<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;
mso-ligatures:none;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">The interface configuration files in /etc/sysconfig/network-scripts appear to be correct, so I am not sure where this might be coming from!<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0cm 0cm 0cm 4.0pt">
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> Taco Scargo <taco@blueonyx.nl>
<br>
<b>Sent:</b> Thursday, December 7, 2023 3:15 PM<br>
<b>To:</b> Darren Wolfe <darren@intersys-group.com>; BlueOnyx General Mailing List <blueonyx@mail.blueonyx.it><br>
<b>Subject:</b> Re: [BlueOnyx:26641] Interfaces and default routes<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I see <span style="color:black">1.1.1.225 is configured on eth1 as well though.</span><o:p></o:p></p>
<div>
<p class="MsoNormal"><span style="color:black">That should not be.</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black"><br>
<br>
</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">I think that is why the default gateway is also “attached” to eth1.</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black"><br>
<br>
</span><o:p></o:p></p>
</div>
<div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">1.1.1.225 0.0.0.0 255.255.255.255 UH 101 0 0 eth1<o:p></o:p></p>
</blockquote>
</blockquote>
</blockquote>
</div>
<div>
<p class="MsoNormal"><span style="color:black"><br id="lineBreakAtBeginningOfMessage">
<br>
</span><o:p></o:p></p>
<div>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="MsoNormal">On 7 Dec 2023, at 14:33, Darren Wolfe via Blueonyx <<a href="mailto:blueonyx@mail.blueonyx.it">blueonyx@mail.blueonyx.it</a>> wrote:<o:p></o:p></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="MsoNormal">Hi,<br>
<br>
I've adjusted for privacies sake, but the last octet is unchanged so the netmasks and network ranges make sense<br>
<br>
eth0 (public interface): 1.1.1.238, netmask 255.255.255.224<br>
Gateway address is 1.1.1.225<br>
<br>
eth1 (private interface): 192.168.17.18, netmask 255.255.255.0<br>
No gateway address or any other routes needed, this is used as a simple DMZ<br>
<br>
<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">-----Original Message-----<br>
From: Taco Scargo <<a href="mailto:taco@blueonyx.nl">taco@blueonyx.nl</a>><br>
Sent: Thursday, December 7, 2023 8:35 AM<br>
To: Darren Wolfe <<a href="mailto:darren@intersys-group.com">darren@intersys-group.com</a>>; BlueOnyx General Mailing List<br>
<<a href="mailto:blueonyx@mail.blueonyx.it">blueonyx@mail.blueonyx.it</a>><br>
Subject: Re: [BlueOnyx:26639] Interfaces and default routes<br>
<br>
Darren,<br>
<br>
Would you be so kind to share the IP addresses of the interfaces?<br>
Because the routing table does not make sense at all and it almost seems that<br>
both interfaces share the same network address space, which you should never<br>
do.<br>
<br>
Thanks,<br>
<br>
Taco<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">On 7 Dec 2023, at 00:44, Darren Wolfe via Blueonyx<o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><<a href="mailto:blueonyx@mail.blueonyx.it">blueonyx@mail.blueonyx.it</a>> wrote:<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><br>
Hi,<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">Indeed, the IPv6 autoconf=no should be set. I'll see to it.<o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
Thank you!<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">As for the default gateway? In my understanding there should be only one<br>
default gateway and that should apply to all interfaces. There may be<br>
additional routes that direct traffic destined for an internal network<br>
to the interface that the internal network is connected to. Or if<br>
OpenVPN is present, there ought to be a route that allows traffic to be<br>
directed to the private network that OpenVPN clients use.<br>
<br>
But there shouldn't be two default gateways.<o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
<br>
I shouldn't have confused the issue by mentioning two public default routes, but<o:p></o:p></p>
</blockquote>
<p class="MsoNormal">the idea that the default gateway should apply to all interfaces is an assumption<br>
that does not always hold. In my case, the public-facing interface has a public IP<br>
address as one would expect, but there is a DMZ network on a different interface<br>
and private address range which should not have the same default route applied<br>
to it.<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><br>
I may be misinterpreting what I see on the boxes which is that when the server<o:p></o:p></p>
</blockquote>
<p class="MsoNormal">is rebooted. This is how it looks:<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">eth0 is the public interface, eth1 is the private (ip's have been changed)<br>
<br>
Destination Gateway Genmask Flags Metric Ref Use Iface<br>
0.0.0.0 1.1.1.225 0.0.0.0 UG 100 0 0 eth0<br>
0.0.0.0 1.1.1.225 0.0.0.0 UG 101 0 0 eth1<br>
1.1.1.224 0.0.0.0 255.255.255.224 U 100 0 0 eth0<br>
1.1.1.225 0.0.0.0 255.255.255.255 UH 101 0 0 eth1<br>
192.168.17.0 0.0.0.0 255.255.255.0 U 101 0 0 eth1<br>
<br>
I don't know what that 4th rule is attempting to do..<br>
<br>
Sometimes eth1 will get the lower route metric, which results in no network<o:p></o:p></p>
</blockquote>
<p class="MsoNormal">connectivity. Even like the above, active monitor says:<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal">The network interface eth0 is down. The network interface eth1 is down.<br>
<br>
If the incorrect routes - the 2nd and 4th in the above, are removed, all is well.<br>
<br>
<br>
<br>
<br>
_______________________________________________<br>
Blueonyx mailing list<br>
<a href="mailto:Blueonyx@mail.blueonyx.it">Blueonyx@mail.blueonyx.it</a><br>
<a href="http://mail.blueonyx.it/mailman/listinfo/blueonyx">http://mail.blueonyx.it/mailman/listinfo/blueonyx</a><o:p></o:p></p>
</blockquote>
</blockquote>
<p class="MsoNormal"><br>
<br>
_______________________________________________<br>
Blueonyx mailing list<br>
<a href="mailto:Blueonyx@mail.blueonyx.it">Blueonyx@mail.blueonyx.it</a><br>
<a href="http://mail.blueonyx.it/mailman/listinfo/blueonyx">http://mail.blueonyx.it/mailman/listinfo/blueonyx</a><o:p></o:p></p>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
</div>
</body>
</html>