I moved most of my routing duties to an x86 box, but I still terminate the PPPoE connection in my OpenWRT Netgear.
And once I'm doing that in the Netgear it means putting a bunch of per-service firewall rules in there I'd much rather keep in the x86 box.
-
-
Basically you're proposing moving more duties/complexity back to the Netgear for the sake of avoiding a double NAT... why?
-
My current setup basically lets me treat it as a black box, pretend my internal IP is public, and everything goes through except one port.
- Show replies
New conversation -
-
-
Fair. I wonder if DMZ (DNAT everything) might help. Just trying to understand.
-
Well that's what I'm doing right now. DNAT everything. (But also MASQUERADE plus the DNAT/SNAT hairpin rules).
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.