Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Wireless Security » Using two routers for securtity without double NAT
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Hiding unsecured wireless networks »
« Linksys Router Daisy Chained to a Netgear RT314  
AuthorAll Replies

apara0

join:2005-07-03
La Crescenta, CA

reply to janderso1
Re: Using two routers for securtity without double

With the NAT disabled in R2, 192.168.8.0 addresses reach R1 and then use R1's NAT to go out to the internet?

So there is still a firewall even with NAT disabled? I always thought that NAT was the firewall in most routers. I guess the SPI firewall is separate from NAT and still does not allow arbitrary traffic INTO the router?

Thanks.
-AP_


janderso1
Jim
Premium,MVM
join:2000-04-15
Saint Petersburg, FL

Yes, R1 must do NAT for both subnets (not all routers will doe this, the ones I mentioned will). On the Zyxel routers you can enable/disable NAT and the SPI firewall separately. You may be able to do this with some of the Linksys routers.
--
Jim Anderson

seezar
Premium
join:2001-07-01
Rochester, NY
·ViaTalk


2 edits
You could always get a soekris box (net4801) for about $275, »www.soekris.com/ which has a WAN port and 2 LAN ports and then run M0n0wall on it, »m0n0.ch/wall/ . I have my wired LAN on one LAN interface and my wireless on the other. Then configure each interface for 2 different subnets and a firewall rule on the wired LAN to block all traffic from the wireless LAN. That way the wireless network is behind NAT but cant get to my wired LAN but I can access the wireless network via the wired.


dnoyeB
Ferrous Phallus

join:2000-10-09
Southfield, MI
Its not clear to me how this avoids double NAT. Its seems like both routers are on seperate subnets!?


janderso1
Jim
Premium,MVM
join:2000-04-15
Saint Petersburg, FL

When you disable NAT on R2 (the Zyxel) it acts as a pure router. When a PC on the R2 LAN accesses the Internet its real 192.168.8.x address is passed to R1 by R2. R1 then replaces the 192.168.8.x with its WAN IP address (which is why R1 must be able to do NAT for more than one subnet).
--
Jim Anderson
Forums » Up and Running » Security » Wireless SecurityHiding unsecured wireless networks »
« Linksys Router Daisy Chained to a Netgear RT314  


Saturday, 28-Nov 21:50:37 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [71] Weekend Open Thread
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Why does it take so long? Mail question [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Why would I want an e reader? [General Questions]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Using DIR-615 C1/3.01 with Trendnet TEW-652BRP in N Mode [D-Link]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]