Re: Poll: Both ends behind NAT...

Eugen Leitl <[email protected]> Sun, 23 Nov 2003 10:46:40 +0100
Newsgroups gmane.comp.audio.speak-freely.general
Message-ID <[email protected]>
On Sat, Nov 22, 2003 at 10:05:34PM +0100, Johannes Poehlmann wrote:
> There is no problem, as long you control the NAT router. 
> 
> There is a problem if your ISP is forcing NAT on you as
> a tool to prevent you from offering services (which technically
> means, that your machine can be contacted from the internet).

Which technically means you're almost on the Internet, but not quite.
"I can't believe it's not Internet! Feels almost like the real thing!
Only half crippled, and we llllllove it!"
 
> There may be several reasons for your ISP to do so:
> 
> Diffenciated services: You want a machine, that can be contacted from
> the internet: No problem, upgrade to a more expensive ISP contract.

Local folks combat this by issuing you a 128/786 kBit/s ADSL line, and
disconnect you once in 24 h (some even twice). Doesn't help very much,
though: there's a DynDNS client built-in in my NAT box, and the most
rejected connects by far are from P2P, the second largest item being
Windows worms.
 
> Fighting peer to peer: Peer to peer technologies make it very hard to control
>  information flow.  So Government naturally do not like peer 2 peer as
>  does the content industry. 

Some local ISPs have been using traffic shaping on selected ports; 
wonder how they intend to do that on IPsec sessions and VPNs. There's really
no other way to combat the P2P than to 1) outlaw P2P use 2) infiltrate the
network 3) start suing individual users
 
> John Walker was pessimistic, so he stopped his work with speak freely.
> In a very clean way I want to say, everything neatly archived, and a 
> clear timetable. 

Great big thanks go out to John Walker for all the years he's been
giving us free software and interesting publications on Fourmilab.
 
> Johannes
> 
> 
> On Sun, Aug 03, 2003 at 01:36:39AM -0700, Tom Scott wrote:
> > My partner and I use SF behind NAT routers on both ends. He has a DSL
> > modem that converts a public address to several local addresses, I have

It's not a modem, it's a router with NAT and DHCP, most likely. I was not
aware there were ISPs (technically, should be spelled sans I, since
offering crippled service) ramming NAT down customer's throat that rudely.

All local providers use PPPoE and PPP, and can be used by a normal
PC supporting such protocols, if eqipped with an Ethernet NIC and
a xDSL modem.

The reason people use NAT is because they get only one IP (dynamically),
have several PCs, want rudimentary firewalling, use extra functionality
(mine is a WiFi AP), etc.

> > to use ISDN (anything faster not available in our rural area) with a
> > similar setup. We had considerable trouble getting SF working at first,
> > but with perseverance we found a way. I had to tell my Netgear RT-328 to
> > forward all unrecognized packets to one private address and make sure
> > that my box was at that address. But that's simply a limitation of my
> > ISDN router. A smarter router could easily make this  more flexible. 

98% of users confronted with your problem would have just downloaded Skype,
and it would have worked out of the box.
 
> > I don't see why NAT is such an insurmountable problem! We simply need

That's because you're a highly unusual user.

> > NAT server hardware and software that will keep track of where packets

Normal users can't spell NAT, don't know what packets are, nor how an internet works.
They already have hardware their ISP issued them with, and are already
very happy to be online.

> > should be forwarded. Until we can get readily available modem/routers
> > that make the job easier. Why couldn't we set up an old slow box with
> > two NICs and some Linux code that would track and route packets from the
> > public port to the local ports?

Oh, you're talking about that elusive, endangered animal again: the empowered user.
If you have space where you can put a noisy box, don't mind the added fire
hazard and the electricity bill, and can set up and administer said box
(proper locking down and keeping patched included) it's definitely a
solution.



-- Eugen* Leitl <a href="http://leitl.org">leitl</a>
______________________________________________________________
ICBM: 48.07078, 11.61144            http://www.leitl.org
8B29F6BE: 099D 78BA 2FD3 B014 B08A  7779 75B0 2443 8B29 F6BE
http://moleculardevices.org         http://nanomachines.net
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux)

iD8DBQE/wIIAdbAkQ4sp9r4RAo4uAKCDzwgwFv5RTvW7qGbJ78QHITel5ACeLjAK
aeO3HKSsp1nJm4YbqO6ZRrc=
=L6lL
-----END PGP SIGNATURE-----