<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: NAT behind NAT not a bad thing ? in Wireless Service Providers</title>
<link>http://www.dslreports.com/forum/r17707135</link>
<description></description>
<language>en</language>
<pubDate>Wed, 02 Dec 2009 16:35:24 EDT</pubDate>
<lastBuildDate>Wed, 02 Dec 2009 16:35:24 EDT</lastBuildDate>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17722277</link>
<description><![CDATA[<A HREF="/useremail/u/901298"><b>Semaphore</b></A> : For reasons that are not explainable (e.g. I still don't understand why they wanted it like that) I've done quadruple bi-directional 1:1 (Static) NAT before with almost any protocol/application you care to think of running across that link.  Everything works, but if there is a problem, troubleshooting is WAY beyond difficult. Bridge if you can. NAT if you must.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17722277</guid>
<pubDate>Sat, 27 Jan 2007 19:00:05 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17719810</link>
<description><![CDATA[<A HREF="/useremail/u/1027543"><b>Airplane777</b></A> : I got the customer to leave the CPE turned on.  That should keep it a little warmer now.<br><br>Where do I go in the CPE GUI to change the port number you were talking about?<br><br>When I do try to log into this customers CPE, the window for the user name and password doesn't come up for login, like it does for my other customer.  Not sure why.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17719810</guid>
<pubDate>Sat, 27 Jan 2007 10:05:56 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17713567</link>
<description><![CDATA[<A HREF="/useremail/u/429429"><b>superdog</b></A> : Bob, In the winter months, I would push the customer to keep the radio on at all times. The radio itself only uses a few cents of electricity every month, so turning it off isn't really saving them a lot?, maybe $1 dollar a year if You are lucky?. I personally have not tried to fire up a DLB in our climate when it is cold out, so I have no clue what would happen?. I guess we will find out very soon huh?. :uhh:<br><SMALL>--<br>&raquo;<A HREF="http://www.wavecrazy.net" >www.wavecrazy.net</A> Join WISPA today! &raquo;<A HREF="http://www.wispa.org/" >www.wispa.org/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17713567</guid>
<pubDate>Fri, 26 Jan 2007 08:47:51 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17713534</link>
<description><![CDATA[<A HREF="/useremail/u/1027543"><b>Airplane777</b></A> : Thanks for that good info Tim.<br><br>I heard that the owner turns off her wireless router at night.  I'm hoping the CPE was also turned off (since it is on the same power strip).<br><br>In this cold weather, wouldn't it be best to keep the CPE powered all the time, so the CPE keeps warm?  If so, I'll tell the customer to keep it on.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17713534</guid>
<pubDate>Fri, 26 Jan 2007 08:41:17 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17713464</link>
<description><![CDATA[<A HREF="/useremail/u/429429"><b>superdog</b></A> : <div class="bquote"><SMALL>said by  Airplane777 <A HREF="/useremail/u/1027543"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Only one problem...tonight I tried to log into the CPE from my NOC.  I couldn't do it.  I can't even see the CPE at all on my AP GUI.  Now I'm worried.  Did the wind blow over my NPRM?<br><br>So I drove there about 30 minutes ago, to see if the tripod is still standing.  It was still there.  Looked ok.  <br><br> </DIV>Bob, The DLB2300's will sometimes lose their web interface on port 8080. I was told it is because so many idiots are scanning the web looking for open holes that the DLB just quits responding. What I would do is change the port# (It allows You to do this) and then Your issues will go away. There is also no need to drive all the way over there?. If this happens, just ping the radio and see if it replies?. If it does?, then ping the customers router (IF it is setup to answer a ping?. Most newer routers will not answer as a security feature?). If it replies too, then You know that everything is OK. :)<br><SMALL>--<br>&raquo;<A HREF="http://www.wavecrazy.net" >www.wavecrazy.net</A> Join WISPA today! &raquo;<A HREF="http://www.wispa.org/" >www.wispa.org/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17713464</guid>
<pubDate>Fri, 26 Jan 2007 08:22:07 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17712363</link>
