You are here

44Net / Tunnel Ingestion / Routing Issue?

1 post / 0 new
KM6TFY
44Net / Tunnel Ingestion / Routing Issue?
Long time Listener, First time Caller.  Hello Everyone

So I will try to be as descriptive as I can without giving out too much PI.   

I am setting up a new mesh island here is california sjv and have already flashed a Mikro AC3 which works awesome, have services already posted and running on a micro PC.  Mesh works no problem.

The real issue I am having is getting internal sever/client tunnels to connect.   The SETUP

I have a 44Net account and a tunnel setup linked to a subnet 44.x.x.96/30 exactly 2 useable ips.    I use a stock gl.inet AR300 shadow to connect to 44Net VPN as a client.  I have a tunnel working and traffic in and out of 44Net.    As far as the linked /30 the glinet is assigned 44.x.x.96 and AC3 is 44.x.x.97 static set by the GLinet, consuming my 2 ips.  I know this all works because if I expose lan to VPN i can access both devices, this was just done for testing, it has been disabled.    I have a feeling I have an issue with asym routing.    

-> Internet Traffic -> 44net Tunnel -> 44.x.x.96 my glinet gateway/edge router ->  aredn node static ip .97 -> wg to lan PortFor 5525 -> AREDN Node .97  // this routing feels good to me. the other end the return path

AREDN node .97  ->  WAN   ->   GLint .96 ->  this traffic should leave via the tunnel back to 44Net here.   I have a feeling its not and breaking here.  causing a asym routing issue and packet / connections to just drop.    It may be leaving my home IP not the VPN tunnel.    I havent confirmed this yet but feels right.

I know this may be a little unconventional setup but it was done to bypass CGNAT in my home service.   So all aredn traffic is contained inside another tunnel to 44net.   MTU on primary tunnel is 1380 and from what i read MTU on Aredn tun is 1280 so i think there is enough over head for this config without packet fragmentation issues.   I have pointed my clients at .96 and .97 with nothing working.    I should be pointing clients at the .96 and let the gli route traffic and make sure it has a stateful return path.

 I have forced glinet to global route traffic out vpn, which to me indicates it should be leaving that interface.  If I do a who am I from my node connection it correctly show 44.x.x.97 as my public ip.  So I have tried a lot of settings in the gl.inet and nothing seems to fix my broken route path.    With out a symmetrical path I don't believe any connections will be accepted.   

Does any one have suggestions for me or a working setup like this?  Thanks in advance for any help and excited to be a part of the group.

DANG IT!!  as I was rereading this and checking I may have found the issue.   .96 and .99 are reserved ips network and broadcast ip.   I will try setting my edge ip as glinet .97 and aredn .98 have a feeling this may do the trick.  I may have posted right on top of my network ip.   Still posting this in case it does not.

-Daniel 

Theme by Danetsoft and Danang Probo Sayekti inspired by Maksimer