[Sussex] Just a bit of news

Steve Dobson steve at dobson.org
Wed Jul 21 09:42:40 UTC 2004


Mike / Gareth

On Wed, Jul 21, 2004 at 09:43:58AM +0100, Gareth Ablett wrote:
> Mike, 
> 
> If you are going to get a router I'd just like to add to Angelo's advice
> and tell you that I hate Thomson (Alctel) router's they one I got is
> complete crap.
> I would recommend a linksys router though.

I have a Thomson SpeedTouch 510 and it works just fine - I don't know
why Gareth dislikes them.  Okay, you need windows to access some of the
advanced config features easterly, but you can do it all from Linux (I
have).  But to be honest I you don't need those features anyway.  If you
are going to run a firewall between you LAN and the Internet (and you 
should) then the web interface has more than enough feature access for
want you need.

I probably have one of the more complex networks in the group.  I signed
up with Zen and as they offered a block of 8 IP addresses for the same
prices one I when for the 8.

My network structure looks like this:

                        | ADSL to Zen
                  +-----+-----+
                  |  Thomson  |
                  | SpeedTouch|
                  |    510    |
                  +--+-+-+-+--+
                     | | | | 
                     | | | +---) Spare
                     | | +-----) RJ45   Not used.
                     | +-------) Ports
                     |
    To my LAN -----+ | +--------- To my DNZ
                   | | |
              +----+-+-+-----+
              | Soekris 4810 |
              |  Firewall    |
              |  (Debian)    |
              +--------------+

The LAN is running on the 10.x.x.x network with the firewall doing
Source Network Address Translation (SNAT) [Masquerading is slower than
SNAT and not needed when the IP address is fixed].

At the moment the DNZ is on the 192.168.x.x private network with the
firewall doing SNAT and DNAT (Destination NAT) but that has complicated
my firewall rules so I plan to change over to using the firewall as a 
bridge between those two network segments.

Steve




More information about the Sussex mailing list