Routing problem on VMs LAB 11.2

Hello,
I've done this lab exercise using my laptop and raspberry pi, and everything worked fine. However, when I try to do it on VMs, it just doesn't work.
Here's my setting:
First VM IPs
inet 192.168.122.223/24 brd 192.168.122.255 scope global dynamic ens3 inet 192.168.1.100/24 scope global ens3
First VM routing table
default via 192.168.122.1 dev ens3 proto dhcp src 192.168.122.223 metric 100 172.16.1.0/24 via 192.168.122.98 dev ens3 192.168.1.0/24 dev ens3 proto kernel scope link src 192.168.1.100 192.168.122.0/24 dev ens3 proto kernel scope link src 192.168.122.223 192.168.122.1 dev ens3 proto dhcp scope link src 192.168.122.223 metric 100
Second VM IPs
inet 192.168.122.98/24 brd 192.168.122.255 scope global dynamic ens3 inet 172.16.1.100/24 scope global ens3
Second VM routing table
default via 192.168.122.1 dev ens3 proto dhcp src 192.168.122.98 metric 100 172.16.1.0/24 dev ens3 proto kernel scope link src 172.16.1.100 192.168.1.0/24 via 192.168.122.223 dev ens3 192.168.122.0/24 dev ens3 proto kernel scope link src 192.168.122.98 192.168.122.1 dev ens3 proto dhcp scope link src 192.168.122.98 metric 100
What am I doing wrong ?
Thanks in advance for your help
Comments
-
Hi in your first VM GW = 192.168.122.98 ?
second VM GW = 192.168.122.223 ? --- two VM use 2 GW different addresses ?0 -
Hello codmd,
In order to reach 192.168.1.100 on VM1 the traffic from VM2 has to be routed through 192.168.122.223
192.168.122.98 -> 192.168.122.223 -> 192.168.1.100
And to reach 176.16.1.100 from VM1
192.168.122.223 -> 192.168.122.98 -> 176.16.1.100
0 -
Thank you for your input.
There is a note at the top of the lab indicating that more than one machine is best for routing exercises,however, the lab should function. Ii will reproduce this lab and post the solution.
Which VM hypervisor are you using?
Lee
0 -
Please verify that ip_forwarding is enabled on all the machines.
sysctl net.ipv4.ip_forward
0 -
Hello Lee,
Thanks in advance for your help!
I am using KVM.
I confirm that ip_forwarding is enabled on both machines.
0 -
The base machine also had ip_forwarding on?
Your configuration looks ok. Something else is causing issues, perhaps a firewall on the main machine?0 -
Sorry, by the base machine you mean my host which is running KVM hypervisor ? If that is the case, ip_forwarding is on
Also, the firewalld and ufw services on my host are stopped. If firewall services are stopped, iptables has no effect, right ?
Just in case, here's the relevant part of my FORWARD chain on the host machine
0 0 ACCEPT all -- virbr1 virbr1 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * virbr1 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
0 0 REJECT all -- virbr1 * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
134K 174M ACCEPT all -- * virbr0 0.0.0.0/0 192.168.122.0/24 ctstate RELATED,ESTABLISHED
30737 2066K ACCEPT all -- virbr0 * 192.168.122.0/24 0.0.0.0/0
24 7449 ACCEPT all -- virbr0 virbr0 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * virbr0 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
0 0 REJECT all -- virbr0 * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
Really appreciate your help !
0 -
It depends if you are using iptables or nft with systemd.
Please shutdown the firewall and verify there is no rules. The flush option should clean out the rules.0 -
On the three machines, Hypervisor,first and second, which of them have the libvirtd service running?
0 -
Hello Lee,
Sorry for the delay.
I cannot flush iptables because I have a lot of other routing options and filters set on my laptop so it seems potentially dangerous (?) That is why I asked if it suffice to shutdown ufw.service
libvirtd is running on hypervisor machine
0 -
Ok, I see. How about creating a new “private” network we can experiment on? The idea is only the vms can use this network, and assign ipaddresses manually through the hyper visor management. I do this a lot just to isolate the traffic so wireshark is less busy. Stay away from the default nat network (192.168.122.0/24 and only use it for outside access.
0 -
Hello Lee,
I've added a new private network 10.11.12.0/24 so now I have another adapter (ens9) on each VM with address 10.11.12.77 on VM1 and 10.11.12.99 on VM2.
