Re: Comcast problems again
Carl Karsten <[email protected]> Thu, 19 May 2011 08:11:00 -0500
| Newsgroups | gmane.org.user-groups.luni.tech |
|---|---|
| Message-ID | <[email protected]> |
Do you have a laptop? On Thu, May 19, 2011 at 12:21 AM, Carey Tyler Schug <[email protected]> wrote: > OK, I'm snorkeling... (just made that up, Think, means in over my head, > stretching to glean bits of knowledge I understand). > > On 05/17/2011 04:34 PM, Trev Peterson wrote: >> Speaking as someone who has a test lab setup in my home office I suggest >> you simplify your network to have the "prod" net directly off the main >> router. You can use subinterfaces on the cisco to support this if you >> don't have enough ports. The problems you are having may be (and I >> suspect are) from your "internal" network (firewall rules, routing >> issues, etc). EVERYTIME you have a problem you will need to change your >> network config to rule out problems from your internal config. >> >> What I suggest is something like this: >> >> internet ---- primary router ----- prod network >> \------ ----- test network > The reason I am set up as I am is that I only have one router with 3 > Ethernet ports, and that is a 3000 series with a 6 Ethernet unit, and > using as above would remove it from use as a lab tool (plus it uses a > lot of heat, and being old, could fail at any time if used 24x7. The > primary router above needs 3 Ethernet ports or additional devices to > convert the non-Ethernet ports back to Ethernet, unless I do as follows, > where "======" is some other kind of serial crossover cable. which could > be done with three 2501 routers: > > internet ----firewall-----primary router==== router ----- prod network > \========== router ----- test network > > Just in case there is any confusion, below is my configuration: > > internet ---- firewall ------ switch ------prod network > \ \ \----- test router 1 ========= test network 1 > \ \----- test router 2 ========= test network 2 > \-------- router& default gateway > > "Default gateway" routes from prod network to firewall or either test router. > > > > IPCOP will do a DMZ, but will it do as you suggest above, meaning (I > presume) serve as the primary router? Will Leaf or (preferably) > zeroshell, since zeroshell runs from a CD and is (1) more secure and (2) > more easily backed up on different hardware should it fail. > > And If I am correct that Comcast is attempting to prevent the use of > NAT, I could set up a new fire wall that still would not work. If I have > to build a new device, I would really like to find a "masquerading > firewall" which, as I understand the terms they use, does translation > internally, but from the web side, looks no different that one large > computer on which running all the programs that are actually running on > the network. > > Remember, from network traffic history graphs on the firewall, > communication ceased at noon exactly. I was not home from 9:30 AM until > 2:30 PM, so did not change anything at the time it failed. >> Excuse the simple ascii art. Hopefully it makes things clear and helps >> out. >> >> As for some of the other questions I'm not really sure you have a total >> grasp on how things work. It is hard to detect if the source of a web >> connection has undergone NAT and disallow or throttle those connections >> (some protocols put the source IP inside the packet but HTTP is not >> normally one of them). I've never heard of any ISP doing that and while >> comcast does MAC address lock the modem to get you to buy "additional >> computers" simply putting a firewall with NAT off the modem defeats that >> rather easily. I've never had any problems doing that (no HTTP >> throttling, etc). >> >> Comcast DOES block outgoing SMTP (tcp port 25) to anything other than >> their mail servers. You can use the submission (tcp port 587) to get >> around this. > That explains why I couldn't set up Thunderbird to talk to my alumna > server or Google.. >> I think I suggested testing SMTP using traceroute but it >> should have been using tcptraceroute since SMTP uses TCP not UDP. >> Please excuse the brain fart there :) Hope this helps, >> >> Trev >> >> On Tue, 2011-05-17 at 18:49 +0000, [email protected] wrote: >>> Thank you for responding. The reason I posted is I thought I recalled >>> from years ago that comcast attempted to prevent people from using >>> multiple computers via NATting. Possibly by blocking or intentionally >>> slowing alternate ports used in NAPT >>> >>> Gathering data is hard because I have to reconfigure the network, shut >>> down computers, go downstairs to reset cable modem each time. I have >>> two computers, I used a winblows notebook and an ubuntu desktop. My >>> internal network is convoluted because I have (not used for years) a >>> cisco home lab and multiple segments. Not wanting to permanently >>> allocate one of only a couple of routers with multiple ethernet ports, >>> I have a small cisco (802) off of my main switch. It is the default >>> router, either routing back to some other cisco lab off of the main >>> switch or to the IPCOP machine also on the main switch. Slows my >>> ethernet a little bit as traffic goes two ways over 10MB/Sec but I >>> still get 3 MB/S download off of the net and has only been an issue in >>> one online game system related app where I get typically 60-100 >>> successes out of 175 while others get 80-120 (this app creates many >>> web connections in a few seconds and ends them). >>> >> > -- > Linux Users Of Northern Illinois (Chicago) - Technical Discussion > http://luni.org/mailman/listinfo/luni > -- Carl K -- Linux Users Of Northern Illinois (Chicago) - Technical Discussion http://luni.org/mailman/listinfo/luni