<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#ffffff" text="#000000">
    Alan,<br>
    <br>
    thank you, this all makes perfect sense. The only outstanding
    problem is that it it unlikely that with this setup computers in LAN
    A will be able to receive broadcasts from computers in LAN B and
    vice-versa.<br>
    <br>
    Cheers,<br>
    Andrew.<br>
    <br>
    On 7/10/2010 11:52 a.m., Alan S. Lawee wrote:
    <blockquote cite="mid:BLU0-SMTP764DD0212BEB1314C76A9AFA6E0@phx.gbl"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 12 (filtered
        medium)">
      <style>
<!--
 /* Font Definitions */
 @font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:"Arial Black";
        panose-1:2 11 10 4 2 1 2 2 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";
        color:black;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;
        color:black;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
-->
</style><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext="edit">
  <o:idmap v:ext="edit" data="1" />
 </o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">In order for you to configure this, you have to
            set up explicit
            routes, and the computers in each location that are hosting
            the tinc
            application must be able to route packets.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">A little more explanation is in order. As you are
            referring to
            the nodes as PC&#8217;s, I am assuming that you are using the
            MsWindows
            operating system.&nbsp; Some versions (e.g. Windows 2000) are
            able to function as
            routers out of the box, others cannot function as routers,
            and yet others
            require some advanced configuration. (Linux or other x-based
            systems can all
            function as routers).<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">Computers on LAN A are configured to use the
            broadband router as
            a default gateway in order to access the Internet.&nbsp; However,
            in order to
            accomplish the configuration you are looking for, you will
            have to set up a
            manual route on each of the computers on LAN A which will
            instruct them to go
            to the computer running tinc in order to reach the nodes on
            LAN B.&nbsp; The reverse
            will be true for the computers on LAN B.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">Your IDEA1 will not work because the subnet masks
            do not define
            distinct networks.&nbsp; IDEA2 has the same problem because the
            tinc subnet is not
            distinct from the other 2.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">So, to follow your example IDEA2, we have in
            household A, LAN A:
            10.30.1.x and 3 PC&#8217;s: PC-A.11, PC-A.12 &amp; PC-A.13, plus a
            router: R-A.1;&nbsp;
            in household B, LAN B: 10.30.2.x, we have a similar
            configuration, PC-B.11, PC-B.12,
            PC-B.13 and R-B.1;&nbsp; the tinc application is hosted on each
            of PC-A.11 and PC-B.11
            and will use the subnet 10.30.3.x.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">As an example, the IP configurations are as
            follows:<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">PC-A.11:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Default
            Gateway 10.30.1.1/255.255.255.0<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            IP Address
            10.30.1.11/255.255.255.0 on physical network interface<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            IP Address
            10.30.3.1/255.255.255.0 on virtual tinc interface<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            Manual entry in
            routing table to 10.30.2.0/255.255.255.0 via 10.30.3.2<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">PC-A.12, PC-A.13:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Default Gateway
            10.30.1.1/255.255.255.0<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            IP Address
            10.30.1.12/255.255.255.0 and 10.30.1.13/255.255.255.0<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            Manual entry in
            routing table to 10.30.2.0/255.255.255.0 via 10.30.1.11<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">PC-B.11:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Default
            Gateway 10.30.2.1/255.255.255.0<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            IP Address
            10.30.2.11/255.255.255.0 on physical network interface<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            IP Address
            10.30.3.2/255.255.255.0 on virtual tinc interface<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            Manual entry in
            routing table to 10.30.1.0/255.255.255.0 via 10.30.3.1<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">PC-B.12, PC-B.13:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Default Gateway
            10.30.2.1/255.255.255.0<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            IP Address
