Re: Comcast problems again

Trev Peterson <[email protected]> Thu, 19 May 2011 11:36:53 -0500
Newsgroups gmane.org.user-groups.luni.tech
Organization Advanced Reality
Message-ID <[email protected]>
I'm pretty sure sub-interfaces can solve this for you rather easily.
Give me a call (number in email sig) and I'll help you work out a good
topology for this.

I should also mention "masquerading" is simply the term used when doing
1 to many NAT (cisco calls it overloading) .  That's it, no extra hiding
or such.  In practice the distinction is rarely made and almost all home
users are doing masquerading instead of 1 to 1 NAT.

Hope this helps,

	Trev

On Thu, 2011-05-19 at 00:21 -0500, Carey Tyler Schug wrote:
> OK, I'm snorkeling... (just made that up, Think, means in over my head, 
> stretching to glean bits of knowledge I understand).
> 
> The reason I am set up as I am is that I only have one router with 3 
> Ethernet ports, and that is a 3000 series with a 6 Ethernet unit, and 
> using as above would remove it from use as a lab tool (plus it uses a 
> lot of heat, and being old, could fail at any time if used 24x7. The 
> primary router above needs 3 Ethernet ports or additional devices to 
> convert the non-Ethernet ports back to Ethernet, unless I do as follows, 
> where "======" is some other kind of serial crossover cable. which could 
> be done with three 2501 routers:
> 
> internet ----firewall-----primary router==== router ----- prod network
> 				\========== router ----- test network
> 
> Just in case there is any confusion, below is my configuration:
> 
> internet ---- firewall ------ switch ------prod network
> 			       \ \ \----- test router 1 ========= test network 1
> 				\ \----- test router 2 ========= test network 2
> 		 		 \-------- router&  default gateway
> 
> "Default gateway" routes from prod network to firewall or either test router.
> 
> 
> 
> IPCOP will do a DMZ, but will it do as you suggest above, meaning (I 
> presume) serve as the primary router? Will Leaf or (preferably) 
> zeroshell, since zeroshell runs from a CD and is (1) more secure and (2) 
> more easily backed up on different hardware should it fail.
> 
> And If I am correct that Comcast is attempting to prevent the use of 
> NAT, I could set up a new fire wall that still would not work. If I have 
> to build a new device, I would really like to find a "masquerading 
> firewall" which, as I understand the terms they use, does translation 
> internally, but from the web side, looks no different that one large 
> computer on which running all the programs that are actually running on 
> the network.
> 

-- 
Trev Peterson
Advanced Reality
Email: [email protected]
Phone: +1 847 406 9018

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni