Sponsored Content
Full Discussion: ISP VPS, routing traffic
Special Forums IP Networking Proxy Server ISP VPS, routing traffic Post 302909414 by solaris_user on Wednesday 16th of July 2014 06:16:39 PM
Old 07-16-2014
Routing traffic from ISP datacenter to enterprise LAN

Hi guys

I need to setup server/router in my firm. We got from our ISP dedicated server in their data center. It has a static IP and it servers as replacement for out DSL connection. I configured our internal server to be border gateway and to connects to data center. "Remote" admin installed squid and IT staff can access to the websites but other can't. I want to remove that proxy server. I think I really don't need it.

Here is the picture how above situation looks

Image

Server router has two NICs, one is connected to ISP router which we can't access, and one nic is connected to our private LAN. I use CentOS Linux 6.5 x64 to act as router. I added in iptables firewall to forward all traffic from eth0 to eth1 (from internal to public) and allowed traffic to leave server. All output traffic is nated.

Problem is on the other site. I'm not a network engineer but only with some knowledge in networking and formal IT education at the firm. My problem is I can't ping anything on the Internet while our VPS can. On that same server only port 80 and 22 are opened. People who setup proxy can connect to outside world but can't ping, can't use other networking software.

I have some questions:

How I can see my private LAN from ISP network, I will need to setup VPN in the short time ?
Is possible to avoid proxy and just with firewall NAT get data from the net back to the hosts in the private LAN ?

I am afraid to mess with ISP server because they administrate that server, we are and I really won't to understand how configure a network.

Thanks for reading and suggestions.

Last edited by solaris_user; 07-16-2014 at 07:26 PM..
 

8 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

Linux for an internet server to an ISP

I just moved away from a T3 line back to a dial up I just wanted to know would a P200 with 64meg and a 4 gig hard drive be ok for a linux server for an additional 3 pcs all running win98. I will be dialing into an isp using a 56k v90 modem. Any support or help will be great. (3 Replies)
Discussion started by: izrailov
3 Replies

2. UNIX for Dummies Questions & Answers

Cannot connect to my ISP

I'm totally frustrated, my administrator has left the state and me high and dry! My modem cannot connect to my ISP all it does is start to ping and the a high pitched squeal for about a minute. I have logged on as the "root" in hope to get into my /etc/ppp/ppp.conf file however I get a... (8 Replies)
Discussion started by: coolteach
8 Replies

3. IP Networking

Routing Network Traffic With Mandrake

I am running Mandrake 8.0 (KDE ver 2.1.1) on a machine with 2 NICs. This is a college project. I am attempting to configure this machine as a firewall, and to pass packets from one network to another. Eth0 is on my external network. Eth1 is on my internal network. I set the gateway in "netconf"... (1 Reply)
Discussion started by: Deuce
1 Replies

4. UNIX for Dummies Questions & Answers

schedule dial-out different ISP's

Hi, I'm running user ppp on FreeBSD. I have an internet account which gives me the oppertunity to login for free (say €25 a month :)) during specific hours. Outside these hours I pay the normal fee. I also have another ISP which gives me the oppertunity to log in for a reduced fee all times. ... (2 Replies)
Discussion started by: Hansaplast
2 Replies

5. IP Networking

2 ip from one subnet my isp

Hi. my english is not so good. sorry. i have some problem. My isp give me second ip from subnet. One network is working, but secong don't. fxp0 - my network dc0 - network isp (that working) re0 - network isp (don't working) i try use ng_one2many, but it's don't working ngctl mkpeer... (0 Replies)
Discussion started by: kil
0 Replies

6. IP Networking

Routing traffic problem between 3G and Office Lan Network

Hi, I would like to ask some networking solution regarding my work LAN and 3G usb network problem. I want to route my internet traffic to the 3G network and sometimes connect to some of my work network for ssh to configure some workstation or print something. Currently my problem is i can't... (0 Replies)
Discussion started by: jao_madn
0 Replies

7. Solaris

Traffic routing through wrong interface

Solaris-9 server is having one primary IP 10.41.161.14 on qfe0 and 10.41.116.0 on qfe3:1. Traffic is going through virtual interface instead of physical interface. How should I force traffic to go with primary interface. root@smtsrvn01:/# netstat -nr Routing Table: IPv4 Destination ... (2 Replies)
Discussion started by: solaris_1977
2 Replies

