Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #13531
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Newsgroups | comp.os.linux.misc |
| Subject | Re: Home network - design ideas |
| Date | 2015-01-31 23:43 +0000 |
| Message-ID | <uu50qb-p6c.ln1@squidward.dionic.net> (permalink) |
| References | <jarupb-7ds.ln1@squidward.dionic.net> <slrnmcqf9g.f1q.ibuprofin@planck.phx.az.us> |
On 31/01/15 20:37, Moe Trin wrote: > By then, your ISP will be handing out IPv6 blocks, and the smallest one > the IETF contemplates being handed out to end customers is a /64 which > gives you 1.845 x10^19 addresses - that's enough to let you set up 4.29 > billion /96 subnets - each being as large as all IPv4 space. Non-problem. I have to confess, mine gave me a block many years ago. I got it working once to "prove a point" - but for now I've disabled IPv6 on my clients as it was causing issues - partly because I don't fully "get" the setup and partly because external existence is limited. One day... >> Option 2 > >> 2) My really public stuff (like IPCams, servers, home automation) on /27 > > Color me paranoid, but does all of that really need to be accessible from > the world? Given the current standard of security being displayed by > the home automation community, I'd be VERY hesitant to make them > accessible. (Heck, there is a folded piece of duct-tape covering the > lens of the built-in camera on the lap-tops, only moved out of the way > when I intentionally want to use the it,) I agree with your sentiments - but I really have a hang up about NAT - I view it as a very dirty "if needs must" option. Possibly been spoilt, working for places with multiple /16 allocations adn zero NATing - but whilst I agree that HA and IPCams are notoriously weak, I still prefer to work without NAT and limit the damage with firewalls. It's partly because I cannot assume I will always have a VPN client (the classic solution) to hand - so it's a trade off between a bit of firewalling and practical easy access. Probably not helped by the few VPNs I've been forced to use for work had setups that sucked. For my work, I punch a load of ssh tunnels through and it's way easier to work with. >> Con: Certain Internal-Internal traffic gets routed so will bottleneck > > Ohhhh, the freeway is narrowing down from 12 lanes in this direction to > only 11 - that might cause congestion in Los Angeles, but is not likely > to be a problem in other metropolitan areas. As your hosts don't all > have point-to-point connections to all other hosts, you've already got a > bottleneck in those switches - but I don't see it as a PRACTICAL problem. Point taken - it WAS a real problem when my router was a Linksys WRT54GS - that could only route (or do anything) at 100Mbits. I have an internal drive to optimise - perhaps sometimes when it is not full justified - I'll admit that. >> Option 3 > >> 1) Visitor network on say 10.0.1.x, NATed >> 2) All my stuff on private, 10.0.0.x NATed >> 3) Router does IP translation from /27 to 10.0.0.x for public stuff > >> Pro: Fast switching for Internal-Internal > > Above - there is an insignificant bottleneck > >> Con: Needs either split-DNS (have this now, do not like it) OR the >> router will end up doing reflection-translation for Internal-Internal > > I suppose it depends on how dynamic the hosts are. MOST of my internal > hosts are fixed (and have fixed addresses/hostnames), and don't go > "walkies" often enough to worry about. The truly dynamic stuff is on > a separate sub-net, but they don't offer services, so a DDNS slaved to > the DHCP server is sufficient. > >> Con: I just don't like it. I am very much pro using public IPs as the >> Internet originally intended. I hate NAT but it is OK for misc visitor >> stuff. Prefer to have my regular kit on public IPs and clean. > > When the Internet was originally developed, the user community was much > smaller, more professional, and better behaved. Yes - indeed. It's sad but inevitable - and the russian IPCam hackery is not lost on me... > While there were > rather enormous security holes, they were rarely exploited because > people didn't think of them, and/or had the good sense to not try to > exploit them. If you scan the "Risks Digest" (news://comp.risks/), I > am no longer amazed at the wide-spread lack of common-sense security. > Why the control computers at the Smithfield Nuclear Power plant need to > be accessible from the world at large... so the local stores, bars or > whatever can upload pictures (and targeted advertisements) of the > products they are delivering to Homer Simpson for his approval? > > Your option 2 (public stuff on the /27, everything else NATed) is likely > the best choice if you have a lot of public stuff - otherwise, I'd go > with option 3, which reduces exposure, but at the cost of extra CPU > cycles on the router doing NAT. It's probably not a bandwidth issue. Thank you for your thoughts - All good things to think about...
Back to comp.os.linux.misc | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 11:36 +0000
Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 18:23 +0000
Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 20:02 +0000
Re: Home network - design ideas Chick Tower <c.tower@deadspam.com> - 2015-02-03 20:17 +0000
Re: Home network - design ideas The Natural Philosopher <tnp@invalid.invalid> - 2015-02-03 20:33 +0000
Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-02-03 20:47 +0000
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-01-31 20:37 +0000
Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 22:24 +0000
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:21 +0000
Re: Home network - design ideas John Hasler <jhasler@newsguy.com> - 2015-02-01 10:52 -0600
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 20:42 +0000
Re: Home network - design ideas Marc Haber <mh+usenetspam1118@zugschl.us> - 2015-02-02 07:24 +0100
Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 23:43 +0000
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:23 +0000
csiph-web