Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #13528
| From | Tim Watts <tw_usenet@dionic.net> |
|---|---|
| Newsgroups | comp.os.linux.misc |
| Subject | Re: Home network - design ideas |
| Date | 2015-01-31 20:02 +0000 |
| Message-ID | <nvovpb-sn9.ln1@squidward.dionic.net> (permalink) |
| References | <jarupb-7ds.ln1@squidward.dionic.net> <maj6jp$jl4$3@dont-email.me> |
On 31/01/15 18:23, William Unruh wrote: > On 2015-01-31, Tim Watts <tw_usenet@dionic.net> wrote: >> Hiya, >> >> This is not a "how do I do this" - that's not a problem. >> >> I'd just like to bat an idea or two as I have a couple of ways and I >> cannot decide which is best... >> >> OK - I have a /27 IPv4 public block (yay for good ISPs!) >> That's enough for: >> >> 4, later 5 servers >> Various IP cams >> Several laptops >> Various infrastructure > > And then you always have 2^24 address block in the 10. /8 address block, > plus NAT. Why would yo uwant your IP cams, etc on a public IP address? > So I can view them without buggering about with VPN on a smartphone. Let's assume I will firewall them to my usual networks (quite wide in the case of my mobile 3G) and I might put an apache proxy in front of them with authentication. >> >> But not enough for every ad hoc smartphone and visitor items. >> >> My PPPoE endpoint *and* router *and* firewall is a linux box, Atom >> MiniITX that can manage gigabit throughput. >> >> Switches are NetGear gigabit SmartSwitches >> >> >> So - Option 1 >> ============= >> >> 1) Visitor network on say 10.0.1.x, NATed >> 2) My stuff on /27 including infrastructure like wifi, switches etc >> 3) Ad hoc smartphones etc use visitor net >> >> Pro: Clean and simple >> Pro: Internal-Internal traffic is switched (fast, no real bottleneck) >> >> Con: Might still might hit the /27 limit one day > > Do you recall the adage of computer purchasing. Only purchase today what > you need for today. Tomorrow it will be 1/100 the price and with options > you never thought of. Good point. Also, though, plan for the future :) >> Con: Still need to NAT all my Netflix devices as Unblock-US only works >> with one client IP >> >> Option 2 >> ======== >> >> 1) Visitor network on say 10.0.1.x, NATed >> 2) My really public stuff (like IPCams, servers, home automation) on /27 >> 3) My other stuff on another private, say 10.0.0.x, NATed > > You can do what you want with 10.x You have 2^24 different addresses. > How you arrange then is up to you. (Mind you NATing 2^24 systems at once > might be a bit tricky). > >> >> Pro: Unlimited local IPs and I will NOT hit the end of a /27 for my >> public stuff >> >> Con: Certain Internal-Internal traffic gets routed so will bottleneck > > All stuff gets routed, whether internal or external. 10.0.0.x vs > 10.0.1.x is no different from 10.0.0.123 vs 10.0.0.124 > > Unless you make it different internally. Well, except the latter get *switched* which is a lot more efficient - my switches can handle several gig on the backplane - my router (aka linux box) will be sharing the 1gig in and back out to the same physical network... > >> >> Option 3 >> ======== >> 1) Visitor network on say 10.0.1.x, NATed >> 2) All my stuff on private, 10.0.0.x NATed >> 3) Router does IP translation from /27 to 10.0.0.x for public stuff > >> >> Pro: Fast switching for Internal-Internal >> >> Con: Needs either split-DNS (have this now, do not like it) OR the >> router will end up doing reflection-translation for Internal-Internal >> >> Pro: Saves one IP that would otherwise be used on the router at the gateway >> >> Pro: Very flexible. >> >> Con: I just don't like it. I am very much pro using public IPs as the >> Internet originally intended. I hate NAT but it is OK for misc visitor >> stuff. Prefer to have my regular kit on public IPs and clean. > > ??? NAT is "as originally intended" And IPV6 would allow you huge > amounts of IP space. But would not solve the routing bottlenecks. I do have IPv6 block too - but not yet configured it as too few other places support it - but one day... >> What would you do? > > Stop worrying. > :) Thanks for your reply - I have more to add but my spag bol is nearly ready so I must run and reply again later...
Back to comp.os.linux.misc | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 11:36 +0000
Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 18:23 +0000
Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 20:02 +0000
Re: Home network - design ideas Chick Tower <c.tower@deadspam.com> - 2015-02-03 20:17 +0000
Re: Home network - design ideas The Natural Philosopher <tnp@invalid.invalid> - 2015-02-03 20:33 +0000
Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-02-03 20:47 +0000
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-01-31 20:37 +0000
Re: Home network - design ideas William Unruh <unruh@invalid.ca> - 2015-01-31 22:24 +0000
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:21 +0000
Re: Home network - design ideas John Hasler <jhasler@newsguy.com> - 2015-02-01 10:52 -0600
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 20:42 +0000
Re: Home network - design ideas Marc Haber <mh+usenetspam1118@zugschl.us> - 2015-02-02 07:24 +0100
Re: Home network - design ideas Tim Watts <tw_usenet@dionic.net> - 2015-01-31 23:43 +0000
Re: Home network - design ideas Moe Trin <ibuprofin@painkiller.example.tld.invalid> - 2015-02-01 16:23 +0000
csiph-web