/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


For what it's worth, I've used double-nat at several sites with no 
problem.  Some examples:  Netgear ISDN router, through Linux to 
the internal network, Cisco 675 DSL router, through either Linux or 
Wingate on NT.  (The wingate wasn't my decision, and I'm trying to 
sell management on Linux.)  

The point is, that it should work; something else is wrong, probably 
at your corporate office.  It may be a routing issue, where the router 
to the outside needs to know about your office router, to get 
packets to your network.  Sorry not to be more help.

Send reply to:          <[EMAIL PROTECTED]>
From:                   "Neal Lippman" <[EMAIL PROTECTED]>
To:                     <[EMAIL PROTECTED]>
Date sent:              Sat, 13 May 2000 21:31:16 -0400
Subject:                [Masq]  Two layers of NAT problem...need help!

> /* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
> 
> 
> This is not a specifically ipmasq problem, but more generally a NAT problem.
> I am hoping someone has some ideas, because I cannot figure this out. The
> problem is as follows (sorry for the length of this post; I am going to be
> detailed to make sure I give a clear enough description of my setup and
> problem):
> 
> I have a LAN located in my office, consisting of a number of Win98 boxes,
> some HP printservers, and a Unix-based server. All of the systems are
> networked via a Linksys 16 port 10/100 hub, and that uplinks into a Linksys
> Cable/DSL router, a recently released piece of hardware designed for home
> users to share multiple computers over a single cable-modem or DSL line, but
> which works equally well in my setup, where my LAN is uplinked via this
> router to a corporate LAN in my building, through which I am receiving
> network connectivity. My Lan uses IP addresses in 192.168.1.x; I statically
> assign the IP addresses rather than using the router's built-in DHCP
> capability because of some problems with Win98 and the NIC's synchronizing
> via the switch in the router.
> 
> The router itself uses 192.168.1.1 internally, and has an ip address in the
> 10.x.x.x network, because that is what the corporate LAN uses internally.
> Obviously, the corporate LAN uses NAT to connect its internal IP assignments
> to its limited external "real" IP addresses. THerefore, to reach hosts
> outside of the corporate LAN, any packet originating on my LAN goes through
> two layers of NAT, one at my router and one at the outer LAN's router to the
> internet.
> 
> Therein lies the problem. I can establish outgoing connections from my LAN
> to the outer corporate LAN, but not get any further. From my desktop, I can
> ping any host on my LAN or on the outer corporate LAN, but not through the
> next layer of NAT to the outside world. The same is true for any outgoing
> connection. Going through the second layer of NAT causes it to fail. (NB: I
> am told by the network operators that they are NOT filtering any packets at
> the firewall level that would cause this problem.)
> 
> As I understand the operation of NAT, this doesn't make sense. It seems to
> me that packets originating on my LAN and going through my router would
> appear to the outside LAN as having appeared at my router, and since there
> shouldn't be anyway to tell that they didn't originate on my router, they
> should get NAT's and deNATed on the way back in, and then my router would
> again deNAT them. I know that the routing between the corporate LAN works,
> because hosts directly attached to the corporate LAN using 10.x.x.x
> addresses work fine, so the problem seems to be in the double layer of NAT.
> I read through the Linux sources that handle all of this, and saw nothing
> that would indicate that double layers of NAT would fail, nor did I see
> anything in the original RFC on NAT to explain this behavoir.
> 
> Unfortunately, I don't know what kind of system the NAT is being done with.
> I would doubt it is Linux-based, more likely WinNT or most likely a Cisco
> router.
> 
> Any thoughts?
> 
> Thanks.
> Neal
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
>UNSUBSCRIBIN
G!
> or email to [EMAIL PROTECTED]
> 
> PLEASE read the HOWTO and search the archives before posting.
> You can start your search at http://www.indyramp.com/masq/
> Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to