<description><![CDATA[<A HREF="/useremail/u/1027543"><b>Airplane777</b></A> : Hello all:<br><br>Thanks for your info on NATing.  I set my CPE to bridge.<br><br>I had minimal problems in setting up the CPE in bridging mode, and using MAC authentication, WPA2, and hidden ssid.  I hooked it to my laptop and got on the Internet right away.<br><br>After that I had to set up the customers wireless router.  Even though I spell out in my TOS that my liability ends at the RJ45 plug coming from my CPE, I still took the time to set up the customers wireless router.  They had no idea how to do it.  It wasn't too bad. <br><br>I tested the wireless router using a pc card in my laptop, and it worked real good.<br><br>The next thing, the customer didn't know how to set up WEP in their wireless client device in their desktop computer.  I set that up.  I got lucky...lol.  It worked.<br><br>She had me set up WEP so her business neighbors can no longer steal her WiFi signal.  I showed her how to change the WEP code, so she can change it frequently, so her neighbors can't get on.<br><br>Only one problem...tonight I tried to log into the CPE from my NOC.  I couldn't do it.  I can't even see the CPE at all on my AP GUI.  Now I'm worried.  Did the wind blow over my NPRM?<br><br>So I drove there about 30 minutes ago, to see if the tripod is still standing.  It was still there.  Looked ok.  <br><br>I'm hoping the customer just turned off the power to the CPE...maybe to save power.  I hope the cold weather didn't kill my DLB2300...lol.  I'd hate to think I had a case of "infant mortality" on the CPE.<br><br>Gee...this is fun.  I want more customers...lol.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17712363</guid>
<pubDate>Thu, 25 Jan 2007 23:13:48 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17710459</link>
<description><![CDATA[<A HREF="/useremail/u/348012"><b>cmaenginsb</b></A> : By double or more NATing you increase the possibility of overlapping your NAT scheme with that used by the VPN user's company network.<br><br>IE if your house is on 192.168.1.x and your the LAN you VPN into is on 192.168.1.x you can and will have routing problems.  By increasing the number of NATed networks you increase the odds of winning the funky VPN traffic lottery.<br><SMALL>--<br>CCNA, Comtrain Certified Tower Climber</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17710459</guid>
<pubDate>Thu, 25 Jan 2007 17:51:05 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17710397</link>
<description><![CDATA[<A HREF="/useremail/u/1219823"><b>lutful</b></A> : <div class="bquote"><SMALL>said by  Airplane777 <A HREF="/useremail/u/1027543"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>This causes me to be doing NAT behind NAT.  Am I correct in thinking that this should work ok?  That is...NAT behind NAT, isn't necessarily a bad thing?<br></DIV>I setup a few tiny rural networks this way - to the best of my recollection - in 2004/5:<br><br>A DSL home's NAT router (10.1.1.1) to wireless backhaul to  rural home's NAT router (10.2.1.1) to broadcast AP to multiple CPEs and NAT routers (10.3.1.1). <br><br>Each NAT router has at least one local customer PC served by DHCP. The wisp radios are on static IP for easier management.<br><br>We usually hardcode good DNS server addresses at NAT routers but leaving them as 10.x.1.1 also works as most NAT routers implement DNS caching. <br><br>It works for all common internet apps including most VoIP and some VPN. GoToMyPC and VNC also works.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17710397</guid>
<pubDate>Thu, 25 Jan 2007 17:39:50 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17710044</link>
<description><![CDATA[<A HREF="/useremail/u/1259526"><b>Wisp</b></A> : We do it like Superdog says, NAT at the NOC, all aps are bridged, and then NAT again at the CPE. So far it's been ok.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17710044</guid>
<pubDate>Thu, 25 Jan 2007 16:40:10 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17708041</link>
<description><![CDATA[<A HREF="/useremail/u/1027543"><b>Airplane777</b></A> : Thank you superdog, robbin, & cmaenginsb:<br><br>Bridging it is.<br><br>I had to do some thinking since this commercial establishment had their own wireless router.  Your ideas on me doing bridging makes sense.  So I just got done setting up a test DLB 2300 in bridge mode (just to make sure I can do it quickly on the clients CPE).<br><br>I finally got the CAT5 run yesterday.  I'm using NPRM with my tripod tapconned to some concrete patio blocks, which are sitting on 3 rubber mats.  Seems to work pretty good.  I still may go up and put a sand bag on each concrete block.  I'm hoping it will take a lot of wind without blowing over...lol.<br><br>This stuff is fun...especially when I was crawling around on the roof setting up the tripod when it was snowing a few days ago.<br><br>To make it even more fun, I'm doing MAC authentication, hidden SSID, and WPA 2...lol.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17708041</guid>
<pubDate>Thu, 25 Jan 2007 11:01:35 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17707135</link>
