Actually I run two PPPoE sessions, and only one (v4) terminates in the Netgear. The other passes through (no NAT or extra routing hop on v6)
-
-
Replying to @marcan42
Okay. I don't think I would have chosen that. To each his own. You have logical reasons, so no complaint here.
1 reply 0 retweets 0 likes -
Replying to @DrScriptt
I mean, my only other option was to stick a PPPoE client in my initramfs. Keeping all routing duties on the Netgear wasn't an option (perf).
2 replies 0 retweets 1 like -
Replying to @marcan42
I get the preference. Why couldn't you put the PPPoE client & creds in the initramfs?
1 reply 0 retweets 0 likes -
Replying to @DrScriptt
I could, but that'd bloat my initramfs, and require retry scripts to ensure it stays connected, and complicate things.
1 reply 0 retweets 0 likes -
Replying to @marcan42 @DrScriptt
Also it still wouldn't let me have out of band serial access to this host like I do now with the double NAT trick.
1 reply 0 retweets 0 likes -
-
Replying to @DrScriptt
Routing doesn't work on the inbound connections. I'd still need to NAT those.
2 replies 0 retweets 0 likes -
Replying to @marcan42 @DrScriptt
And once I'm doing that in the Netgear it means putting a bunch of per-service firewall rules in there I'd much rather keep in the x86 box.
2 replies 0 retweets 0 likes -
Replying to @marcan42
Fair. I wonder if DMZ (DNAT everything) might help. Just trying to understand.
1 reply 0 retweets 0 likes
Well that's what I'm doing right now. DNAT everything. (But also MASQUERADE plus the DNAT/SNAT hairpin rules).
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.