Re: Comcast problems again
Trev Peterson <[email protected]> Thu, 19 May 2011 11:36:53 -0500
| Newsgroups | gmane.org.user-groups.luni.tech |
|---|---|
| Organization | Advanced Reality |
| Message-ID | <[email protected]> |
I'm pretty sure sub-interfaces can solve this for you rather easily. Give me a call (number in email sig) and I'll help you work out a good topology for this. I should also mention "masquerading" is simply the term used when doing 1 to many NAT (cisco calls it overloading) . That's it, no extra hiding or such. In practice the distinction is rarely made and almost all home users are doing masquerading instead of 1 to 1 NAT. Hope this helps, Trev On Thu, 2011-05-19 at 00:21 -0500, Carey Tyler Schug wrote: > OK, I'm snorkeling... (just made that up, Think, means in over my head, > stretching to glean bits of knowledge I understand). > > The reason I am set up as I am is that I only have one router with 3 > Ethernet ports, and that is a 3000 series with a 6 Ethernet unit, and > using as above would remove it from use as a lab tool (plus it uses a > lot of heat, and being old, could fail at any time if used 24x7. The > primary router above needs 3 Ethernet ports or additional devices to > convert the non-Ethernet ports back to Ethernet, unless I do as follows, > where "======" is some other kind of serial crossover cable. which could > be done with three 2501 routers: > > internet ----firewall-----primary router==== router ----- prod network > \========== router ----- test network > > Just in case there is any confusion, below is my configuration: > > internet ---- firewall ------ switch ------prod network > \ \ \----- test router 1 ========= test network 1 > \ \----- test router 2 ========= test network 2 > \-------- router& default gateway > > "Default gateway" routes from prod network to firewall or either test router. > > > > IPCOP will do a DMZ, but will it do as you suggest above, meaning (I > presume) serve as the primary router? Will Leaf or (preferably) > zeroshell, since zeroshell runs from a CD and is (1) more secure and (2) > more easily backed up on different hardware should it fail. > > And If I am correct that Comcast is attempting to prevent the use of > NAT, I could set up a new fire wall that still would not work. If I have > to build a new device, I would really like to find a "masquerading > firewall" which, as I understand the terms they use, does translation > internally, but from the web side, looks no different that one large > computer on which running all the programs that are actually running on > the network. > -- Trev Peterson Advanced Reality Email: [email protected] Phone: +1 847 406 9018 -- Linux Users Of Northern Illinois (Chicago) - Technical Discussion http://luni.org/mailman/listinfo/luni