Forums before death by AOL, social media and spammers... "We can't have nice things"
|    alt.os.linux.slackware    |    I think its the one without Selinux crap    |    87,272 messages    |
[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]
|    Message 86,672 of 87,272    |
|    Lew Pitcher to Henrik Carlqvist    |
|    Re: Need help with LXC container routing    |
|    02 May 24 13:21:26    |
      From: lew.pitcher@digitalfreehold.ca              Hi, Henrik                     On Thu, 02 May 2024 05:15:19 +0000, Henrik Carlqvist wrote:              > On Wed, 01 May 2024 17:12:52 +0000, Lew Pitcher wrote:       >> I should mention that, in this configuration, I /have not/ implemented       >> any firewall rules. I want to get basic routing working before I start       >> complicating the data flow with a firewall.       >       > Maybe those firewall rules are exactly what you need. My guess is that       > you are lacking NAT (IP masqueradning). When sending ping or any other       > packet out from sysdev2 to internet those packages come from your private       > IP address 192.168.55.2 but only the sysdev1 machine knows how to reach       > back to that IP address. Your machine wordsworth with IP address       > 192.168.99.3 does not have a route back to 192.168.55.2.              And, with that simple statement, you have solved my problem.       /Of course/, wordsworth needs a route back to sysdev2. And, in the       environment I'm trying to model, that route would be supplied by       a NAT rule on sysdev1.              > Either you will       > need to implement NAT on sysdev1 or add a route on wordsworth (and       > probably also implement a more cumbersome NAT in your real internet       > facing router).                            Thanks, Henrik. You've hit the nail on the head.       And now, I'm off to make some firewall rules.              --       Lew Pitcher       "In Skills We Trust"              --- SoupGate-Win32 v1.05        * Origin: you cannot sedate... all the things you hate (1:229/2)    |
[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]
(c) 1994, bbs@darkrealms.ca