Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #13531

Re: Home network - design ideas

From Tim Watts <tw_usenet@dionic.net>
Newsgroups comp.os.linux.misc
Subject Re: Home network - design ideas
Date 2015-01-31 23:43 +0000
Message-ID <uu50qb-p6c.ln1@squidward.dionic.net> (permalink)
References <jarupb-7ds.ln1@squidward.dionic.net> <slrnmcqf9g.f1q.ibuprofin@planck.phx.az.us>

Show all headers | View raw


On 31/01/15 20:37, Moe Trin wrote:

> By then, your ISP will be handing out IPv6 blocks, and the smallest one
> the IETF contemplates being handed out to end customers is a /64 which
> gives you 1.845 x10^19 addresses - that's enough to let you set up 4.29
> billion /96 subnets - each being as large as all IPv4 space. Non-problem.

I have to confess, mine gave me a block many years ago. I got it working 
once to "prove a point" - but for now I've disabled IPv6 on my clients 
as it was causing issues - partly because I don't fully "get" the setup 
and partly because external existence is limited.

One day...

>> Option 2
>
>> 2) My really public stuff (like IPCams, servers, home automation) on /27
>
> Color me paranoid, but does all of that really need to be accessible from
> the world?   Given the current standard of security being displayed by
> the home automation community, I'd be VERY hesitant to make them
> accessible.  (Heck, there is a folded piece of duct-tape covering the
> lens of the built-in camera on the lap-tops, only moved out of the way
> when I intentionally want to use the it,)

I agree with your sentiments - but I really have a hang up about NAT - I 
view it as a very dirty "if needs must" option. Possibly been spoilt, 
working for places with multiple /16 allocations adn zero NATing - but 
whilst I agree that HA and IPCams are notoriously weak, I still prefer 
to work without NAT and limit the damage with firewalls.

It's partly because I cannot assume I will always have a VPN client (the 
classic solution) to hand - so it's a trade off between a bit of 
firewalling and practical easy access. Probably not helped by the few 
VPNs I've been forced to use for work had setups that sucked. For my 
work, I punch a load of ssh tunnels through and it's way easier to work 
with.

>> Con: Certain Internal-Internal traffic gets routed so will bottleneck
>
> Ohhhh, the freeway is narrowing down from 12 lanes in this direction to
> only 11 - that might cause congestion in Los Angeles, but is not likely
> to be a problem in other metropolitan areas.   As your hosts don't all
> have point-to-point connections to all other hosts, you've already got a
> bottleneck in those switches - but I don't see it as a PRACTICAL problem.

Point taken - it WAS a real problem when my router was a Linksys WRT54GS 
- that could only route (or do anything) at 100Mbits. I have an internal 
drive to optimise - perhaps sometimes when it is not full justified - 
I'll admit that.

>> Option 3
>
>> 1) Visitor network on say 10.0.1.x, NATed
>> 2) All my stuff on private, 10.0.0.x NATed
>> 3) Router does IP translation from /27 to 10.0.0.x for public stuff
>
>> Pro: Fast switching for Internal-Internal
>
> Above - there is an insignificant bottleneck
>
>> Con: Needs either split-DNS (have this now, do not like it) OR the
>> router will end up doing reflection-translation for Internal-Internal
>
> I suppose it depends on how dynamic the hosts are.  MOST of my internal
> hosts are fixed (and have fixed addresses/hostnames), and don't go
> "walkies" often enough to worry about.   The truly dynamic stuff is on
> a separate sub-net, but they don't offer services, so a DDNS slaved to
> the DHCP server is sufficient.
>
>> Con: I just don't like it. I am very much pro using public IPs as the
>> Internet originally intended. I hate NAT but it is OK for misc visitor
>> stuff. Prefer to have my regular kit on public IPs and clean.
>
> When the Internet was originally developed, the user community was much
> smaller, more professional, and better behaved.

Yes - indeed. It's sad but inevitable - and the russian IPCam hackery is 
not lost on me...

> While there were
> rather enormous security holes, they were rarely exploited because
> people didn't think of them, and/or had the good sense to not try to
> exploit them.   If you scan the "Risks Digest" (news://comp.risks/), I
> am no longer amazed at the wide-spread lack of common-sense security.
> Why the control computers at the Smithfield Nuclear Power plant need to
> be accessible from the world at large...  so the local stores, bars or
> whatever can upload pictures (and targeted advertisements) of the
> products they are delivering to Homer Simpson for his approval?
>
> Your option 2 (public stuff on the /27, everything else NATed) is likely
> the best choice if you have a lot of public stuff - otherwise, I'd go
> with option 3, which reduces exposure, but at the cost of extra CPU
> cycles on the router doing NAT.  It's probably not a bandwidth issue.

Thank you for your thoughts - All good things to think about...

Back to comp.os.linux.misc | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 11:36 +0000
  Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 18:23 +0000
    Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 20:02 +0000
      Re: Home network - design ideas Chick Tower <c.tower@deadspam.com> - 2015-02-03 20:17 +0000
        Re: Home network - design ideas The Natural Philosopher <tnp@invalid.invalid> - 2015-02-03 20:33 +0000
        Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-02-03 20:47 +0000
  Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-01-31 20:37 +0000
    Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 22:24 +0000
      Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:21 +0000
        Re: Home network - design ideas John Hasler <jhasler@newsguy.com> - 2015-02-01 10:52 -0600
          Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 20:42 +0000
            Re: Home network - design ideas Marc Haber <mh+usenetspam1118@zugschl.us> - 2015-02-02 07:24 +0100
    Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 23:43 +0000
      Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:23 +0000

csiph-web