!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

916 Members
Declaratively manage your switching, routing, wireless, tunneling and more.269 Servers

Load older messages


SenderMessageTime
5 Jun 2021
@hexa:lossy.networkhexahttps://git.openwrt.org/?p=openwrt/openwrt.git;a=commit;h=634c13c186646aff2badb51a43b248825d0fe5a000:54:28
@hexa:lossy.networkhexa
In reply to @noah:matrix.chatsubo.cafe
hexa I probably need to forward 25 from wg0 to eth0 on my remote as well right?
No, iptables just needs to mark that traffic, the rest happens with routing based on that fwmark
00:55:02
@zhaofeng:zhaofeng.liZhaofeng Li
In reply to @hexa:lossy.network
https://git.openwrt.org/?p=openwrt/openwrt.git;a=commit;h=634c13c186646aff2badb51a43b248825d0fe5a0
Wow nice, I might actually consider it
00:55:26
@hexa:lossy.networkhexaDual A53 (1,36 GHz)00:55:50
@hexa:lossy.networkhexahttps://www.mediatek.com/products/homenetworking/mt762200:56:12
@zhaofeng:zhaofeng.liZhaofeng LiWell, it's an AP so it doesn't matter that much00:56:15
@hexa:lossy.networkhexayup00:56:18
@noah:matrix.chatsubo.cafeChurchHmm what would be the easiest way for me to see how a packet flows? 01:00:58
@hexa:lossy.networkhexatcpdump to see the packet01:01:15
@hexa:lossy.networkhexa then use ip route get <dest> from <src> 01:01:27
@elvishjerricco:matrix.orgElvishJerriccoSo on a dual band router, does the OS on the router see two different wireless interfaces, one for each band?01:28:48
@hexa:lossy.networkhexayes01:37:50
@noah:matrix.chatsubo.cafeChurchHmm, is there not a mangle table on nixOS?02:43:04
@noah:matrix.chatsubo.cafeChurchSeems to not be there by default at least when I try to insert a rule02:43:18
@hexa:lossy.networkhexaRedacted or Malformed Event03:04:03
@hexa:lossy.networkhexaimage.png
Download image.png
03:05:02
@hexa:lossy.networkhexa(https://en.wikipedia.org/wiki/Netfilter#/media/File:Netfilter-packet-flow.svg)03:05:20
@hexa:lossy.networkhexait's not available in all chains03:06:00
@noah:matrix.chatsubo.cafeChurch
[root@teapot:~]# iptables -A prerouting -t mangle -i wg0 -p tcp --dport 25 --jump MARK --set-mark 2
iptables: No chain/target/match by that name.
03:34:17
@zhaofeng:zhaofeng.liZhaofeng LiChains are case-sensitive. Use PREROUTING04:53:03
@noah:matrix.chatsubo.cafeChurchAh05:23:23
@zhaofeng:zhaofeng.liZhaofeng Li Upgrading my routers today and noticed that I'm building the kernels. Turns out I have a kernelPatch to enable CONFIG_INFINIBAND_IPOIB_CM back when I first switched to NixOS from Arch, and it's not enabled in the default kernel. 06:37:45
@zhaofeng:zhaofeng.liZhaofeng LiSo apparently no one except me is using IB with NixOS? 😅 Opening a PR in a bit06:38:36
@corbin:matrix.orgCorbinYou might be the only one using the Connected Mode feature. A PR seems sensible, since it would only trigger the underlying module to be built.07:38:04
@zhaofeng:zhaofeng.liZhaofeng LiI was saying that because IPoIB isn't really "usable" without Connected Mode. The performance is just so much better.08:01:24
@nyanotech:catgirl.solutionsnyanotech joined the room.14:24:01
@noah:matrix.chatsubo.cafeChurchHmm seems my policy based route for port 25 traffic still isn't working. Grumble, I think this is why I quit trying this last time to heh17:37:27
@mutantmell:helveticastandard.commutantmellI have an old Unifi AC I'm currently not using, maybe I'll try putting NixOS or openwrt on it18:11:35
@hexa:lossy.networkhexa Church: might not need fwmark after all 22:11:53
@hexa:lossy.networkhexa ip rule knows dport 25 and iif eth0 22:12:09

Show newer messages


Back to Room ListRoom Version: 6