8. IP Networking

Multiple isp physical connection

Hello all my friends see picture to understand my problem http://www.imageurlhost.com/images/8mf8ni4btu6r4qy1rp9_Networking-photo.png i want to know that how my company can connect multiple isp via switch and output from switch is directly connected to linux firewall. Any help Thanks (1 Reply)
Discussion started by: rink
1 Replies
ovs-vlan-test(1)						Open vSwitch Manual						  ovs-vlan-test(1)

NAME
ovs-vlan-test - check Linux drivers for problems with vlan traffic SYNOPSIS
ovs-vlan-test [-s | --server] control_ip vlan_ip Common options: [-h | --help] [-V | --version] DESCRIPTION
The ovs-vlan-test utility has some limitations, for example, it does not use TCP in its tests. Also it does not take into account MTU to detect potential edge cases. To overcome those limitations a new tool was developed - ovs-test. ovs-test is currently supported only on Debian so, if possible try to use that on instead of ovs-vlan-test. The ovs-vlan-test program may be used to check for problems sending 802.1Q traffic which may occur when running Open vSwitch. These prob- lems can occur when Open vSwitch is used to send 802.1Q traffic through physical interfaces running certain drivers of certain Linux kernel versions. To run a test, configure Open vSwitch to tag traffic originating from vlan_ip and forward it out the target interface. Then run the ovs-vlan-test in client mode connecting to an ovs-vlan-test server. ovs-vlan-test will display "OK" if it did not detect problems. Some examples of the types of problems that may be encountered are: o When NICs use VLAN stripping on receive they must pass a pointer to a vlan_group when reporting the stripped tag to the networking core. If no vlan_group is in use then some drivers just drop the extracted tag. Drivers are supposed to only enable stripping if a vlan_group is registered but not all of them do that. o On receive, some drivers handle priority tagged packets specially and don't pass the tag onto the network stack at all, so Open vSwitch never has a chance to see it. o Some drivers size their receive buffers based on whether a vlan_group is enabled, meaning that a maximum size packet with a VLAN tag will not fit if no vlan_group is configured. o On transmit, some drivers expect that VLAN acceleration will be used if it is available, which can only be done if a vlan_group is configured. In these cases, the driver may fail to parse the packet and correctly setup checksum offloading or TSO. Client Mode An ovs-vlan-test client may be run on a host to check for VLAN connectivity problems. The client must be able to establish HTTP connec- tions with an ovs-vlan-test server located at the specified control_ip address. UDP traffic sourced at vlan_ip should be tagged and directed out the interface whose connectivity is being tested. Server Mode To conduct tests, an ovs-vlan-test server must be running on a host known not to have VLAN connectivity problems. The server must have a control_ip on a non-VLAN network which clients can establish connectivity with. It must also have a vlan_ip address on a VLAN network which clients will use to test their VLAN connectivity. Multiple clients may test against a single ovs-vlan-test server concurrently. OPTIONS
-s, --server Run in server mode. -h, --help Prints a brief help message to the console. -V, --version Prints version information to the console. EXAMPLES
Display the Linux kernel version and driver of eth1. uname -r ethtool -i eth1 Set up a bridge which forwards traffic originating from 1.2.3.4 out eth1 with VLAN tag 10. ovs-vsctl -- add-br vlan-br -- add-port vlan-br eth1 -- add-port vlan-br vlan-br-tag tag=10 -- set Interface vlan-br-tag type=internal ifconfig vlan-br-tag up 1.2.3.4 Run an ovs-vlan-test server listening for client control traffic on 172.16.0.142 port 8080 and VLAN traffic on the default port of 1.2.3.3. ovs-vlan-test -s 172.16.0.142:8080 1.2.3.3 Run an ovs-vlan-test client with a control server located at 172.16.0.142 port 8080 and a local VLAN ip of 1.2.3.4. ovs-vlan-test 172.16.0.142:8080 1.2.3.4 SEE ALSO ovs-vswitchd(8), ovs-ofctl(8), ovs-vsctl(8), ovs-test(8), ethtool(8), uname(1) Open vSwitch December 2010 ovs-vlan-test(1)
All times are GMT -4. The time now is 10:48 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy