New Zealand ADSL Mailing List


Re: M1122 routing confusion.

From: Alex King <alex_at_king.net.nz>
Date: Tue, 15 Jul 2003 09:41:20 +1200
Message-ID: <20030714214120.GB32508@king.net.nz>

What you're looking for can't really be done. There is a fundamental
difference between DSL routers and modems, which isn't really that well
understood generally.

As you know, in NZ telecom use PPPoA, which means there is a ppp
connection. At one end of the ppp connection is telecom, at the other
is your router or computer, which is assigned a real internet IP. If
you have a modem, the real IP is assigned to your computer. If you have
a router, the real IP is assigned to the router, and there is a private
IP subnet between you and the router (usually 192.168.x.y addresses)

If you want complete control of the connection, you need a modem, not a
router.

If you have a router, it will do NAT so you can access the internet, and
your computer is not directly accessable from the internet (so there is
a security advantage). Usually, routers can forward certain incomming
tcp or udp packets to the internal machine (NATing again). If the
routers firmware is not up to scratch though, there is stuff all you can
do about it. A router will never have the flexibility of a linux box
with a modem (unless it is a linux box with a modem, and you can reload
the software).

Most external boxes are routers, and all internal boxes are modems.
However there are some external boxes that are modems, eg, with usb
connections, or that do conversions between PPPoA and PPPoE or PPPPoA
and PPTP, thereby terminating the PPP session on the linux box.

In answer to your questions, you can't use your M1122 as a modem and
terminate the PPP session on your linux box, it isn't designed that way.
AFAIK, there is no way to forward all incomming tcp and udp connections
to an internal machine (I could be wrong, it's a long time since they
played with them). I doubt a firmware upgrade will help much.

However, if all you want is a better firewall, there is no reason why
you can't use a linux box doing NAT & packet filtering or proxying
between the router and your internal network.

Cheers,

Alex

On Mon, Jul 14, 2003 at 07:12:24PM +0000, Chris Smith wrote:
> Hi Guys,
>
> Long time reader, first time poster etc...
>
> I'm the owner of a M1122 ADSL Modem/Gateway/Router box. Which is connected to
> my Linux server which provides internet/email for the household. Recently,
> I've lost faith in the security of the ADSL router and its firewalling
> capabilities, and decided I would let Linux's firewall take care of the
> security side of things.
>
> So I've been poking around in the HTTP configuration screens for this modem,
> and have tried a few things, but I just can't get the router to forward all
> connections it recieves to my linux box. I rang Xtra's helpdesk, but as soon
> as I mentioned Linux, they didn't want to know, even though it was help with
> the modem I needed.
>
> Also, I looked at the firmware version and saw it was .V04 and I remember
> reading somewhere that the latest was .V09 Where can I obtain this upgrade,
> and do I really need to do it?
>
> Thanks in advance,
> Chris.
>
> --
> This message is part of the NZ ADSL mailing list.
> see http://unixathome.org/adsl/ for archives, FAQ,
> and various documents.
> To unsubscribe: send mail to majordomo@lists.unixathome.org
> with "unsubscribe adsl" in the body of the message
>

-- 
This message is part of the NZ ADSL mailing list. 
see http://unixathome.org/adsl/ for archives, FAQ, 
and various documents. 
To unsubscribe: send mail to majordomo@lists.unixathome.org 
with "unsubscribe adsl" in the body of the message 
 
Received on Tue Jul 15 09:41:36 2003

This archive was generated by hypermail 2.2.0 : Thu Nov 30 11:48:25 2006 EST