feat(mesh): retire nh3-dev from the mesh and revert the masquerade it required
nh3-dev sits on the NH3 LAN and reaches every site through its own default gateway; RouteAll was already false, so it never used the tunnel for routing. Membership bought a 100.64.0.4 address nothing referenced -- grep across the repo and ~/development found only docs and memory hits. It also cost something concrete. A host running Tailscale installs -A ts-input -s 100.64.0.0/10 ! -i tailscale0 -j DROP, and because the fleet's subnet routers preserve source rather than masquerading RFC1918, a mesh client's packet reached nh3-dev's ens18 still sourced 100.64.x and was dropped silently. That is why nh3-dev.nh3.internal failed from the mesh while every NH3 host that does not run Tailscale worked, and it needed a -d 10.100.10.50/32 -j MASQUERADE exception on nh3-scale to paper over. Retiring the membership removed the anti-spoof rule, so the exception went with it -- mesh-exit-masq.sh is back to the two rules it had before yesterday. Verified after: nh3-dev reachable at 10.100.10.50 from ESH, Anaheim, FV, Irvine and NH3, and reaching all four sites plus the internet itself. fv-ml1 unaffected. The mesh is now six nodes and every one has a job: three site routers, vb-gateway, irv-ml1 (Irvine's own router, no separate scale node), and the operator's MacBook Air. Nothing is enrolled just in case.
This commit is contained in:
@@ -2,27 +2,6 @@
|
||||
# Masquerade mesh clients' INTERNET-bound (exit-node) traffic only; preserve site-to-site source.
|
||||
iptables -t nat -F MESH-EXIT 2>/dev/null || iptables -t nat -N MESH-EXIT
|
||||
|
||||
# ── Mesh-member hosts on this routed subnet — MUST come before the RFC1918 RETURNs ──
|
||||
# A host that runs Tailscale itself installs an anti-spoof rule:
|
||||
# -A ts-input -s 100.64.0.0/10 ! -i tailscale0 -j DROP
|
||||
# With source preservation, a mesh client's packet reaches that host's ETHERNET
|
||||
# interface still carrying its 100.64.x source, and is dropped there — silently,
|
||||
# before anything can answer. Hosts that do NOT run Tailscale are unaffected,
|
||||
# which is why every other NH3 address worked and only this one did not.
|
||||
# Masquerading just these destinations makes them behave like every other host
|
||||
# while leaving source preservation absolute for the rest of the subnet.
|
||||
# (2026-09-14. Tailscale's own default is --snat-subnet-routes=true, i.e. SNAT
|
||||
# everything; this file is the deliberate departure from that, so the exception
|
||||
# belongs here rather than as a reason to abandon the design.)
|
||||
#
|
||||
# ⚠ Do NOT "fix" this instead by advertising the host's /32 from the host
|
||||
# itself. That was tried on nh3-dev 2026-09-14 and black-holed it from ESH,
|
||||
# Anaheim, FV and Irvine — `ip rule` there puts `lookup 52` at priority 5270,
|
||||
# ahead of main at 32766, and becoming a subnet router let table 52 capture
|
||||
# cross-site traffic the node had no accepted route for. Its own LAN and the
|
||||
# internet kept working, so a narrow check looks clean. Fix it at the router.
|
||||
iptables -t nat -A MESH-EXIT -d 10.100.10.50/32 -j MASQUERADE # nh3-dev
|
||||
|
||||
iptables -t nat -A MESH-EXIT -d 10.0.0.0/8 -j RETURN
|
||||
iptables -t nat -A MESH-EXIT -d 172.16.0.0/12 -j RETURN
|
||||
iptables -t nat -A MESH-EXIT -d 192.168.0.0/16 -j RETURN
|
||||
|
||||
Reference in New Issue
Block a user