Masquerading and NAT
Carey Tyler Schug <[email protected]> Thu, 19 May 2011 15:11:57 -0500
| Newsgroups | gmane.org.user-groups.luni.tech |
|---|---|
| Message-ID | <[email protected]> |
Recently, starting at noon Friday (a suspicious time) my ISP (Comcast)
connection did not work when I went through my IPCOP
firewall/router/NAT, but did work when I connected one computer directly
to the cable modem. Well, it would work, but was throttled to such a
low data rate, that I could not get beyond maybe the Google search
page. Ping and traceroute worked as far as the target firewall.
The first support person I talked to asked if I could connect directly,
without my "wireless router", making me suspect he knew something.
Subsequent calls were stonewalled, other than to try to sell me premium
support.
Sometime between yesterday and today everything was back to normal. I
changed nothing in my network Friday through today.
I had a similar experience years ago when they broke the pinhole for
DHCP to acquire IP leases. The denied any problem and eventually it was
fixed, thus reporting no customer down time.
But clearly, something is different about the TCP/IP coming our of the
NAT router than coming directly from a PC, I lack the skills to
understand my web searches and find out what that difference is.
I found this page on masquerading
http://tldp.org/HOWTO/IP-Masquerade-HOWTO/ipmasq-background2.1.html
which made it sound like the process included in those instructions was
different than used in a typical NAT router, specifically:
MASQ allows a set of machines to *invisibly* access the Internet via
the MASQ gateway. To other machines on the Internet, the outgoing
traffic will appear to be from the IP MASQ Linux server itself. In
addition to the added functionality, IP Masquerade provides the
foundation to create a HEAVILY secured networking environment. With
a well built firewall, breaking the security of a well configured
masquerading system and internal LAN should be considerably
difficult to accomplish.
However, much later, I realized that story seems to be dated 2005, so
perhaps it was "new" back then but now an ISP can recognize the
forwarded traffic.
The answer to any of these questions could be a web page, web archive,
or another forum where I might find the answer.
Question 1:
What is different about the internet side of a NAT router that makes it
possible for traffic to be throttled?
Question 2
Is there a form of IP Masquerading that would escape that scrutiny?
Question 3:
Is there a firewall distribution that would appear to be a single
computer to an ISP?
--
Linux Users Of Northern Illinois (Chicago) - Technical Discussion
http://luni.org/mailman/listinfo/luni