Displaying 20 results from an estimated 50000 matches similar to: "No subject"
2010 Mar 12
1
Routing issue
Hi,
I just set up tinc between two hosts (for now). All seems to work fine,
but now I run in to a routing issue:
I gave both of my vpn routers an IP in the 172.16.100.0/24 range, and
used the Subnet-directive to inform tinc of this. This works fine, I can
ping both hosts from both sides of the vpn.
Ofcourse both vpn routers give access to other subnets, but they don't
know the IP-ranges
2017 Sep 07
1
A FAQ: is it mandatory to include the local IP address classes in the global VPN address class?
Hello,
Since the present tinc documentation is not very clear about this, please
explain the following: is it mandatory to include the local IP address
classes in the global VPN address class?
Namely, please consider the following setup (which works great in practice):
1. A tinc VPN, full mesh, with n nodes (n > 3)
2. tinc runs on the firewall, which is also the default gateway for each
2018 May 14
0
Node to Node UDP Tunnels HOWTO?
Here are a few facts that should make things clearer.
Regarding keys:
- The key used for the metaconnections (routing protocol over TCP) - i.e.
the one you configure in your host files - is NOT the same as the key used
for UDP data tunnels.
- The key for data tunnels is negotiated over the metaconnections, by
sending REQ_KEY and ANS_KEY messages over the metagraph (i.e. the graph of
2015 Oct 01
2
Tinc + OSPF - is it feasible?
Hello,
Please tell me if it's possible to use tinc together with OSPF (instead of
static routes in LAN). By OSPF I mean Quagga's GNU/Linux daemon.
Namely, I have a group of LANs (private 192.168.x.0/24 each).
Each LAN has a GNU/Linux default gateway, 192.168.x.1, that also connects
to the Internet via a public IP address (does NAT and firewall for the LAN
"behind" it).
tinc
2015 May 12
0
Letting linux be the router, allowing dynamic routes, suggestion
On Tue, May 12, 2015 at 04:27:10PM -0300, Marcelo Pacheco wrote:
> Consider the challenge of having completely dynamic routing between vpn
> peers. In one minute I might have 10000 routes towards one specific peer,
> and hour latter I might have NONE. And I need to diferentiate each peer at
> the kernel routing layer.
> And no, it can't be a pure bridge, it has to be L3
2016 Nov 17
1
Windows tinc network no data despite tinc connection
Hi guys, thanks in advance for any answers.
Trying to get tinc up and running, I hit a roadblock though. What I’m trying to do is to connect to my roaming notebook to my company network.
All hosts on our network live in the 10.42.x.x range, netmask is 255.255.0.0.
Tinc 1.1pre14 service is running on a Windows host 10.42.2.50.
Public ports are natted through, telnetting public ip port 655 the
2005 Dec 03
2
Tinc OSPF involving bridge
Hi Everyone,
I have a routing situation where Tinc looks like it could come in extremely useful, but I have a query I hope someone can cast an eye on, as I'm unsure whether Tinc can help me here.
I currently have a Quagga OSPF linux router which connects LAN A to LAN B over the quickest available of two routes (both routes at both ends connect to Quagga boxes to prevent collisions).
One of
2015 Jun 11
0
tinc as layer 2 switch doesn't automatically mesh with other nodes
tinc uses direct UDP communication for performance, not reliability.
If you want to establish more metaconnections for increased
reliability, you can use AutoConnect (though it probably won't work
across NATs). A better solution is to use two central nodes (instead
of one) for redundancy.
On 11 June 2015 at 18:59, Daniel J. Grinkevich
<danielgrinkevich at gmail.com> wrote:
> If we
2016 Sep 03
0
One host for forwarding only without keys
If you're using StrictSubnets, you will still be fine. StrictSubnets means
that A will only use B's key (which C does not know) to send packets to B's
statically configured subnets. C cannot impersonate B (as in, take its node
name) because it would have to know B's private key to do so, and it cannot
impersonate B's subnets because A is using StrictSubnets. The worst that C
2015 May 12
4
Letting linux be the router, allowing dynamic routes, suggestion
What challenge this would solve ?
VPN software in general tries to be another router when running in server
mode with multiple clients.
This restricts VPN customers from having complex topology.
For instance, I'd like to have two tunnels between each client network and
each server (with two broadband connections on each end), with some OSPF
running and automatically switching from one to
2002 Apr 25
1
Routing between two tunnels
Hi!
Me and two friends are trying to get a VPN working, but we cant get routing
between two tunnels.
This is how it looks, all servers (192.168.*.1) are running IP Masquerade to
enable the other computers behind them to access the internet.
Both elayne and glenn are connecting to melc, and the tunnel between melc
and glenn are running TCPOnly because that glenn doesnt have a public IP
(it's
2015 May 12
2
Letting linux be the router, allowing dynamic routes, suggestion
I see what you want me to do. But it does incur an extra MAC layer header
to each VPN packet, more fragmentation.
And broadcasts leak to all peers.
It sure saves you from doing any improvements, but there are side effects
that are undesirable to many customers.
This is specially a problem if I want two VPN connections between two sites
using redundant connections, we get an instant L2 loop.
With
2017 May 01
0
Concept clarification between multiple ConnecTo and multiple netname
That's exactly right. Corollary: if you take one node from a tinc network
and connect it to a node from another isolated tinc network, the two
networks become one :)
On 1 May 2017 at 13:16, Bright Zhao <startryst at gmail.com> wrote:
> Hi, Etienne
>
> Thanks for your clarification, and this helped a lot. And in order to get
> a better understanding for the mechanism of Tinc
2018 May 24
0
Cannot ping subnet hosts
did you add a forwarding allow rule from tinc interface to lan and vise
versa on both ends? even with firewall off default is to not forward till
told to do so.
On Thu, May 24, 2018, 10:07 AM Davide L <davide.lovreglio at gmail.com> wrote:
> Dear all,
>
> I am trying to configure a basic TINC vpn between two sites using OpenWRT
> routers. The link seems to work, the ping
2018 May 24
1
Cannot ping subnet hosts
I have done it... added on both routers a new firewall zone covering the
tinc interface, policy in accept, out accept, fwd accept, interzone
forwarding from/to LAN.... when I do it, I am not even able to ping the
routers between them, even though the PING PONG is ok in the tinc debug....
2018-05-24 20:28 GMT+02:00 Naemr . <naemrr at gmail.com>:
> did you add a forwarding allow rule from
2014 Sep 23
2
Using Tinc to create overlay network for VMs or LXC containers?
Hi, I am trying to understand Tinc better. I have gone through the
documentation and the recent mailing lists.
What I am trying to do is see if Tinc can be an alternative to using OVS
with GRE tunnels to connect VMs on 2 subnets, only in this case I am using
LXC containers.
LXC creates a NAT network called lxcbr0 typically on a 10.0.3.0 subnet
(similar in functionality to virbr0 for KVM) that
2006 Apr 26
3
Weird arp behavior
Hi all,
So, I've deployed Tinc in a non normal manor to which has been working
just fine for days up until recent. Here is a description of the network.
There are two VPN host controllers, A and B. All nodes have a separate
connection to A and B. Tinc has been configured to be in 'switch' mode
for both the A cloud and B cloud. On the back end, I have OSPF running
on all nodes and
2014 Feb 25
3
PMTU = 1518 over local network at 1500 MTU
Hi all,
I have two nodes, connected to a switch, using Tinc 1.1 from git.
They connect each other with sptps, and to other nodes in the Internet
with old protocol because they have Tinc 1.0.
There is no problem with remote nodes, but between my 2 local nodes,
they see 1518 PMTU. But local network is 1500 MTU !!! So nodes can ping
each other but larger data does not go.
test1=sllm1
test2=sllm2
1999 Sep 12
1
No subject
Hi,
I am using tin-0.3 and trying to route over a tinc tunnel. Here is my
details:
192.168.10.0/24
/ \
|
| ethernet network
|
\ /
-------------------------
| 192.168.10.254 (eth0) |
| Linux Router |
| 192.168.0.1 (tap0) |
-------------------------
/ \
|
|
| tinc tunnel
|
|
2017 May 01
2
Concept clarification between multiple ConnecTo and multiple netname
Hi, Etienne
Thanks for your clarification, and this helped a lot. And in order to get a better understanding for the mechanism of Tinc and the purpose of ConnectTo statement, can I think the ConnectTo is the way to get the node into the Tinc VPN domain, instead of establish VPN connection between nodes.
Once any node ConnectTo the Tinc VPN domain, it learns all other nodes, subnets, and