Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #13528

Re: Home network - design ideas

From Tim Watts <tw_usenet@dionic.net>
Newsgroups comp.os.linux.misc
Subject Re: Home network - design ideas
Date 2015-01-31 20:02 +0000
Message-ID <nvovpb-sn9.ln1@squidward.dionic.net> (permalink)
References <jarupb-7ds.ln1@squidward.dionic.net> <maj6jp$jl4$3@dont-email.me>

Show all headers | View raw


On 31/01/15 18:23, William Unruh wrote:
> On 2015-01-31, Tim Watts <tw_usenet@dionic.net> wrote:
>> Hiya,
>>
>> This is not a "how do I do this" - that's not a problem.
>>
>> I'd just like to bat an idea or two as I have a couple of ways and I
>> cannot decide which is best...
>>
>> OK - I have a /27 IPv4 public block (yay for good ISPs!)
>> That's enough for:
>>
>> 4, later 5 servers
>> Various IP cams
>> Several laptops
>> Various infrastructure
>
> And then you always have 2^24 address block in the 10. /8 address block,
> plus NAT. Why would yo uwant your IP cams, etc on a public IP address?
>

So I can view them without buggering about with VPN on a smartphone.

Let's assume I will firewall them to my usual networks (quite wide in 
the case of my mobile 3G) and I might put an apache proxy in front of 
them with authentication.

>>
>> But not enough for every ad hoc smartphone and visitor items.
>>
>> My PPPoE endpoint *and* router *and* firewall is a linux box, Atom
>> MiniITX that can manage gigabit throughput.
>>
>> Switches are NetGear gigabit SmartSwitches
>>
>>
>> So - Option 1
>> =============
>>
>> 1) Visitor network on say 10.0.1.x, NATed
>> 2) My stuff on /27 including infrastructure like wifi, switches etc
>> 3) Ad hoc smartphones etc use visitor net
>>
>> Pro: Clean and simple
>> Pro: Internal-Internal traffic is switched (fast, no real bottleneck)
>>
>> Con: Might still might hit the /27 limit one day
>
> Do you recall the adage of computer purchasing. Only purchase today what
> you need for today. Tomorrow it will be 1/100 the price and with options
> you never thought of.

Good point.

Also, though, plan for the future :)

>> Con: Still need to NAT all my Netflix devices as Unblock-US only works
>> with one client IP
>>
>> Option 2
>> ========
>>
>> 1) Visitor network on say 10.0.1.x, NATed
>> 2) My really public stuff (like IPCams, servers, home automation) on /27
>> 3) My other stuff on another private, say 10.0.0.x, NATed
>
> You can do what you want with 10.x You have 2^24 different addresses.
> How you arrange then is up to you. (Mind you NATing 2^24 systems at once
> might be a bit tricky).
>
>>
>> Pro: Unlimited local IPs and I will NOT hit the end of a /27 for my
>> public stuff
>>
>> Con: Certain Internal-Internal traffic gets routed so will bottleneck
>
> All stuff gets routed, whether internal or external. 10.0.0.x vs
> 10.0.1.x is no different from 10.0.0.123 vs 10.0.0.124
>
> Unless you make it different internally.

Well, except the latter get *switched* which is a lot more efficient - 
my switches can handle several gig on the backplane - my router (aka 
linux box) will be sharing the 1gig in and back out to the same physical 
network...

>
>>
>> Option 3
>> ========
>> 1) Visitor network on say 10.0.1.x, NATed
>> 2) All my stuff on private, 10.0.0.x NATed
>> 3) Router does IP translation from /27 to 10.0.0.x for public stuff
>
>>
>> Pro: Fast switching for Internal-Internal
>>
>> Con: Needs either split-DNS (have this now, do not like it) OR the
>> router will end up doing reflection-translation for Internal-Internal
>>
>> Pro: Saves one IP that would otherwise be used on the router at the gateway
>>
>> Pro: Very flexible.
>>
>> Con: I just don't like it. I am very much pro using public IPs as the
>> Internet originally intended. I hate NAT but it is OK for misc visitor
>> stuff. Prefer to have my regular kit on public IPs and clean.
>
> ??? NAT is "as originally intended" And IPV6 would allow you huge
> amounts of IP space. But would not solve the routing bottlenecks.

I do have IPv6 block too - but not yet configured it as too few other 
places support it - but one day...

>> What would you do?
>
> Stop worrying.
>

:)

Thanks for your reply - I have more to add but my spag bol is nearly 
ready so I must run and reply again later...

Back to comp.os.linux.misc | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 11:36 +0000
  Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 18:23 +0000
    Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 20:02 +0000
      Re: Home network - design ideas Chick Tower <c.tower@deadspam.com> - 2015-02-03 20:17 +0000
        Re: Home network - design ideas The Natural Philosopher <tnp@invalid.invalid> - 2015-02-03 20:33 +0000
        Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-02-03 20:47 +0000
  Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-01-31 20:37 +0000
    Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 22:24 +0000
      Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:21 +0000
        Re: Home network - design ideas John Hasler <jhasler@newsguy.com> - 2015-02-01 10:52 -0600
          Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 20:42 +0000
            Re: Home network - design ideas Marc Haber <mh+usenetspam1118@zugschl.us> - 2015-02-02 07:24 +0100
    Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 23:43 +0000
      Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:23 +0000

csiph-web