Masquerading and NAT

Carey Tyler Schug <[email protected]> Thu, 19 May 2011 15:11:57 -0500
Newsgroups gmane.org.user-groups.luni.tech
Message-ID <[email protected]>
Recently, starting at noon Friday (a suspicious time) my ISP (Comcast) 
connection did not work when I went through my IPCOP 
firewall/router/NAT, but did work when I connected one computer directly 
to the cable modem.  Well, it would work, but was throttled to such a 
low data rate, that I could not get beyond maybe the Google search 
page.  Ping and traceroute worked as far as the target firewall.

The first support person I talked to asked if I could connect directly, 
without my "wireless router", making me suspect he knew something.  
Subsequent calls were stonewalled, other than to try to sell me premium 
support.

Sometime between yesterday and today everything was back to normal.  I 
changed nothing in my network Friday through today.

I had a similar experience years ago when they broke the pinhole for 
DHCP to acquire IP leases.  The denied any problem and eventually it was 
fixed, thus reporting no customer down time.

But clearly, something is different about the TCP/IP coming our of the 
NAT router than coming directly from a PC, I lack the skills to 
understand my web searches and find out what that difference is.

I found this page on masquerading

    http://tldp.org/HOWTO/IP-Masquerade-HOWTO/ipmasq-background2.1.html

which made it sound like the process included in those instructions was 
different than used in a typical NAT router, specifically:

    MASQ allows a set of machines to *invisibly* access the Internet via
    the MASQ gateway. To other machines on the Internet, the outgoing
    traffic will appear to be from the IP MASQ Linux server itself. In
    addition to the added functionality, IP Masquerade provides the
    foundation to create a HEAVILY secured networking environment. With
    a well built firewall, breaking the security of a well configured
    masquerading system and internal LAN should be considerably
    difficult to accomplish.

However, much later, I realized that story seems to be dated 2005, so 
perhaps it was "new" back then but now an ISP can recognize the 
forwarded traffic.

The answer to any of these questions could be a web page, web archive, 
or another forum where I might find the answer.

Question 1:

What is different about the internet side of a NAT router that makes it 
possible for traffic to be throttled?

Question 2

Is there a form of IP Masquerading that would escape that scrutiny?

Question 3:

Is there a firewall distribution that would appear to be a single 
computer to an ISP?

-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni