Re: Comcast problems again

Carey Tyler Schug <[email protected]> Thu, 26 May 2011 21:57:04 -0500
Newsgroups gmane.org.user-groups.luni.tech
Message-ID <[email protected]>
On 05/25/2011 11:58 PM, Trev Peterson wrote:
>
> sub-interfaces are not VLAN trunking.  You can configure sub-interfaces
> on non-VLAN aware equipment it just means they share the same broadcast
> domain.  On a single port router connected to a dumb hub (not switch) I
> can configure 100+ subnets on the router connected to the switch.
> Sub-interfaces are merely logical divisions of the physical port.
OK,  sub-interfaces are returning from the depths of memory.  I took a 
CCNA class, the first CCNP class, and passed the CNA license in the 2004 
time frame, but never used the knowledge, so it has been slipping into 
forgotten nooks and crannies.  In class, I think we only used 
sub-interfaces between routers, maybe between switches.

So I could connect my firewall to a dumb hub, and ports on it to a 
switch for each of my internal subnets?  Or a switch that supports 
sub-interfaces and VLANs, for which (maybe?) a Cisco 1900-EN would 
qualify.  Cool, that sounds workable.  if the 1900 won't work, I'll need 
to look for a small dumb hub, I think the only ones I have left are a 24 
port with a noisy fan and a 10Base2 hub., .  I wonder if I could find 
one of the very small number of 100BaseT hubs manufactured.

And presumably I can configure sub-interfaces on the firewall 
computer....have to learn how to do that....

--Carey
> I hope this doesn't sound condescending.
Not at all, I appreciate the corrections.
>   You have a lot of equipment
> but need to learn more of the fundamentals of routing/switching.
mostly re-learn what I have forgotten with the passage of time.
>> What I am still looking for on the web is an explanation of how traffic
>> coming back to a system is routed to the correct location, and why
>> masquerading is different so that Comcast can break it.   And if there
>> is a "firewall" solution that Comcast can't detect or break.
> Basic networking coursework (like I mentioned above) will teach you
> about ports and how NAT works.
If I could afford thousands of dollars for Cisco courses, I could just 
buy a commercial grade internet connection.  I need something on the web 
or a book I can get at a library.  I have a set of router 11.1 IOS 
books, if you think it would be int here, I can start searching, but it 
is a whole shelf of books.
>   I've tried to explain that to Comcast
> there is no difference between NAT and Masquerading but maybe wikipedia
> can explain it better:
>
> http://en.wikipedia.org/wiki/Network_address_translation
I read that before you sent it, and think I understood enough.  So we 
will assume the HOWTO in my previous post is wrong,.  Or maybe those 
instructions are for a different variation of Masquerading that would 
work, but I don't feel competent to install source patches on my Linux 
kernal...patches from 2005 that may no longer work without rewriting, of 
course.

It still doesn't explain how the web side of NAT looks different 
compared to a single computer so Comcast can break it, and if there is 
some way to tweak NAT so Comcast won't break it.  Like force NAT to use 
a smaller range of translated port numbers?

--Carey
-- 
Linux Users Of Northern Illinois (Chicago) - Technical Discussion 
http://luni.org/mailman/listinfo/luni