Re: Comcast problems again

Carey Tyler Schug <[email protected]> Thu, 19 May 2011 00:21:26 -0500
Newsgroups gmane.org.user-groups.luni.tech
Message-ID <[email protected]>
OK, I'm snorkeling... (just made that up, Think, means in over my head, 
stretching to glean bits of knowledge I understand).

On 05/17/2011 04:34 PM, Trev Peterson wrote:
> Speaking as someone who has a test lab setup in my home office I suggest
> you simplify your network to have the "prod" net directly off the main
> router.  You can use subinterfaces on the cisco to support this if you
> don't have enough ports.  The problems you are having may be (and I
> suspect are) from your "internal" network (firewall rules, routing
> issues, etc).  EVERYTIME you have a problem you will need to change your
> network config to rule out problems from your internal config.
>
> What I suggest is something like this:
>
> internet	----	primary router 	-----	prod network
> 				\------	-----	test network
The reason I am set up as I am is that I only have one router with 3 
Ethernet ports, and that is a 3000 series with a 6 Ethernet unit, and 
using as above would remove it from use as a lab tool (plus it uses a 
lot of heat, and being old, could fail at any time if used 24x7. The 
primary router above needs 3 Ethernet ports or additional devices to 
convert the non-Ethernet ports back to Ethernet, unless I do as follows, 
where "======" is some other kind of serial crossover cable. which could 
be done with three 2501 routers:

internet ----firewall-----primary router==== router ----- prod network
				\========== router ----- test network

Just in case there is any confusion, below is my configuration:

internet ---- firewall ------ switch ------prod network
			       \ \ \----- test router 1 ========= test network 1
				\ \----- test router 2 ========= test network 2
		 		 \-------- router&  default gateway

"Default gateway" routes from prod network to firewall or either test router.



IPCOP will do a DMZ, but will it do as you suggest above, meaning (I 
presume) serve as the primary router? Will Leaf or (preferably) 
zeroshell, since zeroshell runs from a CD and is (1) more secure and (2) 
more easily backed up on different hardware should it fail.

And If I am correct that Comcast is attempting to prevent the use of 
NAT, I could set up a new fire wall that still would not work. If I have 
to build a new device, I would really like to find a "masquerading 
firewall" which, as I understand the terms they use, does translation 
internally, but from the web side, looks no different that one large 
computer on which running all the programs that are actually running on 
the network.

Remember, from network traffic history graphs on the firewall, 
communication ceased at noon exactly. I was not home from 9:30 AM until 
2:30 PM, so did not change anything at the time it failed.
> Excuse the simple ascii art.  Hopefully it makes things clear and helps
> out.
>
> As for some of the other questions I'm not really sure you have a total
> grasp on how things work.  It is hard to detect if the source of a web
> connection has undergone NAT and disallow or throttle those connections
> (some protocols put the source IP inside the packet but HTTP is not
> normally one of them).  I've never heard of any ISP doing that and while
> comcast does MAC address lock the modem to get you to buy "additional
> computers" simply putting a firewall with NAT off the modem defeats that
> rather easily.  I've never had any problems doing that (no HTTP
> throttling, etc).
>
> Comcast DOES block outgoing SMTP (tcp port 25) to anything other than
> their mail servers.  You can use the submission (tcp port 587) to get
> around this.
That explains why I couldn't set up Thunderbird to talk to my alumna 
server or Google..
> I think I suggested testing SMTP using traceroute but it
> should have been using tcptraceroute since SMTP uses TCP not UDP.
> Please excuse the brain fart there :)  Hope this helps,
>
> 	Trev
>
> On Tue, 2011-05-17 at 18:49 +0000, [email protected] wrote:
>> Thank you for responding.  The reason I posted is I thought I recalled
>> from years ago that comcast attempted to prevent people from using
>> multiple computers via NATting.  Possibly by blocking or intentionally
>> slowing alternate ports used in NAPT
>>
>> Gathering data is hard because I have to reconfigure the network, shut
>> down computers, go downstairs to reset cable modem each time.  I have
>> two computers, I used a winblows notebook and an ubuntu desktop.  My
>> internal network is convoluted because I have (not used for years) a
>> cisco home lab and multiple segments.  Not wanting to permanently
>> allocate one of only a couple of routers with multiple ethernet ports,
>> I have a small cisco (802) off of my main switch.  It is the default
>> router, either routing back to some other cisco lab off of the main
>> switch or to the IPCOP machine also on the main switch.  Slows my
>> ethernet a little bit as traffic goes two ways over 10MB/Sec but I
>> still get 3 MB/S download off of the net and has only been an issue in
>> one online game system related app where I get typically 60-100
>> successes out of 175 while others get 80-120 (this app creates many
>> web connections in a few seconds and ends them).
>>
>
-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni