Re: Masquerading and NAT
Carl Karsten <[email protected]> Thu, 19 May 2011 16:51:48 -0500
| Newsgroups | gmane.org.user-groups.luni.tech |
|---|---|
| Message-ID | <[email protected]> |
You seem hyper focused on the nat ting. Your 2nd and 3rd questions are written as if you know the answer to the first. I think you should open up to it maybe being something else. You should also answer the questions we ask. On Thu, May 19, 2011 at 3:11 PM, Carey Tyler Schug <[email protected]> wrote: > Recently, starting at noon Friday (a suspicious time) my ISP (Comcast) > connection did not work when I went through my IPCOP firewall/router/NAT, > but did work when I connected one computer directly to the cable modem. > Well, it would work, but was throttled to such a low data rate, that I could > not get beyond maybe the Google search page. Ping and traceroute worked as > far as the target firewall. > > The first support person I talked to asked if I could connect directly, > without my "wireless router", making me suspect he knew something. > Subsequent calls were stonewalled, other than to try to sell me premium > support. > > Sometime between yesterday and today everything was back to normal. I > changed nothing in my network Friday through today. > > I had a similar experience years ago when they broke the pinhole for DHCP to > acquire IP leases. The denied any problem and eventually it was fixed, thus > reporting no customer down time. > > But clearly, something is different about the TCP/IP coming our of the NAT > router than coming directly from a PC, I lack the skills to understand my > web searches and find out what that difference is. > > I found this page on masquerading > > http://tldp.org/HOWTO/IP-Masquerade-HOWTO/ipmasq-background2.1.html > > which made it sound like the process included in those instructions was > different than used in a typical NAT router, specifically: > > MASQ allows a set of machines to invisibly access the Internet via the MASQ > gateway. To other machines on the Internet, the outgoing traffic will appear > to be from the IP MASQ Linux server itself. In addition to the added > functionality, IP Masquerade provides the foundation to create a HEAVILY > secured networking environment. With a well built firewall, breaking the > security of a well configured masquerading system and internal LAN should be > considerably difficult to accomplish. > > However, much later, I realized that story seems to be dated 2005, so > perhaps it was "new" back then but now an ISP can recognize the forwarded > traffic. > > The answer to any of these questions could be a web page, web archive, or > another forum where I might find the answer. > > Question 1: > > What is different about the internet side of a NAT router that makes it > possible for traffic to be throttled? > > Question 2 > > Is there a form of IP Masquerading that would escape that scrutiny? > > Question 3: > > Is there a firewall distribution that would appear to be a single computer > to an ISP? > > > -- > Linux Users Of Northern Illinois (Chicago) - Technical Discussion > http://luni.org/mailman/listinfo/luni > > -- Carl K -- Linux Users Of Northern Illinois (Chicago) - Technical Discussion http://luni.org/mailman/listinfo/luni