Networking-Blog

My WordPress Blog

Linux Ubuntu Add Sub-Interface

Ubuntu Sub-interfaces

I have found myself searching the internet for the correct configuration for
Linux subinterfaces.
A subinterface is a division of one physical interface into multiple logical interfaces.

So why would we do that?
!
I use subinterfaces for hosting multiple SSL sites, DSR returns for localhost for my
load balancers, and anything else you would need multiple ips on the same physical interface.

In Ubuntu it is easy to add subinterfaces I have never had to add a temporary subinterface
in Ubuntu but I guess I figure it is easier to just add it to the system and restart networking
.

Here is how to add a Ubuntu subinterface with ifconfig.

Adding a Ubuntu subinterface without restarting networking.

1. Add the interface and ip with one step

$ sudo ifconfig eth0:0 192.168.1.253 netmask 255.255.255.0

2. Turn the ip address up

$ sudo ifconfig eth0:0 up

3.  Check and make sure it is in ifconfig

$ ifconfig -a

eth0      Link encap:Ethernet  HWaddr 00:30:48:28:65:2b
inet addr:192.168.1.5  Bcast:192.168.1.255  Mask:255.255.255.0
inet6 addr: fe80::230:48ff:fe28:652b/64 Scope:Link
UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
RX packets:101278725 errors:10 dropped:0 overruns:0 frame:10
TX packets:96594294 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3734515707 (3.7 GB)  TX bytes:1773845088 (1.7 GB)

eth0:0    Link encap:Ethernet  HWaddr 00:30:48:28:65:2b
inet addr:192.168.1.253  Bcast:192.168.1.255  Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1

4. Remember the subinterface is gone unless you add it to /etc/network/interfaces.


Adding a Ubuntu subinterface permanently.

Now that you have added the subinterface without restarting networking,
or
rebooting, we need to add the ip address to the configuration file on Ubuntu so the
new ip address will be on the system when you do some upgrades and need to reboot.

1.  Open the /etc/network/interfaces file with your favorite editor

$ sudo vi /etc/network/interfaces

2. Add the following lines below your physical interface to create the subinterface on reboot.

auto eth0:0
iface eth0:0 inet static
address 192.168.1.253
netmask 255.255.255.0

3. You can always add more Ubuntu subinterfaces by changing
eth0:0 to eth0:1 and eth0:2 and so on
.

Here is  and example of my complete /etc/network/interfaces file with Ubuntu subinterfaces.

# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

# The loopback network interface
auto lo
iface lo inet loopback

# The primary network interface
auto eth0
iface eth0 inet static
address 192.168.1.5
netmask 255.255.255.0
network 192.168.1.0
broadcast 192.168.1.255
gateway 192.168.1.1

auto eth0:0
iface eth0:0 inet static
address 66.37.141.237
netmask 255.255.255.0

Linux Transit VM Port Forward

Need forwarding to Telford Internal IP Address – 10.10.1.1
Fixed Internet IP Address – 1.1.1.1

Ports 40000, 41000, 42000, 43000, 44000, 45000, & 46000 need forwarding to 10.10.1.1

Configuration to be Done.

Need to create a Ethernet Subinterface on the VM :

# Advanced Micro Devices [AMD] 79c970 [PCnet32 LANCE]
DEVICE=eth1:3
BOOTPROTO=static
ONBOOT=yes
HWADDR=00:0c:29:fa:da:13
IPADDR=1.1.1.1
NETMASK=255.255.255.0
NETWORK=1.1.1.254
BROADCAST=1.1.1.253
Bring Interface UP :

sudo ifup eth1:3

To View a list of rules with the NAT table :

sudo iptables -vnL -t nat –line-numbers

Need to complete PREROUTING chain in order to DNAT these ports from WAN to destination LAN address :

sudo iptables -t nat -I PREROUTING 1 -d 1.1.1.1 -p tcp –dport 40000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 2 -d 1.1.1.1 -p tcp –dport 41000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 3 -d 1.1.1.1 -p tcp –dport 42000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 4 -d 1.1.1.1 -p tcp –dport 43000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 5 -d 1.1.1.1 -p tcp –dport 44000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 6 -d 1.1.1.1 -p tcp –dport 45000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 7 -d 1.1.1.1 -p tcp –dport 46000 -j DNAT –to 10.10.1.1

To summarize this as one rule :

sudo iptables -t nat -I PREROUTING 18 -d 85.234.86.115 -p tcp -m multiport –dport 40000,41000,42000,43000,44000,45000,46000 -j DNAT –to 10.10.1.1

Need to complete POSTROUTING chain in order to SNAT these ports from LAN address to destination Subinterface : :

sudo iptables -t nat -I POSTROUTING 20 -o eth1:3 -s 10.10.1.1 -p tcp -m multiport –dports 40000,41000,42000,43000,44000,45000,46000 -j SNAT –to 1.1.1.1

To Delete a Chain Rule

sudo iptables -t nat -D POSTROUTING 20
sudo iptables -t nat -D PREROUTING 20

Troubleshooting Diagnostics Testing :

From the Internet :

telnet 85.234.86.115 40000

B00m.