/srv/irclogs.ubuntu.com/2010/11/27/#ubuntu-cloud.txt

flaccidsmoser: gearing up for debian launch :)03:07
Ashtray777I need to create a Customer Gateway, but I don't have a router, I only have a cable modem.  Any ideas?07:19
Ashtray777Not that I would know how to create a Customer Gateway even if I had a router.07:19
kiallAshtray777, a "Customer Gateway"  .. what exactly is that meant to be? :) Kinda sounds like "I need to create a Web 2.0 site, but I only have Web 1.0" .. lol ;)07:23
Ashtray777well umm I created a VPC, and created the subnets07:23
kiallaha .. that makes more sense now ;)07:24
Ashtray777now I need to create a customer gateway by specifying "BGP ASN" and an IP address07:24
Ashtray777and I'm totally not sure if this is possible without some type of virutalization or router simulation07:24
kiallYou need something on the "office" side that can speak BGP .. typically, a proper router (aka not a cable modem) .. but you could stick pFsense or similar between your LAN, and your cable modem .. it can do BGP for you ...07:25
kiallNot sure if VPC requires a *valid* AS Number tho ..07:26
Ashtray777ok ok.  If did have a standard home router (which I dont right now) would that be even better?07:26
Ashtray777would that speak BGP07:27
kiallNo .. No home routers dont do BGP :)07:27
kiallwait07:27
kiallNo .. No home routers do BGP :)07:27
Ashtray777oh ok :)07:27
Ashtray777I'm looking at this pfense thing07:28
kiallyou would need a "proper" router (think Cisco ...) or something like pFsense which can do both the VPN and BGP needed for VPC07:28
Ashtray777So you think I can just go ahead and install this pFsense program on my machine and it will git er done?07:29
kiallwell .. not "on your machine" .. usually on some old PC since it takes over the whole PC to act as a network firewall/router ;) .. There are likely things you can just install on your PC .. but I've never looks for any07:31
Ashtray777oh crap.  lol.  I'm reading it now that its a whole OS.  LOL07:31
flaccidAshtray777: you can't be on the internet without a router. you have a router.07:31
Ashtray777I just have a cable modem.  That's not functionally considered the same thing as a router is it? It cant be.07:32
flaccidtrue, it could be bridged directly to 1 client only. either way, you need supported hardware to run a VPC, which you don't have.07:33
Ashtray777oh i know.  I can use virtualbox to create a pfSense Installation!07:33
Ashtray777?07:33
kiallflaccid, exactly .. pFsense can be used to do what your looking for (assuming your cable modem can run as a bridge)07:33
kiallAshtray777, kinda .. VPC will route the traffic from your VPC to your public IP .. and pfsense needs to running on that IP..07:34
flaccidkiall: i'm not looking to do anything07:35
kiallI was just agreeing with you .. then adding more ;)07:36
Ashtray777So should work.  Thanks guys.  I'd be lost without you.07:36
flaccidi have doubts that this would work, but good luck07:36
kiallThe simple/cheap answer is grab an old PC (200Mhz P2's will pass a good few Mb/s) and put pFsense on it .. the other way is to replace your router(/modem) with something compatible.. there are more ways .. but i'll pass on trying to explain them in IRC ;)07:36
kiallflaccid, I've used VPC and pfSense .. it does work ..07:36
flaccidthe simple/cheap answer is to just use a routed OpenVPN. costs nothing.07:37
flaccidkiall: doesn't mean it will work with other variables07:37
kiallof course .. but you can say that in any situation ;)07:37
Ashtray777a routed OpenVPN you say.  let me google that07:37
kialleven with openVPN, dont you need something to speak BGP with aws?07:38
flaccidwith openvpn, you wouldn't need anything else07:40
Ashtray777openVPN habla BGP?07:41
Ashtray777it speaks BGP?07:41
flaccidnot sure07:41
flaccidit doesn't need to07:41
kiallflaccid, it doesnt need to with VPC .. or EC2?07:41
kiall(Im asking since it could simplify things for me ;))07:42
Ashtray777It says I need to enter my gateway routers BGP ASN number07:42
flaccida routed openvpn negates the need for BGP.07:42
kiallYea .. I'm 99.999% sure that Amazon VPC requires the use of BGP .. flaccid you sure you can use VPC without BGP?07:43
flaccidi'm not talking about using vpc07:43
kiallah .. he is ;) and I am ;)07:43
Ashtray777yeah yeah my bad for not re-iterating that.07:44
flaccidnd he doesn't have bgp and an asn.07:44
flaccid*and07:44
kiallASN's over 65k-ish are free for all and usable with VPC .. no need for an "official" one07:45
kiallanyway .. if you can get the same thing with simple OpenVPN and EC2 .. why not.. easier to setup / manage unless you have a good reason to specifically use VPC07:45
Ashtray777not a good reason.  Just practice.  I'm learning.07:46
Ashtray777OpenVPN sounds interesting07:46
Ashtray777So you say ASNs over 65k are free for all.... Does that mean I can just randomly put in any # over 65k in the ASN field?  kind of a dumb question, probably 'no'07:47
kiallyea. . anything between .. 64512 and 65534 ish are public .. but you would still need something (either a proper router .. or software like pfsense) on the client side that speaks BGP .. flaccid's method might be easier if your not familiar with the likes of BGP .. :)07:48
flaccidyes, that was my original point.07:48
Ashtray777I need to get familiar with BGP cause I'm going to do CCNA07:49
flaccidin that case Ashtray777  you should get a cisco vpn router such as a PIX07:49
kiallAha .. In that case ... pfsense will do what you need .. but wont be worth a thing for your CCNA since it aint cisco :)07:49
flaccidyerp07:50
flaccidif you wanna learn cisco console get a device with it07:50
kiallyou can get second hand cisco kit v.cheap on ebay .. well worth it if your serious about CCNA and above exams ..07:50
Ashtray777which one of these should i get?  wow this has so much.07:51
Ashtray777I want to do ssl and ipsec too!07:51
Ashtray777http://www.amazon.com/s/?ie=UTF8&keywords=cisco+vpn+router&tag=googhydr-20&index=aps&hvadid=4112376355&ref=pd_sl_94bfgr0fzz_b07:51
* kiall glares at the pile of asa 5510's currently under my desk ;)07:51
kiallwell .. thats all cisco's home and small business range ..07:51
flaccidget what you can afford and make sure it is not linksys07:52
Ashtray777thats what I'm looking for right kiall ?07:52
flaccidit needs to be a real cisco product07:52
kiallwell .. first ebay hit for "cisco CCNA" is http://cgi.ebay.ie/CISCO-CCNA-LAB-270-00-2620XM-2950-WIC-1T-DTE-DCE-/250722197987?pt=UK_Computing_NetworkSwitches_RL&hash=item3a603521e3#ht_3045wt_90707:52
Ashtray777ok07:52
flaccidcisco home = linksys07:52
kiall3x routers and 2x switches for 270 ;) .. so 1x should be cheap enough!07:52
Ashtray777I really only want this for VPN functionality guys because I already have GNS3 router emulator07:53
flaccidthat contradicts your point on learning cisco07:53
flaccidwhich then comes back to my original response07:53
flaccidof using openvpn. if you aint going to have the hardware then whats the point07:53
flaccidor do pfsense as per kiall07:54
Ashtray777Will a $110 router create the VPN I need to do a VPC?07:55
flaccidthe cost of the router has nothing to do with requirements07:55
flaccidwill a $100 car get me to the corner store?07:56
kiallflaccid, exactly ... for example .. here's a £35.25 router that I believe will work .. http://cgi.ebay.ie/CISCO-2611-CCNA-Router-WIC-1T-12-3-IOS-2610-Lab-/290495027881?pt=LH_DefaultDomain_3&hash=item43a2da5aa9#ht_1349wt_90707:56
Ashtray777true, i was just wondering if that's the price I would expect to pay to meet those requirements07:56
flaccidlol still searching with ccna in the product, thats hilaroius07:57
flaccidi just use a pix 50107:57
flacciddone.07:57
kiallflaccid, yea .. people sell "CCNA kits"07:57
flaccidlame07:57
kiallAnyway .. Ashtray777 if your going for the CCNA .. Amazon VPC isnt on the exam .. your better off getting one of those "CCNA Kits" for £250ish and having a proper "lab" to experiment with.. you'll learn a hell of a lot more... oh and .. good luck ;)08:06
Ashtray777I know Amazon VPC isn't on the exam =)  I just like learning different technologies.  Thanks for the help much appreciated.08:07
kiall(or buy whatever pieces of kit you need individually .. makes no difference .. its all just second hand gear)08:07
flaccidor just get a pix firewall and have the best of both worlds cheaper08:07
Ashtray777yeah i'm thinking about a pix08:08
kialltrue .. but a single pix will work with VPC alright, but doesnt cover all the CCNA setup's your going to run into..08:08
Ashtray777I dont plan on spending any money on CCNA "kits" though.08:08
flaccidthis channel is not about getting ccna qualified :)08:08
Ashtray777I'm just going to have to learn in the classroom and with GNS308:08
flaccidlol08:08
kialllol .. that works too .. use the college lab ;)08:08
flaccidwell thats what they are for08:09
flaccidif it is sufficient08:09
Ashtray777u guys gave me lots of options so I'm going to need to re-read this conversation again.  hehe08:09
flaccidomg. you might want to reconsider your profession then heh08:09
flaccidsorry that was a joke08:10
Ashtray777lol no worries08:10
flaccidwhat you guys doing talking about hardware08:10
flaccidcloud made me able to not go to hardware08:11
Ashtray777i know right08:11
flaccidi guess we'll consider vpn routers as donuts in the cloud08:11
Ashtray777There's a BGP routing daemon in the Ubuntu Software Center08:24
kiallquagga probably08:24
Ashtray777yeah.  you know of it?08:25
kiallUse it all the time .. but its only a small part of you need to get hooked up to VPC .. part of it being, you need your public IP to be the VPN termination point, which also needs to be running the BPG daemon (eg quagga).. so installing it on my PC probably wont help with getting it working .. at least - not without some other funky network setup08:26
Ashtray777thanks, I'll take your word for it08:28
Ashtray777no VPC until I get a real router or a box with pfsense08:29
kiallIf you can get your cable modem to pass the public IP directly to your PC (No form of NAT will not work), you can run quagga + racoon/openswan on your PC and get it going .. but most cable modems wont do that08:29
kiall(No form of NAT will work*)08:29
kiallKeeping using double and triple negatives for some reason .. and using them wrong at that.08:29
Ashtray777over my head because this entire time I thought the public IP was simply my PC IP address08:30
kiallyour public IP is what you see when you go to http://checkip.dyndns.org08:30
Ashtray777ok yeah, thats right.08:30
Ashtray777my pc ip address08:31
kiall(aka it doesnt start with 10. / 192.168 / 172.something)08:31
Ashtray777yeah i'm not on a router08:31
Ashtray777my ip starts with 6808:31
kiallaha .. didnt know ISP's still gave out "true modems" that dont do any routing ..08:31
kiallyour in luck then ;)08:32
kiallhttp://openfoo.org/blog/amazon_vpc_with_linux.html08:32
Ashtray777:)08:32
kiallThats a guide for quagga + raccoon .. ;)08:32
Ashtray777sweet!   thanks!!!08:33
kiallNo idea why I didnt think of that earlier .. ah well .. its early!08:33
Ashtray777no matter, thanks so much08:33
Ashtray777I need more coffee08:34
flaccidyes kiall thats called bridging :)09:38
flaccidyour desktop OS is the router09:38
kialllol .. really? .. joking aside .. I've yet to see any CPE here (Ireland) that supports it ..09:39
kiallguess other ISPs dont disable it like ours do ;)09:40
kiallAnd .. I also noticed he kept calling it a "modem" .. Im so used to hearing that word and thinking "screwed up router" ;)09:41
kiallrather than an actual modem with no routing functionality ;)09:41
flaccida modem is a modem09:43
flaccida router is a router09:43
flaccidan example of a commonly used modem is a wireless usb stick09:43
kiallof course .. but when 90% of people say the word "modem" to me .. they really mean "router" ... ;)09:44
flaccidthis plugs into your windows or whatever and your OS becomes the router09:44
flaccidi don't make those kind of assumption and i prefer to educate if they are wrong09:44
flaccidits a good idea to clarify what they are actually using09:44
kialljust like when family/friends ask me to fix their god damn PC's .. "sure .. bring the PC over and I'll look - I just need the PC tho, not the keyb / mouse / screen .." .. they then arrive with the monitor .. just the monitor.09:45
kiallSo yea .. I make assumptions about what people say sometimes ;)09:45
=== timwood_ is now known as timwood
=== nigelb is now known as Guest81825
=== dizz is now known as dizz|away

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!