NATing

NATing

Post by Andrew Paxto » Sun, 12 Nov 2000 04:00:00



Currently,  I have a server (redhat linux box) connected to a Cisco 1600
router. The server has a multiple rs232card with 6 terminals attached.
What I want to do is to to dump the terminals and replace them with PCs. As
the cisco has NAT capability, it occurs to me that I can connect everything
through a hub and assign private IP  (eg 10.0.0.x) addresses to the PCs so
that they can access the internet.
The problem is that the server has a valid non-private IP address (I mustn't
change that), but the pcs need to talk to it. Can I assign a second
(private) IP address to the its ethernet interface? Would all the macine on
the local lan be able to talk to each other and access the internet, and
would the server be accessible from the outside using its non-private
address? Any alternative suggestions?
Any help appreciated.
AndyP
 
 
 

NATing

Post by David K. Mean » Mon, 13 Nov 2000 04:00:00



Quote:> Currently,  I have a server (redhat linux box) connected to a Cisco 1600
> router. The server has a multiple rs232card with 6 terminals attached.
> What I want to do is to to dump the terminals and replace them with PCs.
As
> the cisco has NAT capability, it occurs to me that I can connect
everything
> through a hub and assign private IP  (eg 10.0.0.x) addresses to the PCs so
> that they can access the internet.
> The problem is that the server has a valid non-private IP address (I
mustn't
> change that), but the pcs need to talk to it. Can I assign a second
> (private) IP address to the its ethernet interface? Would all the macine
on
> the local lan be able to talk to each other and access the internet, and
> would the server be accessible from the outside using its non-private
> address? Any alternative suggestions?

  While the Cisco 1600 does have a NAT facility built into it, you are
probably better off doing the NAT (aka masquerading) on the server, or on
a second machine connected to the network segment inhabited by the router
and the server.
  The reason is that you not only would need to make NAT work, but you would
also have to overlay the *real* IP subnet on the same physical segment in
the
scheme you suggested; at the expense of an extra ethernet card in your
server,
you could keep your current setup, get masquerading and firewalling
capabilities,
and have a less complex setup to debug.
  This alternate scenario is described pretty fully at
    http://www.digitalelephant.org/computing/fire/firewall.html

 
 
 

1. Accessing Samba From Behind a NATing Router

    Folks:  Have a Samba 2.0.x server (based on the NetMAX File Server
appliance distro) that works very well and I want to provide access to
the server from the outside world.  The server sits behind a Linksys
cable modem router/firewall and I've explicitly forwarded ports 137-139
to my server's IP address (192.168.1.100), but I still can't access
the server.  As I type this, I've just re-read 'Using Samba' and the only
thing I haven't looked into are the hosts allow/deny clauses of smb.conf,
since this file is normally controlled by the NetMAX appliance sware.  Will
do so during my next client-site visit....

    I also wrote a Python script that looks up the current (translated) IP
addr for my server (eg. from server.foobar.com) and writes a fresh LMHOSTS
file for its NETBIOS name on each telecommuting workstation.  So NET USE
\\server\share shud work, but I get a 'computer or sharename could not be
found.' error message.

    Perhaps there are other things I need to do in order to make this
work.  Any suggestions ?  TIA....Jet

--

================================================================
  In Paris, they simply stared when I spoke to them in French;
  I never did succeed in making those idiots understand their
  own language.         - Mark Twain, The Innocent Abroad,1869

2. mod_jserv.so/tomcat/Apache

3. iptables only NATing the first udp packet in a "connection"

4. module symbol problems in 2.0.30

5. Assistance with NATing PPTP connections through OBSD router (longish)

6. OK FAQ not in the FAQ

7. Devin Nate -- Where are you?

8. Multiple opens of a single STREAMS device

9. User level NATing

10. Problems NATing PPP traffic on 3.1

11. Nate sucks - was Re: Uptime Discussion - longest current time since rebooting.

12. Setting up a VPN over multiple layer of nating??

13. FW stops NATing