Page 2 of 2 FirstFirst 12
Results 11 to 20 of 20

Thread: Routing problem

  1. #11
    Untangle Ninja dwasserman's Avatar
    Join Date
    Jun 2008
    Location
    Argentina
    Posts
    3,998

    Default

    Wich device is the .253?
    Paste here the trace route from network 10 please
    From untangle you can ping any device in net 10?
    Last edited by dwasserman; 08-03-2010 at 07:12 AM. Reason: reverse ping
    The world is divided into 10 kinds of people, who know binary and those not

  2. #12
    Untangle Ninja proactivens's Avatar
    Join Date
    Sep 2008
    Location
    Greensburg, Pa
    Posts
    2,328

    Default

    you need to either change you subnet mask from /24 to /16 or give untangle an IP alias on the 192.168.10.x network.

    Untangle cannot see the 192.168.10.x network unless you give it an ip alias or change your snm to cover the 192.168.10.x network.
    www.untangleappliances.com
    Toll Free: 866-794-8879
    UNTANGLE PLATINUM PARTNER
    Follow us at spiceworks!

  3. #13
    Untangle Ninja dwasserman's Avatar
    Join Date
    Jun 2008
    Location
    Argentina
    Posts
    3,998

    Default

    Quote Originally Posted by proactivens View Post
    you need to either change you subnet mask from /24 to /16 or give untangle an IP alias on the 192.168.10.x network.

    Untangle cannot see the 192.168.10.x network unless you give it an ip alias or change your snm to cover the 192.168.10.x network.
    Is more beautiful create static routes in networking/advance/route that's what he did, and it should work fine.
    But its dependent how work this vpn I think.
    The world is divided into 10 kinds of people, who know binary and those not

  4. #14
    Untanglit soborno's Avatar
    Join Date
    Feb 2010
    Location
    Uruguay
    Posts
    28

    Default

    I paste the screenshots from the 192.168.10.1 and the Ut screenshot.
    The device in the 192.168.20.253 or any .253 is a router run by a provider, Itīs out of my hands, all the non-VPN traffic is sent to 192.168.20.251, that always work fine in the other fw and it seems so also for the trace output.
    In the meanwhile, Iīll check proactivens advice.

    Regards,
    Claudio
    Attached Images Attached Images

  5. #15
    Untangle Ninja proactivens's Avatar
    Join Date
    Sep 2008
    Location
    Greensburg, Pa
    Posts
    2,328

    Default

    Quote Originally Posted by dwasserman View Post
    Is more beautiful create static routes in networking/advance/route that's what he did, and it should work fine.
    But its dependent how work this vpn I think.
    static routes isnt enough. ive done this plenty of times, you need either an ip alias or change the snm the way i described.
    www.untangleappliances.com
    Toll Free: 866-794-8879
    UNTANGLE PLATINUM PARTNER
    Follow us at spiceworks!

  6. #16
    Untanglit soborno's Avatar
    Join Date
    Feb 2010
    Location
    Uruguay
    Posts
    28

    Default

    Exactly as you say proactivens, it works now
    Thanks all for the help!
    I donīt want to bother anymore, but can you explain a little bit why change the snm was necesary, and static rules werenīt enough

    Anyway, it was a big help.

    Regards,
    Claudio

  7. #17
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,973

    Default

    Blame linux... the linux kernel isn't a bridge, it's a b-router. It has to know it's responsible for the address ranges in question.

    So you either have to add an alias, to put the server on all networks it needs to filter. Or, you widen the subnet mask to cover all of the IPs in question.

    The static route is really a pointless addition. The only reason you ever need that on a bridge is to cover a remote segment.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    NexgenAppliances.com
    Phone: 866-794-8879

  8. #18
    Untangle Ninja proactivens's Avatar
    Join Date
    Sep 2008
    Location
    Greensburg, Pa
    Posts
    2,328

    Default

    your welcome Skyknight is right, untangle needs to be addressable on every network its connected to. Otherwise, it doesnt know how to communicate to that network. Static routes should be enough, but they are not. Thats just the way it is. One of the caveats of Untangle.
    www.untangleappliances.com
    Toll Free: 866-794-8879
    UNTANGLE PLATINUM PARTNER
    Follow us at spiceworks!

  9. #19
    Untangle Ninja dwasserman's Avatar
    Join Date
    Jun 2008
    Location
    Argentina
    Posts
    3,998

    Default

    Really I dont finish to understand well.
    If you change the netmask to 16 work ok, but generate a big broadcast domain, with the risk of saturate the vpn links with this.
    I have only one installation with UT and remote private 5 sites, and config them in networking/advance/routes without any problem. No alias, no widen subnet mask, but its true also, are pure private links, not vpn.
    The world is divided into 10 kinds of people, who know binary and those not

  10. #20
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,973

    Default

    Remote segments are a different story. Those use static routes because there is another router responsible for them. The widened mask is for when you have those IP spaces transiting a single segment where Untangle resides.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    NexgenAppliances.com
    Phone: 866-794-8879

Page 2 of 2 FirstFirst 12

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2