From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from relay.sandelman.ca (relay.cooperix.net [67.23.6.41]) by huchra.bufferbloat.net (Postfix) with ESMTP id 118B62020B8 for ; Thu, 21 Jun 2012 13:43:02 -0700 (PDT) Received: from sandelman.ca (unknown [132.213.238.4]) by relay.sandelman.ca (Postfix) with ESMTPS id A0C3684D8 for ; Thu, 21 Jun 2012 16:40:17 -0400 (EDT) Received: by sandelman.ca (Postfix, from userid 179) id 7054E98C2F; Thu, 21 Jun 2012 16:43:00 -0400 (EDT) Received: from marajade.sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 6D81E98C2E for ; Thu, 21 Jun 2012 16:43:00 -0400 (EDT) From: Michael Richardson To: cerowrt-devel@lists.bufferbloat.net In-Reply-To: References: X-Mailer: MH-E 8.3; nmh 1.3-dev; XEmacs 21.4 (patch 22) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha1; protocol="application/pgp-signature" Date: Thu, 21 Jun 2012 16:43:00 -0400 Message-ID: <13687.1340311380@marajade.sandelman.ca> Sender: mcr@sandelman.ca Subject: [Cerowrt-devel] slowly moving to deploy 3.3.8-6 X-BeenThere: cerowrt-devel@lists.bufferbloat.net X-Mailman-Version: 2.1.13 Precedence: list List-Id: Development issues regarding the cerowrt test router project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 21 Jun 2012 20:43:03 -0000 --=-=-= Content-Transfer-Encoding: quoted-printable After our brief G+ Hangout, I hooked a 100Mb/s switch between my 3800 running CeroWRT and my 24-port Cisco 203 "SOHO" switch. Then I got layer-2 LINK, and low and behold things worked. My network currently looks like this in ASCII art: | R-X / \ | \ | \ trusted service | | wife me + |-wrt54gl<~~wireless~~>--+---+- | | wii .. + +-mail | +-www (X- dead, no longer used) (R- NetBSD 5.0 machine, PII-400. upgraded to fanless low power PIII-600, which died, so back to PII-400) wrt54gl is running kamizake, is in living room. | R- / \ (1| \2) | \ trusted service | | wife me + |-wrt54gl<~~wireless~~>--+---+- | | wii + +-mail |-38--| +-www The Netgear 3800 is inserted between trusted and service right now. So it's upstream is my trusted network, and downstream is my service network, and current wireless. From=20some emails and IRC, I understood that I would not be able to split the LAN ports on the 3800 into seperate LANs. Maybe not true. I am currently using VLAN tagging, which works. So, my switch has VLAN 470 as service already, and this is seen by the 3800 as network "service" (device se00.470), and I can get v4 and v6 traffic to it. The ge00 port of the 3800 is plugged into my trusted VLAN (which is VLAN 1). I can now ssh into the "WAN" side of the CeroWRT. I set up the cisco switch so that the untagged packets on the se00 interface were placed into vlan 3800, which I exposed to my desktop as tagged vlan 3800, so my desktop could be behind as well as on the internet. (Oh, I have public IPv4s everywhere, btw. /25 at home) My plan is to sever the link (2) above, and remove the interface on R for "service" and move that IP to the 3800. Once I'm happy with that, I'll promote the 3800 to replace R. My upstream is bridged DSL ("HSA"), so it looks like ethernet and has a native IPv4 (/30) and native IPv6 (/64) on it. No DHCPv6PD on that link, alas. Depending upon the wireless strengh I see from the 3800 I may obsolete the wrt54gl, or not. (It's v4 and v6 *routed*, not bridged). This email isn't so much a query, as a point of documentation, and=20 partial success story. (Oh, wife's laptop often has flaky wifi, wrt54gl is bg only. I am blaming Ubuntu oneiric kernel, since it worked great on Hardy. She spends most days on wired on "trusted" network. Wife laptop is son's youtube toy. I will definitely see if I can move the laptop to 802.11a, where the 3800 will get a chance to AQM/codel it) =2D-=20 ] He who is tired of Weird Al is tired of life! | firewall= s [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON |net archit= ect[ ] mcr@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device dri= ver[ Kyoto Plus: watch the video then sign the petition.=20 --=-=-= Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQCVAwUAT+OHVIqHRg3pndX9AQKGRwQA8MTqKow2ntjFSFtiF6cvVlh9+6FpEXj5 xmTH8eLlUd/dx7VJdCfeNks+er6ElwmaYNoKHl0YeHhQqYoxIknHyubqWKh6m/7V DN4bYqzJpiNd+VYs0cAuoDZhj9vDq9osoD+kMAwkumVDtLiqSeo8crb9Gzove9JA Opxv58Yvp3g= =pCOw -----END PGP SIGNATURE----- --=-=-=--