- Netgear DG834 in NAT disabled mode
- Posted by Joe Butler on June 24th, 2005
How does one disable NAT on the Netgear DG834 so that still functions?
Specifically, I have this setup:
Internet
|
DG834 ADSL Modem Router (v1.04.01)
|
FVS318 VPN Firewall Router
|
Internal network.
The DG834 is configured to log in to my ISP, etc.
Firewall-wise, the DG834 allows everything out, and passes everything in to
the FVS318.
I.e. the FVS318 is in the DMZ of the DG834.
Neither device is set up for DHCP - all internal IPs are configured
manually.
This setup works OK for normal Internet use: e-mail, web, games.
Peer to peer is a bit odd - in that a lot of incoming packets to my p2p app
are dropped as suspicious by the FVS318 (even if the entire port range is
forward to the p2p machine).
Now, I'd like to try running this setup with the NAT'ing of the DG834
switched off. Problem is, that I loose internet access if I do that.
When I switched NATing off, my p2p app lost all its download connections,
but 2 uploads continued without issue.
Web browsing and e-mail don't work.
I hooked a hub between the DG834 and FVS318 to look at the traffic going
between them and see that when NAT'ing is switched off, the DG834 returns an
ICMP Type 3, Code 0 - Destination Unreachable, Net Unreachable packet in
response to the DNS query.
So, how do I tell the DG834 what to do with outgoing packets - so that it
actually sends them out rather than not knowing what to do with them?
It fails even if I use the IP address for google, and then the same IP
address works as soon as I re-enable NAT'ing.
Anyone got any insights - I know I'm probably doing something stupid, but
what is it?
Thanks.
- Posted by Tony on June 24th, 2005
On Fri, 24 Jun 2005 03:54:24 +0100, "Joe Butler"
<ffffh.no.spam@hotmail-spammers-paradise.com> wrote:
I don't understand why you would want to turn off Network Address
Translation, and how you expect your router / PC to work together
without it.
--
Tony
- Posted by Paul D.Smith on June 24th, 2005
Is the FVS318 just there to provide VPN support? If so, upgrade the DG384
to the latest software (see Netgear site) - this new version has its own VPN
support and you may be able to ditch the FVS318.
Paul DS.
- Posted by Paul D.Smith on June 24th, 2005
Do you simply want the VPN function of the FVS318? Are you aware that the
latest DG384 software supports VPNs? I'm not VPN expert but it might be
worth upgrading the DG384 and then trying it's VPN support. Perhaps you can
ditch the FVS318 altogether.
Paul DS.
- Posted by Joe Butler on June 24th, 2005
I expected the DG834 to simply pass packets back and forth without modifying
the source/destination addresses, etc. The only thing that's plugged into
the DG834 LAN-side is the FVS318 which is already NATing.
"Tony" <look@reply-to.stuff> wrote in message
news:7mdnb11e65n5qfd1ge6j1prg6esc06rn08@4ax.com...
- Posted by Joe Butler on June 24th, 2005
Yes, the FVS318 is there for VPN support (8 VPN endpoints).
I'll try the latest DG384 firmware.
Presumably you are talking about the v1.05 firmware and not the version 2
beta stuff?
thanks.
"Paul D.Smith" <paul_d_smith@x-hotmail.com> wrote in message
news:42bbbb5a$0$6470$ed9e5944@reading.news.pipex.n et...
- Posted by Joe Butler on June 24th, 2005
p.s.
I would still like to know how to configure the non-NAT mode with my current
setup - since it seems that the configuration is sensible.
"Joe Butler" <ffffh.no.spam@hotmail-spammers-paradise.com> wrote in message
news:42bbc461$0$23642$db0fefd9@news.zen.co.uk...
- Posted by ABC on June 24th, 2005
"Joe Butler" <ffffh.no.spam@hotmail-spammers-paradise.com> wrote in message
news:42bbc461$0$23642$db0fefd9@news.zen.co.uk...
website
- Posted by Phil on June 24th, 2005
"Joe Butler" <ffffh.no.spam@hotmail-spammers-paradise.com> wrote in
news:42bbc5ec$0$24452$da0feed9@news.zen.co.uk:
Have you got a block of public IP addresses to use? If so, you can set up
the DG834 to use multiple public IP addresses:
http://www.zensupport.co.uk/knowledg....aspx?id=10048
--
Phil
http://www.philipchung.co.uk/
- Posted by Paul D.Smith on June 24th, 2005
v2 is now official. See the Netgear website.
Paul DS
- Posted by [-=Dan=-] on June 24th, 2005
"Paul D.Smith" <paul_d_smith@x-hotmail.com> wrote in message
news:42bbbb30$1$6468$ed9e5944@reading.news.pipex.n et...
- Posted by [-=Dan=-] on June 24th, 2005
"[-=Dan=-]" <getbent@ease.com> wrote in message
news:3i2nc0Fjhp3uU1@individual.net...