Geolocation …

(Blogged via flickr)

… ist auch so eine Geschichte voller Mißverständnisse. Warum zum Beispiel das N9 trotz A-GPS mich schon in Gütersloh wähnt, statt korrekt zwischen Wolfsburg und Hannover verortet, und warum die Panasonic DMC-ZS10 trotz angeblich daueraktivem GPS-Chip immer gefühlte Stunden unter freiem Himmel für die (Neu-) Positionierung benötigt … Man weiß es nicht.

Your tunnel just caved in

75788333

Did I mention that I consider IPsec bloated and overly complicated? Well, stressing the L2TP/IPSEC connection during a train ride it just proved my point — whereas the OpenVPN between Laptop and the datacenter is lossy (when there is no GSM connectivity) but rock solid, Androids multilayer complex solution just dies every now and then, leading myself reducing the password, needed to be entered each time, to just ‘.’ – standard behaviour of humans if technology suck big time, as does Androids VPN solution.

Will reconsider rooting and dumping OpenVPN on the phones instead …

Android and VPN — it finally works

Oh yeah. After I recently discovered that OpenVPN on the Fritzbox was the cause of all the grief I had with trying to connect two Fritzboxes via SIP over the Internet (tunneled, of course), and got rid of that (on the FB; my VPN-of-choice is still OpenVPN) and now even did a native Fritz-VPN link between two of them, I though, “hey, why not linking my Android to it as well?” Few I knew, back then, on how impossible this is with current, i. e. 2.3-ish, Android — the Fritzbox only does IPsec, Android only does L2TP/IPsec.

To cut a long (two nights, that is) story short: thanks to the awesome howto of Philip Bailey I got this going in next to no time — on a fresh Debian box, that is:

wusel@greebo:~$ traceroute dyn-130.mobile.uu.org
traceroute to dyn-130.mobile.uu.org (192.251.226.130), 64 hops max, 40 byte packets
 1  gw.berlin.uu.org (193.26.120.113)  0 ms  0 ms  0 ms
 2  gw-alice-b.vpn.uu.org (192.251.226.173)  27 ms  27 ms  33 ms
 3  quoth.uu.org (195.71.106.48)  28 ms  31 ms  28 ms
 4  dyn-130.mobile.uu.org (192.251.226.130)  101 ms  99 ms  101 ms

Cool stuff is: I now can happily start my VPN on the Android, start a SIP client and connect to my Fritzbox at home to take calls or make some — from my fixed line number, that is. I’m still not certain if I keep it this way or once again bring up my Asterisk. But for now it “just works” with two Fritzboxes, connected via a VPN (in this case, the FB in Berlin is the one hooked to DSL, the one doing SIP2ISDN in Gütersloh is actually a second one, as I seem to have some cabling issue on the ISDN side of the one in Gütersloh that does the PPPoE stuff) but not, this seems to be the important part, running OpenVPN locally.

I really would liked to connect directly to a Fritzbox from Android, but as I did not want to neither root nor custom-firmware all the Androids in my family, providing just a Android-compatible VPN gateways is the only approach.

Bezeichnend, oder: o2 can do

1026191257

Die einzigen Kosten, mal von dem Faulheitsanruf vom Festnetz nach 0179 abgesehen, sind die von meinem Anruf bei der [censored] Alice-Hotline, weil deren versiffter PPPoE-Server mal wieder für signifikante Zeit unpäßlich war — und die ‘Gesprächszeit’ war zu 90% nervige Warteschleife.

Schon geil, wie Alice/o2 sich da refinanzieren: Server wiederholt kaputtgehen lassen, damit den Service nicht erbringen — und die Kunden in der kostenpflichtigigen Warteschleife abzocken. IMHO ‘o2 can do’ in Reinform :-(

Der Trend geht zum Zweit-VPN

Nachdem ich nun OpenVPN von meinen Fritzboxen runterwarf, da die SIP-Geschichte sich verhaspelte, habe ich eine laue Winternacht genutzt, zwei Fritzboxen über deren VPN-Lösung (IPSec; irgendwann muß man ja auch damit mal anfangen, woll?) zu verbandeln. Und da sich DynDNS grade zugenköpft gibt, was kostenlose Account angeht, habe ich gleich noch meinen eigene DDNS-Service von der Google-Query zum funktionierenen Prototypen gebracht:

21.02.12 03:04:49 VPN-Verbindung zu fb-gt.dyn.uu.org wurde erfolgreich hergestellt.
21.02.12 03:04:25 Internetverbindung wurde erfolgreich hergestellt. IP-Adresse: 92.1.2.3, DNS-Server: 213.4.5.6 und 62.7.8.9, Gateway: 9.8.7.6, Breitband-PoP: HN-XDSL

Und nach ein bißchen Source-Routing klappt auch die Verbindung soweit; hier Berlin-Gütersloh:

wusel@greebo:~$ traceroute 192.168.177.2
traceroute to 192.168.177.2 (192.168.177.2), 64 hops max, 40 byte packets
1 gw.berlin.uu.org (193.26.120.113) 0 ms 0 ms 0 ms
2 fritz.box (192.168.178.1) 1 ms 1 ms 1 ms
3 192.168.177.2 (192.168.177.2) 59 ms 55 ms 56 ms
4 192.168.177.2 (192.168.177.2) 61 ms 61 ms 61 ms

Der Charme liegt klar in der Umgehung des zentralen Hosts, den ich bislang noch benötigte; Fritzens VPN geht direkt zwischen dem Berliner Alice- und dem Gütersloher T-Entertain-Anschluß, wohingegen mein OpenVPN sich bislang eines zentralen Servers “in da klaud” bedient(e):

wusel@greebo:~$ traceroute nslug-1.uu.org
traceroute to nslug-1.uu.org (192.168.5.245), 64 hops max, 40 byte packets
1 gw.berlin.uu.org (193.26.120.113) 0 ms 0 ms 0 ms
2 gw-alice-b.vpn.uu.org (192.251.226.173) 27 ms 26 ms 26 ms
3 nslug-1.uu.org (192.168.5.245) 64 ms 65 ms 64 ms

Dank des privaten DDNS-Service (der mich nun doch wieder an meine Colocation-Systeme bindet – gut, noch gibt es kostenlose Alternativen zu DynDNS), müßte der Verbindungsaufbau beim Fritz-VPN auch bidirektional klappen. Ob das der Fall ist, muß die Zukunft zeigen; die DDNS-Adressen kann natürlich auch meine OpenVPN-Lösung nutzen, um direkt zu kommunizieren …
FTR, ich setze in Güterloh »FRITZ!Box Fon WLAN 7270 v1 Speedport W503V« und in Berlin »FRITZ!Box Fon WLAN 7270 v2« ein; 7570er bzw. Speedport W920V für Gütersloh als Ersatz der Kombination Speedport 300HS (als VDSL-Modem) und 503V (als Router) sind im Zulauf … Mit der 71er-Serie würde ich die VPN-Sache heute nicht mehr probieren. Seit sowohl dem lokalen Modemausfall als auch den PPPoE-Ausfällen von Alice/o2 akzeptiere ich keine Blackbox-Lösung mehr – Anbieter, die den Leitungsstatus mir nicht offenbaren wollen, wissen offensichtlich, daß sie den Vertrag gar nicht erfüllen können … Auf diese Schmerzen verzichte ich dementsprechend gerne :-)

Karneval und Kamelle

So, den diesjährigen Umzug in Kist ‘überstanden’; ist ja schon ‘irgendwie anders’ aus der Perspektive eines karnevalsunaffinen Nordlichts, wie viel Aufwand man sich machen kann. Aber lustig ist’s auch — und die Kinder sind mit der Ausbeute auch mehr als zufrieden :-)

Not my President 2.0

Wulff hat gestern hingeworfen — schöne Symbolik im Web der ARD übrigens –, aber die Drohung Merkels mit einem Konsenskandidaten läßt aufhorchen. Zumal erste Stimmen von einer Frau als Zeichen eines Neuanfanges laut werden, gilt es, die Grafiken aus 2010 zu recyceln, denn an der Untragbarkeit von der Leyens hat sich nichts geändert. Zwar berichten Medien davon, daß die Opposition keinen aktuellen Amtsträger akzeptieren wolle, aber Aussagen deutscher Politiker sind leider mehr denn je mit einem MHD im Tagesbereich zu sehen; nicht zuletzt Wulff hat jüngst wieder ‘was geht mich mein Geschwätz von gestern an?’ exemplarisch vorgelebt.

Bildnachweis: twitpic.com/1t819d (@Gmaedzl); Screenshot www.tagesschau.de v. 18.02.2012