<description><![CDATA[<A HREF="/useremail/u/429429"><b>superdog</b></A> : <div class="bquote"><SMALL>said by  Airplane777 <A HREF="/useremail/u/1027543"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>How do you get those public static IPs through your edge router (since I assume your edge router is NATed)? You do some kind of port forwarding?  (Isn't an edge router the one connected directly to the modem that goes to the Internet backbone?)  Or do you do bridging of your edge router also?<br> </DIV>Bob, when You have a T1 or larger to the net, all of us use a router at the edge that basically bridges all of our static IP's right thru to the end user or at least to the CPE. If You are using DSL as a backhaul, You may only have 1 real world IP?, and that is used in Your modem. If that is the case?, You would then in all reality be NAT'ing 3 times?. Once at Your NOC, once at the CPE and then the 3rd time on Your customers router. This is a really bad idea. While I have seen VPN's work thru 2 NAT boxes, I have also seen some strange things happen to programs like Citrix(allows You to use a local computer to run a remote one across a VPN and special software). I would use that DLB2300 or Highgain CPE as a bridge. That way You are at least only NAT'ing twice. Once at the NOC(modem) and then again on the customers router. :)<br><SMALL>--<br>&raquo;<A HREF="http://www.wavecrazy.net" >www.wavecrazy.net</A> Join WISPA today! &raquo;<A HREF="http://www.wispa.org/" >www.wispa.org/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17707135</guid>
<pubDate>Thu, 25 Jan 2007 07:06:39 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17706729</link>
<description><![CDATA[<A HREF="/useremail/u/205331"><b>robbin</b></A> : Well, to start with, I use Trango equipment. The AP / SU (CPE) link is a bridge (no choices). It's hard to explain if you are used to WIFI equipment but basically my APs and CPEs do not exist on the client to internet network -- they are totally invisible. So whatever I do with them has no effect on the IP address assignment of the client router.<br><br>I am currently 100% bridged. As I get larger, if I decide to grow that much, I will probably do 1 to 1 NAT. Many (perhaps the majority) of my customers use a VPN on a regular basis and there has never been a problem for them. They are extremely grateful as this means that they don't have to drive 75 to 100 miles on the days they work from home!<br><br>My edge router is my T1 router -- you don't need a modem for a T1, only for DSL.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17706729</guid>
<pubDate>Thu, 25 Jan 2007 02:01:37 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17706704</link>
<description><![CDATA[<A HREF="/useremail/u/348012"><b>cmaenginsb</b></A> : Airplane, robbin uses Trango equipment which only works as a bridge.<br><br>As to the edge router, most of us simply don't have the edge router set to NAT.  <br><br>I haven't seen a problem with double NAT yet but in theory I would think VPNs could be an issue depending on the subnets used for each.<br><br>Why not turn NAT off in your CPE?<br><SMALL>--<br>CCNA, Comtrain Certified Tower Climber</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17706704</guid>
<pubDate>Thu, 25 Jan 2007 01:50:48 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17706683</link>
<description><![CDATA[<A HREF="/useremail/u/1027543"><b>Airplane777</b></A> : Hi robbin:<br><br>Thanks for your post.<br><br>Since you give public static IPs to your clients, I assume your CPEs are then set to bridging-client mode?  I'm trying to get this bridging and client stuff streight in my head...lol.<br><br>How do you get those public static IPs through your edge router (since I assume your edge router is NATed)? You do some kind of port forwarding?  (Isn't an edge router the one connected directly to the modem that goes to the Internet backbone?)  Or do you do bridging of your edge router also?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17706683</guid>
<pubDate>Thu, 25 Jan 2007 01:40:17 EDT</pubDate>
</item>

<item>
<title>Re: NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17706664</link>
<description><![CDATA[<A HREF="/useremail/u/205331"><b>robbin</b></A> : I would be concerned if they use VPN -- I understand double NAT can give it problems. I provide public static IPs so I don't have any first hand knowledge.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17706664</guid>
<pubDate>Thu, 25 Jan 2007 01:32:58 EDT</pubDate>
</item>

<item>
<title>NAT behind NAT not a bad thing ?</title>
<link>http://www.dslreports.com/forum/remark,17706397</link>
<description><![CDATA[<A HREF="/useremail/u/1027543"><b>Airplane777</b></A> : I will be hooking up my first commercial WISP customer Thursday afternoon.  <br><br>I will be connecting the WAN side of their wireless router to the LAN side of my CPE.  Their wireless router does NATing and DHCP. <br><br>But my CPE is also set up to do NATing.  I will be providing a private static IP address to their wireless router. <br><br>This causes me to be doing NAT behind NAT.  Am I correct in thinking that this should work ok?  That is...NAT behind NAT, isn't necessarily a bad thing?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17706397</guid>
<pubDate>Thu, 25 Jan 2007 00:15:31 EDT</pubDate>
</item>

</channel>
</rss>
