All of lore.kernel.org
 help / color / mirror / Atom feed
From: Shawn <core@enodev.com>
To: 'Netfilter Mailing List' <netfilter@lists.netfilter.org>
Subject: Re: Routing Public IPs over NAT Address Space
Date: 14 Jul 2003 17:38:24 -0500	[thread overview]
Message-ID: <1058222304.24132.166.camel@localhost> (raw)
In-Reply-To: <000901c34a54$be16cf20$0f00a8c0@tandem>

To follow up on a private reply, it can be troublesome to have NAT
gateways in between the big "I" and customers anyway.

I think what you're saying is you want your linux router to forward
public subnets to private subnets over at some customer site. Problem
is, if they want to administer their own DNS, they have to figure out
how to correctly configure DNS views, so internal resolvers don't
resolve to external addresses, etc etc. BIG TROUBLE!!!

I suggest simply routing whatever public traffic, or, in addition to
that, implement an MPLS infrastructure if you/they care about privacy.

On Mon, 2003-07-14 at 17:10, A. Clausen wrote:
> ----- Original Message ----- 
> From: "Shawn" <core@enodev.com>
> To: <techlists@alberni.net>
> Cc: "Netfilter Mailing List" <netfilter@lists.netfilter.org>
> Sent: Monday, July 14, 2003 13:23
> Subject: Re: Routing Public IPs over NAT Address Space
> 
> 
> > Please describe precisely, what you want to accomplish. An example:
> >
> > I would like for hosts out on the public internet to be able to connect
> > to my nnn.nnn.nnn.0/24 through my router, whose internet facing
> > interface is responsible for routing said nnn.nnn.nnn.0/24, but where
> > nnn.nnn.nnn.0/24 lies across some 10.0.0.0/24 which is "directly
> > connected" to the other interface of said router.
> >
> > There are folks out there that would like to help you, but if you can't
> > be bothered to take the time to describe your question with enough
> > specificity (and with correct terms), no one can help.
> 
> Sorry about that.  I'll be more specific.
> 
> I work for a small ISP, and we are selling residential and business wireless
> service.  Thus far, using iptables NAT, we've had no problems.  It works
> well and permits MSN Messenger and the like to work.  For those people who
> want a public IP, I simply do forwarding, and this works very well.
> 
> However, we've had some inquiries about a few businesses who want actual
> subnets (for mail servers, web servers, or whatever).  The problem with NAT
> is that I can't guarantee there will be a helper for every protocol.  What I
> was wondering was whether I could allocate a subnet and get it across the
> private (NAT) network to their router.  I have my doubts as to whether this
> is possible, but not being an expert I thought I'd ask.
> 
> My thoughts are that VPN may be the way to go.


  reply	other threads:[~2003-07-14 22:38 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-07-14 17:52 Routing Public IPs over NAT Address Space Aaron Clausen
2003-07-14 18:10 ` Shawn
2003-07-14 19:57 ` Rowan Reid
2003-07-14 20:23 ` Shawn
2003-07-14 20:35   ` Aldo S. Lagana
2003-07-14 20:49     ` Shawn
2003-07-14 22:10       ` A. Clausen
2003-07-14 22:38         ` Shawn [this message]
  -- strict thread matches above, loose matches on Subject: below --
2003-07-15  0:23 Daniel Chemko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1058222304.24132.166.camel@localhost \
    --to=core@enodev.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.