, id 11344, seq 1, length 64
InternetWAN
igc0 2024-11-22
09:55:03.087745 20:66:cf:60:32:31 a8:b8:e0:01:ef:b1 ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 118, id 0, offset 0, flags [none], proto ICMP (1), length 84)
8.8.8.8 > 82.XX.XX.64: ICMP echo reply, id 11344, seq 1, length 64
VLAN50Free
vlan0.50 2024-11-22
09:55:03.087763 a8:b8:e0:01:ef:b3 0c:b2:b7:cf:da:8e ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 117, id 0, offset 0, flags [none], proto ICMP (1), length 84)
8.8.8.8 > 192.168.50.44: ICMP echo reply, id 27503, seq 1, length 64
----------------------------------------------------------
But a remote host doesn't go internet. No NAT
----------------------------------------------------------
VLAN50Free
vlan0.50 2024-11-22
09:53:46.895976 ec:b1:d7:99:25:9c a8:b8:e0:01:ef:b3 ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 128, id 53111, offset 0, flags [none], proto ICMP (1), length 60)
192.168.50.45 > 8.8.8.8: ICMP echo request, id 1, seq 236, length 40
InternetWAN
igc0 2024-11-22
09:53:46.896003 a8:b8:e0:01:ef:b1 20:66:cf:60:32:31 ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 127, id 53111, offset 0, flags [none], proto ICMP (1), length 60)
[b]192.168.50.45 > 8.8.8.8[/b]: ICMP echo request, id 1, seq 236, length 40