After adding routes through new interfaces, the machines can ping each other and everything works as expected.
I'm really puzzled... Is there a way to find out why it wasn't working in the first place (or an explication at least) ?
Thanks a lot for your help !
k0dard
0 -
The software bridges control the paths the packets take, the default is set so packets are not returned on the same path that they arrived on. This is an option called "hairpin" and the default is off. Rather than messing about with the primary bridge, using another bridge with the option already on is easier.
Regards Lee1 -
Cool, thanks for the explanation !
0
Categories
- All Categories
- 51 LFX Mentorship
- 104 LFX Mentorship: Linux Kernel
- 576 Linux Foundation IT Professional Programs
- 304 Cloud Engineer IT Professional Program
- 125 Advanced Cloud Engineer IT Professional Program
- 53 DevOps Engineer IT Professional Program
- 61 Cloud Native Developer IT Professional Program
- 5 Express Training Courses
- 5 Express Courses - Discussion Forum
- 2.1K Training Courses
- 19 LFC110 Class Forum
- 7 LFC131 Class Forum
- 27 LFD102 Class Forum
- 158 LFD103 Class Forum
- 21 LFD121 Class Forum
- 1 LFD137 Class Forum
- 61 LFD201 Class Forum
- 1 LFD210 Class Forum
- LFD210-CN Class Forum
- 1 LFD213 Class Forum - Discontinued
- 128 LFD232 Class Forum
- LFD237 Class Forum
- 23 LFD254 Class Forum
- 613 LFD259 Class Forum
- 105 LFD272 Class Forum
- 1 LFD272-JP クラス フォーラム
- 1 LFD273 Class Forum
- 2 LFS145 Class Forum
- 25 LFS200 Class Forum
- 739 LFS201 Class Forum
- 1 LFS201-JP クラス フォーラム
- 11 LFS203 Class Forum
- 77 LFS207 Class Forum
- 300 LFS211 Class Forum
- 54 LFS216 Class Forum
- 47 LFS241 Class Forum
- 41 LFS242 Class Forum
- 37 LFS243 Class Forum
- 11 LFS244 Class Forum
- 37 LFS250 Class Forum
- 1 LFS250-JP クラス フォーラム
- LFS251 Class Forum
- 141 LFS253 Class Forum
- LFS254 Class Forum
- 1.1K LFS258 Class Forum
- 10 LFS258-JP クラス フォーラム
- 93 LFS260 Class Forum
- 132 LFS261 Class Forum
- 33 LFS262 Class Forum
- 80 LFS263 Class Forum
- 15 LFS264 Class Forum
- 11 LFS266 Class Forum
- 18 LFS267 Class Forum
- 18 LFS268 Class Forum
- 23 LFS269 Class Forum
- 203 LFS272 Class Forum
- 1 LFS272-JP クラス フォーラム
- LFS274 Class Forum
- LFS281 Class Forum
- 236 LFW211 Class Forum
- 172 LFW212 Class Forum
- 7 SKF100 Class Forum
- SKF200 Class Forum
- 903 Hardware
- 219 Drivers
- 74 I/O Devices
- 44 Monitors
- 116 Multimedia
- 209 Networking
- 101 Printers & Scanners
- 85 Storage
- 763 Linux Distributions
- 88 Debian
- 66 Fedora
- 15 Linux Mint
- 13 Mageia
- 24 openSUSE
- 142 Red Hat Enterprise
- 33 Slackware
- 13 SUSE Enterprise
- 357 Ubuntu
- 479 Linux System Administration
- 41 Cloud Computing
- 70 Command Line/Scripting
- Github systems admin projects
- 95 Linux Security
- 78 Network Management
- 108 System Management
- 49 Web Management
- 68 Mobile Computing
- 23 Android
- 30 Development
- 1.2K New to Linux
- 1.1K Getting Started with Linux
- 538 Off Topic
- 131 Introductions
- 217 Small Talk
- 22 Study Material
- 826 Programming and Development
- 278 Kernel Development
- 514 Software Development
- 928 Software
- 260 Applications
- 184 Command Line
- 3 Compiling/Installing
- 76 Games
- 316 Installation
- 61 All In Program
- 61 All In Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)