            10.30.2.12/255.255.255.0 and 10.30.2.13/255.255.255.0<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
            Manual entry in
            routing table to 10.30.1.0/255.255.255.0 via 10.30.2.11<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">Now every PC knows where to send packets destined
            for both the
            Internet and the other household.&nbsp; The PC&#8217;s hosting tinc are
            acting as
            the virtual routers between the two sites.&nbsp; Note once again
            that various
            versions of Windows have this routing function disabled.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">Hope this helps you,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">Alan<o:p></o:p></span></p>
        <div>
          <div style="border-right: medium none; border-width: 1pt
            medium medium; border-style: solid none none; border-color:
            rgb(181, 196, 223) -moz-use-text-color -moz-use-text-color;
            padding: 3pt 0in 0in;">
            <p class="MsoNormal"><b><span style="font-size: 10pt;
                  font-family:
                  &quot;Tahoma&quot;,&quot;sans-serif&quot;; color:
                  windowtext;">From:</span></b><span style="font-size:
                10pt; font-family:
                &quot;Tahoma&quot;,&quot;sans-serif&quot;; color:
                windowtext;"> <a class="moz-txt-link-abbreviated" href="mailto:tinc-bounces@tinc-vpn.org">tinc-bounces@tinc-vpn.org</a>
                [<a class="moz-txt-link-freetext" href="mailto:tinc-bounces@tinc-vpn.org">mailto:tinc-bounces@tinc-vpn.org</a>] <b>On Behalf Of </b>Andrew
                Savinykh<br>
                <b>Sent:</b> Wednesday, October 06, 2010 18:17<br>
                <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:tinc@tinc-vpn.org">tinc@tinc-vpn.org</a><br>
                <b>Subject:</b> Re: Windows subnets<o:p></o:p></span></p>
          </div>
        </div>
        <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        <p class="MsoNormal">Donald,<br>
          <br>
          thank you, while I still have some questions, your answer is
          definitely a step
          in the right direction.<br>
          In the other reply I was asked what I'm trying to achieve.
          Let's consider the
          following scenario (which is quite similar to the one that
          described in the
          tinc manual).<br>
          <br>
          Let's assume we have two households, each has 3-5 computers in
          it.&nbsp; Both
          house holds have similar network configuration:<br>
          They are connected to internet with an ADSL line and a router.<br>
          The computers in the local network access internet via the
          router.<br>
          The router is configured so that one of the computers have
          port 665 forwarded
          to be accessible outside.<br>
          The external IP is changed rarely and there is dynamic DNS
          service (external)
          in use to accommodate for the change of IP when it happens.<br>
          <br>
          One household has local network addresses of 192.168.1.* and
          the other has
          10.1.1.*<br>
          I'm installing tinc on one computer in each household. <br>
          <br>
          The goal is to let all computers in both house holds to see
          each other by ip
          address. Also it is desired that for computer games purposes<br>
          all computers appear to be on the same LAN (for broadcasts).
          But this is not
          mandatory. (it appears that it's not possible without
          installing tinc on every
          PC <br>
          as every tinc daemon serves a subnet and two tinc daemons
          can't serve a part of
          subnet each)<br>
          <br>
          All computers run different flavours of Windows, most being
          Windows 7.<br>
          <br>
          I have two ideas how to set this up, although I'm not sure if
          any of these two
          works:<br>
          <br>
          IDEA1.<br>
          =====<br>
          Household A<br>
          Gateway IP: 10.30.0.1<br>
          Gateway Mask: 255.255.255.0<br>
          Gateway Default Gateway: ????<br>
          <br>
          Other PCs IP: 10.30.0.2,3,4 etc<br>
          Other PCs Mask: 255.255.255.0<br>
          Other PCs Deafult Gateway: 10.30.0.1<br>
          <br>
          Tinc Subnet: 10.30.0.0/25<br>
          <br>
          Household B<br>
          Gateway IP: 10.30.0.129<br>
          Gateway Mask: 255.255.255.0<br>
          Gateway Default Gateway: ????<br>
          <br>
          Other PCs IP: 10.30.0.130,131,132 etc<br>
          Other PCs Mask: 255.255.255.0<br>
          Other PCs Default Gateway: 10.30.0.129<br>
          <br>
          Tinc Subnet: 10.30.0.128/25<br>
          <br>
          <br>
          IDEA2.<br>
          =====<br>
          Household A<br>
          Gatway IP: 10.30.0.1<br>
          Gateway Mask: 255.255.255.0<br>
          Gateway Default Gateway: ????<br>
          <br>
          Other PCs IP: 10.30.0.2-255 etc<br>
          Other PCs Mask: 255.255.255.0<br>
          Other PCs Default Gateway: 10.30.0.1<br>
          <br>
          Tinc Subnet: 10.30.0.0/24<br>
          <br>
          Household B<br>
          Gateway IP: 10.30.1.1<br>
          Gateway Mask: 255.255.255.0<br>
          Gateway Default Gateway: ????<br>
          <br>
          Other PCs IP: 10.30.1.2-255 etc<br>
          Other PCs Mask: 255.255.255.0<br>
          Other PCs Default Gateway: 10.30.0.129<br>
          <br>
          Tinc Subnet: 10.30.1.0/24<br>
          <br>
          <br>
          So IDEA 1 probably won't work at all. Will it? And with IDEA 2
          the pc's won't
          appear on the same LAN and their broadcasts won't reach each
          other.<br>
          As far as I understand I need to install TAP interface on each
          of the
          participating windows PCs, correct?<br>
          What is specified in default gateway of the gateways?<br>
          <br>
          <br>
          Thank you in advance,<br>
          Andrew<br>
          <br>
          On 7/10/2010 4:36 a.m., Donald Pearson wrote: <o:p></o:p></p>
        <p class="MsoNormal">The PCs that you want to participate need
          to have a route
          for the VPN subnet pointing to their local VPN gateway, which
          would be the
          local device with Tinc installed on it. <o:p></o:p></p>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <div>
          <p class="MsoNormal">Theoretical configuration example.<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <div>
          <p class="MsoNormal">VPN subnet is <a moz-do-not-send="true"
              href="http://10.10.10.0/24">10.10.10.0/24</a><o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <div>
          <p class="MsoNormal">At a location, one computer <a
              moz-do-not-send="true" href="http://192.168.1.254/24">192.168.1.254/24</a>
            connects to the VPN and serves as the VPN gateway. &nbsp;This
            gateway needs to
            be configured for TCP/IP forwarding.<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><a moz-do-not-send="true"
              href="http://support.microsoft.com/kb/315236">http://support.microsoft.com/kb/315236</a>&nbsp;-
            windows<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><a moz-do-not-send="true"
href="http://www.ducea.com/2006/08/01/how-to-enable-ip-forwarding-in-linux/">http://www.ducea.com/2006/08/01/how-to-enable-ip-forwarding-in-linux/</a>&nbsp;-
            linux<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <div>
          <p class="MsoNormal">Other computers local to the gateway need
            a route to the VPN
            network added so they know how to get there.<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <div>
          <p class="MsoNormal">In windows. &nbsp; route -p add 10.10.10.0
            mask
            255.255.255.0 192.168.1.254<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal">This will add the persistent route that
            remains after
            reboot.<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <div>
          <p class="MsoNormal">Does that answer your question?<o:p></o:p></p>
        </div>
        <div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
          <div>
            <p class="MsoNormal">On Wed, Oct 6, 2010 at 6:41 AM, Andrew
              Savinykh &lt;<a moz-do-not-send="true"
                href="mailto:andrews@brutsoft.com">andrews@brutsoft.com</a>&gt;
              wrote:<o:p></o:p></p>
            <div>
              <p class="MsoNormal">Thank you for your reply. As far as I
                can see there is no
                point specifying subnet that consists of more than one
                PC in tinc config if you
                are going to install tinc on every PC in the subnet
                anyway. Correct me if I'm
                wrong.<br>
                Now, assuming I'm right, there will be PCs in the subnet
                that don't have tinc
                installed on them. How to configure these PCs so they
                are a part of the subnet
                and participate in routing?<br>
                <br>
                Cheers,<br>
                Andrew <o:p></o:p></p>
              <div>
                <div>
                  <p class="MsoNormal"><br>
                    <br>
                    On 6/10/2010 10:13 p.m., C&eacute;dric Lemarchand wrote: <o:p></o:p></p>
                </div>
              </div>
              <blockquote style="margin-top: 5pt; margin-bottom: 5pt;">
                <div>
                  <div>
                    <p class="MsoNormal">Hi,<br>
                      <br>
                      I am not sure to understand what you mean with
                      "joining" a subnet.<br>
                      <br>
                      But if your "local computer" need to reach the
                      "remote
                      subnet" served by tinc, you can set the local IP
                      of the local tinc server
                      as the default gateway, or add a route to the
                      remote subnet via the local tinc
                      IP. Of course, computer located on the remote
                      subnet need the same thing.<br>
                      <br>
                      C&eacute;dric<br>
                      <br>
                      Le 06/10/10 09:37, Andrew Savinykh a &eacute;crit&nbsp;: <o:p></o:p></p>
                    <p class="MsoNormal">&nbsp;Hello all, <br>
                      <br>
                      I understand that each tinc daemon corresponds to
                      one or more subnets that it
                      "owns" a subnet can be a single ip or more. <br>
                      Could you please tell me what do I need to do to
                      join a computer in local
                      network (windows) to a subnet served by tinc? <br>
                      <br>
                      Thank you in advance, <br>
                      Andrew <br>
                      <br>
                      _______________________________________________ <br>
                      tinc mailing list <br>
                      <a moz-do-not-send="true"
                        href="mailto:tinc@tinc-vpn.org" target="_blank">tinc@tinc-vpn.org</a>
                      <br>
                      <a moz-do-not-send="true"
                        href="http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc"
                        target="_blank">http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc</a>
                      <o:p></o:p></p>
                    <p class="MsoNormal" style="margin-bottom: 12pt;"><o:p>&nbsp;</o:p></p>
                    <div>
                      <p class="MsoNormal">-- <o:p></o:p></p>
                      <p style="margin-bottom: 0.0001pt;"><b><span
                            style="font-size: 10pt; font-family:
                            &quot;Arial
                            Black&quot;,&quot;sans-serif&quot;;">C&eacute;dric
                            Lemarchand &#8211; iXSea SAS</span></b><o:p></o:p></p>
                      <p style="margin-bottom: 0.0001pt;"><span
                          style="font-size: 10pt; font-family:
                          &quot;Arial&quot;,&quot;sans-serif&quot;;">Administrateur
Syst&egrave;me
                          &amp; R&eacute;seaux</span><o:p></o:p></p>
                      <p style="margin-bottom: 0.0001pt;"><span
                          style="font-size: 10pt; font-family:
                          &quot;Arial&quot;,&quot;sans-serif&quot;;
                          color: rgb(35, 35, 220);"><a
                            moz-do-not-send="true"
                            href="http://www.ixsea.com/" target="_blank">http://www.ixsea.com/</a>
                          - <a moz-do-not-send="true"
                            href="mailto:cedric.lemarchand@ixsea.com"
                            target="_blank">&lt;cedric.lemarchand@ixsea.com&gt;</a></span><o:p></o:p></p>
                      <p style="margin-bottom: 0.0001pt;"><span
                          style="font-size: 10pt; font-family:
                          &quot;Arial&quot;,&quot;sans-serif&quot;;">Tel:
                          +33 1 30 08 8888
                          &#8211; GSM: +33 6 37 23 40 93</span><o:p></o:p></p>
                    </div>
                  </div>
                </div>
                <pre><o:p>&nbsp;</o:p></pre>
                <pre>_______________________________________________<o:p></o:p></pre>
                <pre>tinc mailing list<o:p></o:p></pre>
                <div>
                  <pre><a moz-do-not-send="true" href="mailto:tinc@tinc-vpn.org" target="_blank">tinc@tinc-vpn.org</a><o:p></o:p></pre>
                  <pre><a moz-do-not-send="true" href="http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc" target="_blank">http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc</a><o:p></o:p></pre>
                </div>
              </blockquote>
              <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
            </div>
            <p class="MsoNormal" style="margin-bottom: 12pt;"><br>
              _______________________________________________<br>
              tinc mailing list<br>
              <a moz-do-not-send="true" href="mailto:tinc@tinc-vpn.org">tinc@tinc-vpn.org</a><br>
              <a moz-do-not-send="true"
                href="http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc"
                target="_blank">http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc</a><o:p></o:p></p>
          </div>
          <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
        </div>
        <pre><o:p>&nbsp;</o:p></pre>
        <pre><o:p>&nbsp;</o:p></pre>
        <pre>_______________________________________________<o:p></o:p></pre>
        <pre>tinc mailing list<o:p></o:p></pre>
        <pre><a moz-do-not-send="true" href="mailto:tinc@tinc-vpn.org">tinc@tinc-vpn.org</a><o:p></o:p></pre>
        <pre><a moz-do-not-send="true" href="http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc">http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc</a><o:p></o:p></pre>
        <p class="MsoNormal"><o:p>&nbsp;</o:p></p>
      </div>
      <pre wrap="">
<fieldset class="mimeAttachmentHeader"></fieldset>
_______________________________________________
tinc mailing list
<a class="moz-txt-link-abbreviated" href="mailto:tinc@tinc-vpn.org">tinc@tinc-vpn.org</a>
<a class="moz-txt-link-freetext" href="http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc">http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>