RE: FreeBSD deny 'unusual' IP-addresses?

From: Patrik Forsberg (patrik.forsberg_at_dataphone.net)
Date: 01/17/04

  • Next message: Justin Hopper: "Re: Fair Share Scheduling Needed. I want 1/3 of a server"
    Date: Sat, 17 Jan 2004 14:52:41 +0100
    To: <freebsd-isp@freebsd.org>
    
    

    > I work in a small ISP company. We are using FreeBSD machines
    > for routing and
    > counting traffic of our clients. I faced with subject 'feature' twise:
    >
    > 1) FreeBSD Server with a real ip in external interface and a
    > lot of IPs like
    > 10.1.1.1/24, 172.16.13.1/24 (NOT ANY 192.168...!)on internal
    > interface. If
    > someone tries to up an ANY address like 192.168.0.1/24 - our
    > server always
    > talk that this address is already in use. Those clients need these
    > addresses, becouse they use our LAN as transport beetween two
    > offices. I
    > solved this problem by upping 192.168.1.1/16 on internal
    > server interface .

    I dont quite understand this. A machine that dont have the network
    segment you're trying to assign to another machine should never ever
    bother about it. Nether should it complain that it is already in use..
    sense it doesn't know about it at all. It might be some proxy-arp thing,
    that I dont know about, that might couse that kind of behavur .. but
    normally it shouldent bother sense it doesn't know about the network ..
    even less the specified ip-address.

    > 2) One of our client use our LAN for testing their
    > experimental hardware
    > device (i don`t know what that thing do, but in connected to
    > network). For
    > some unknown reason that device use a real IP-address that
    > not belongs to
    > me, but they don't want to change the address(why? - I don't
    > know). Our
    > server swears that this address is already in use.

    This is generally a very bad idea. Two machines connected to the same
    layer-2 segment should never have the same IP. Ether you or they should
    change IP otherwise all kinds of havock can brake lose on the LAN.
    Ofcourse your server will complain that the address is already in use..
    becouse it is. Im amazed if that works at all.
    The only time two equipments could have the same IP is if they are using
    some kind of high-availability mode .. like vrrp or something.. but even
    then the same IP aint connected at the same time to the same layer-2
    segment. This is simply a NO-NO.

    > I understand, that using such thing is not compliant to
    > standarts, but maybe
    > someone knows how to switch off those kind of alarms?

    Wouldent bet there is a way.. without kernel-hacking. It is a very basic
    part of the tcp/ip core to complain about it. Like you and me complain
    if a person steps into our foot-steps before we have stept out of them.

    I wouldent call it a feature if you could disable it.. more like a bug
    ;)

    Well.. I could be wrong, ofcourse.

    Regards,
    Patrik

    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: Justin Hopper: "Re: Fair Share Scheduling Needed. I want 1/3 of a server"

    Relevant Pages

    • Re: Domain Controller Stops Processing All Login Requests Randomly
      ... > control the clients and shutdown a bunch of machines at once or turn them ... >>> machines simultaneously that are Deep Freeze clients. ... the server exhibited the same behaviour. ...
      (microsoft.public.windows.server.dns)
    • Re: XP clients do not appear in Collections
      ... You may have to enable logging on your server through the Tools - Service ... XP machines were not discovered until I created a collection ... .ddr file on clients. ... >> What discovery method did you enable? ...
      (microsoft.public.sms.admin)
    • Re: Mail sync - Evolution and Outlook
      ... > Sync Outlook with IMAP server before travelling. ... > seen / tried before to keep two machines in sync. ... automatic routines in modern mail clients. ...
      (alt.os.linux.suse)
    • Re: Help need desperately!
      ... > Have you given your SMS Server's machine account FULL CONTROL of the Systems ... > machines are already discovered or you wouldn't be able to push to them. ... > Check through the SMS Server logs, ... All clients are discovered, assigned and have successfully installed the ...
      (microsoft.public.sms.inventory)
    • Re: Inconsistant DNS resolution problems on 2003 RRAS server
      ... some clients are resolving DNS names differently that others. ... then "this server" is ambiguous. ... machines but you need to clearly differentiated each pronound, ...
      (microsoft.public.win2000.ras_routing)