Repository navigation
Cannot specify "-o" in AP mode #100
Description
Activity
Additional info: Policy based routing (/etc/NetworkManager/dispatcher.d/99-policy-routing-in-out-match.sh) is used because there are 2 ISP connections
I haven't look through all you log. I saw in your
setup_ipv6()ip route add default via "$gw6" dev "$IFACE" table "$TABLE_ID"
Did you miss
-6? Please make sure theenp5s0works all around first.On your Linux
ping -I enp5s0 <try-some-ips>
does it work?
I don't have IPv6 on
enp5s0andsetup_ipv6()doesn't add route/rule.ping is working.
PING bing.com (150.171.28.10) from 10.1.*.* enp5s0: 56(84) bytes of data. 64 bytes from 150.171.28.10: icmp_seq=1 ttl=113 time=77.2 ms 64 bytes from 150.171.28.10: icmp_seq=2 ttl=113 time=76.3 ms 64 bytes from 150.171.28.10: icmp_seq=3 ttl=113 time=74.2 ms 64 bytes from 150.171.28.10: icmp_seq=4 ttl=113 time=77.0 ms 64 bytes from 150.171.28.10: icmp_seq=5 ttl=113 time=74.2 ms 64 bytes from 150.171.28.10: icmp_seq=6 ttl=113 time=77.1 ms 64 bytes from 150.171.28.10: icmp_seq=7 ttl=113 time=74.2 ms 64 bytes from 150.171.28.10: icmp_seq=8 ttl=113 time=77.0 ms 64 bytes from 150.171.28.10: icmp_seq=9 ttl=113 time=74.2 ms 64 bytes from 150.171.28.10: icmp_seq=10 ttl=113 time=77.1 ms ...-
Try
lnxrouter --virt-name <name>. Use a short name likemyap0. -
Run your lnxrouter command as you did. Use viddy to watch iptables hit counter.
Open several terminals and run:
sudo viddy -d -n 0.3 iptables -L -v -n sudo viddy -d -n 0.3 iptables -L -v -n -t nat sudo viddy -d -n 0.3 iptables -L -v -n -t mangle
to see if we can find out which rule is in the way.
From your log, your system is using iptables-nft. So maybe there's something in
nft list rulesetin the way too.Seeing nft counter is troublesome a little. Although there're some command we can use
nft monitor trace xtables-monitor --trace
but they requires explictly added trace/counter rule.
-
Try replacing iptables-nft with legacy iptables.
For example in my system ,
iptablescommand is/usr/sbin/iptables (symlink ) -> /etc/alternatives/iptables -> /usr/sbin/xtables-legacy-multiIn your system it must be being linked to
xtables-nft-multi. Replace it withxtables-legacy-multi(and reboot)
-
I asked AI. An
ip rulemust be added manually:ip rule add from "$HOTSPOT_GATEWAY"/24 table $TABLE_ID priority $((PRIO_V4 + 1))And specify host subnet.
sudo lnxrouter -o enp5s0 --ap wlx************ wujinjun -p 12345678 -g "$HOTSPOT_GATEWAY", then clients can connect to Internet throughenp5s0.Also
-6can work without addingip -6 rule ....The script did not account for a scenario where, when multiple interfaces have internet , the
-ointerface is not used in the main routing table.We should add a note in the readme to remind users that in such cases, they will additionally need to add their routing rules
I also considered enhancing our script, to let the script to handle this . But, this would involve selecting routing table IDs and priority numbers (unlike iptables rules, which do not require such numbering). Therefore, I think it's better to leave this to user, so they decide the number.
If
-ois used to specify Internet interface, ping is alwaysDestination Port Unreachable.Command log: