ZeroTier + Active Directory Authentication
-
@Dashrender You have a "how to" instruction set?
-
Would you say that the biggest difference between ZT and Pertino in terms of logistics is that Pertino routes traffic across its network, whereas ZT just performs the initial connection and the "clients" then communicate with each other until a loss of connectivity occurs?
Pertino does have smartzones that allows you to tell it when it should just route traffic locally/across the non pertino interface but I don't think it would be encrypted.
-
@FATeknollogee
I don't, but I think @BRRABill was working on it.https://www.zerotier.com/community/topic/5/bridging-ethernet-to-zerotier-virtual-networks-on-linux
This thread talks about it.
The gist is that you make a router out of a device that you can install ZT onto.
-
@FATeknollogee said:
@Dashrender You have a "how to" instruction set?
I think @dafyre created a script for it. I am pretty sure you can only install the bridge on a connector, which has to be a Linux box.
-
I just had a thought.
This is just a wacky solution to the multi IP's for a single host problem that @dafyre was able to solve by telling a NIC to not register with DNS, but I couldn't get to work.
What if you install a bridge on the network, and make your default gateway aware of that network? then if your PC gets a ZT IP from DNS, it can still communicate, only it will be through the bridge.
It's ugly.. but provides a path.
-
@wrx7m said:
@FATeknollogee said:
@Dashrender You have a "how to" instruction set?
I think @dafyre created a script for it. I am pretty sure you can only install the bridge on a connector, which has to be a Linux box.
Doh! you're right it was @dafyre
-
@Dashrender said:
I just had a thought.
This is just a wacky solution to the multi IP's for a single host problem that @dafyre was able to solve by telling a NIC to not register with DNS, but I couldn't get to work.
What if you install a bridge on the network, and make your default gateway aware of that network? then if your PC gets a ZT IP from DNS, it can still communicate, only it will be through the bridge.
It's ugly.. but provides a path.
Why does the gateway need to be aware of it?
-
@scottalanmiller He might mean that the ZT clients would need to know which gateway to use if it is a different gateway on the same network.
-
@scottalanmiller said:
@Dashrender said:
I just had a thought.
This is just a wacky solution to the multi IP's for a single host problem that @dafyre was able to solve by telling a NIC to not register with DNS, but I couldn't get to work.
What if you install a bridge on the network, and make your default gateway aware of that network? then if your PC gets a ZT IP from DNS, it can still communicate, only it will be through the bridge.
It's ugly.. but provides a path.
Why does the gateway need to be aware of it?
Well.. hmm.. OK I was going to say because that way it knows where to forward the packets to internal bridge/router...
But I just read the ZT forum post about the bridge, it's a bridge, not a router between two networks.. it's assumed (bridge) that all devices are on the same network, so there won't be any involvement of the default gateway.. so you can disregard my earlier comments.
-
@Dashrender said:
@scottalanmiller said:
@Dashrender said:
I just had a thought.
This is just a wacky solution to the multi IP's for a single host problem that @dafyre was able to solve by telling a NIC to not register with DNS, but I couldn't get to work.
What if you install a bridge on the network, and make your default gateway aware of that network? then if your PC gets a ZT IP from DNS, it can still communicate, only it will be through the bridge.
It's ugly.. but provides a path.
Why does the gateway need to be aware of it?
Well.. hmm.. OK I was going to say because that way it knows where to forward the packets to internal bridge/router...
But I just read the ZT forum post about the bridge, it's a bridge, not a router between two networks.. it's assumed (bridge) that all devices are on the same network, so there won't be any involvement of the default gateway.. so you can disregard my earlier comments.
That's what I was wondering about A bridge is just like another switch port.
-
@scottalanmiller said:
@Dashrender said:
@scottalanmiller said:
@Dashrender said:
I just had a thought.
This is just a wacky solution to the multi IP's for a single host problem that @dafyre was able to solve by telling a NIC to not register with DNS, but I couldn't get to work.
What if you install a bridge on the network, and make your default gateway aware of that network? then if your PC gets a ZT IP from DNS, it can still communicate, only it will be through the bridge.
It's ugly.. but provides a path.
Why does the gateway need to be aware of it?
Well.. hmm.. OK I was going to say because that way it knows where to forward the packets to internal bridge/router...
But I just read the ZT forum post about the bridge, it's a bridge, not a router between two networks.. it's assumed (bridge) that all devices are on the same network, so there won't be any involvement of the default gateway.. so you can disregard my earlier comments.
That's what I was wondering about A bridge is just like another switch port.
And now I understand why in that ZT post that they wanted an open unused nic port to act like a switch port.. that's what ZT grabs onto to form the bridge...lol weird.
-
I'm thankful that my installation would be simple and only require editing the hosts file to point at the right DNS server.
-
@scottalanmiller you can not so respectfully piss off.
I can tell you that your opinion of how ZT should work is your opinion and nothing more than that. The developer told you to post your information to that thread.
My goal has nothing to do with making everything work for AD. That thread has nothing to do with my desire to make AD be the only piece that works.
-
@Dashrender said:
@wrx7m said:
@FATeknollogee said:
@Dashrender You have a "how to" instruction set?
I think @dafyre created a script for it. I am pretty sure you can only install the bridge on a connector, which has to be a Linux box.
Doh! you're right it was @dafyre
It wasn't a script... Esentially what I did was build a Linux router.
I have been unable to get the Official Bridged mode to work for some reason or another... It sounds like that is more involved than what @JaredBusch wants to do though.
-
@dafyre said:
@Dashrender said:
@wrx7m said:
@FATeknollogee said:
@Dashrender You have a "how to" instruction set?
I think @dafyre created a script for it. I am pretty sure you can only install the bridge on a connector, which has to be a Linux box.
Doh! you're right it was @dafyre
It wasn't a script... Esentially what I did was build a Linux router.
I have been unable to get the Official Bridged mode to work for some reason or another... It sounds like that is more involved than what @JaredBusch wants to do though.
I'd agree - bridge mode is like a huge pain. Putting all devices into a /16 network? WOW - no thanks. Of course I realize you could just as easily do with with a /23 or /22.
I'm curious though.. what happens when two NICs have IPs in the same range? This would be the case when a laptop is in the office.
-
@Dashrender said:
I'm curious though.. what happens when two NICs have IPs in the same range? This would be the case when a laptop is in the office.
Why would that happen with laptops?
-
@scottalanmiller said:
@Dashrender said:
I'm curious though.. what happens when two NICs have IPs in the same range? This would be the case when a laptop is in the office.
Why would that happen with laptops?
He means if they use the same IP range for both the LAN and the ZT network... what would happen if a laptop got 192.168.16.16 on the LAN, as well as 192.168.16.16 on the ZT network.
-
@dafyre said:
@scottalanmiller said:
@Dashrender said:
I'm curious though.. what happens when two NICs have IPs in the same range? This would be the case when a laptop is in the office.
Why would that happen with laptops?
He means if they use the same IP range for both the LAN and the ZT network... what would happen if a laptop got 192.168.16.16 on the LAN, as well as 192.168.16.16 on the ZT network.
Oh, you can't do that. The devices would freak out. It's as simple as... you can't.
But... when would this happen? Why would you choose a ZT network that overlaps with the LAN?
-
Oh, you can't do that. The devices would freak out. It's as simple as... you can't.
But... when would this happen? Why would you choose a ZT network that overlaps with the LAN?Couldn't you create two separate reservations--one for the LAN and one for ZT?
-
@scottalanmiller said:
@dafyre said:
@scottalanmiller said:
@Dashrender said:
I'm curious though.. what happens when two NICs have IPs in the same range? This would be the case when a laptop is in the office.
Why would that happen with laptops?
He means if they use the same IP range for both the LAN and the ZT network... what would happen if a laptop got 192.168.16.16 on the LAN, as well as 192.168.16.16 on the ZT network.
Oh, you can't do that. The devices would freak out. It's as simple as... you can't.
But... when would this happen? Why would you choose a ZT network that overlaps with the LAN?
I think that may have been something that someone read a little too much into what @adam-ierymenko was saying about bridging (either in this thread, or another).