Specifications
30
Rather then terminating building cables at a patch panel they were directly terminated with CAT5 plugs.
Terminating plugs is somewhat harder then receptacles but it eliminated the need and cost of a patch panel
and patch cables. Building wire is plugged directly into the central hub.
PCs run Microsoft Windows 98SE or Millennium operating system. The only communication protocol
used is TCP/IP. Using the same protocol for local access and Internet simplifies configuration. Most
machines are assigned a dynamic IP address. This minimizes problems adding and removing computers
from the network. Servers need static address so the can be referenced by IP address. The router has a
provision to bind the IP address to Ethernet MAC address. This is convenient because the router always
assigns the same address even though the device is configured for dynamic addressing.
One PC is dedicated for use as a server. It runs file sharing, web server, and a timeserver. It has Browse
Master enabled so it is always the Network Neighborhood Browse Master. This insures Network
Neighborhood is always visible. A dedicated print server is used for network printing.
8 Broadband Router – One Address So Many Computers
This section describes how to connect a LAN to a single Internet
account.
When the LAN was first set up we used Wingate proxy software
running on a laptop. This allowed multiple computers to share a
single dialup ISP account. At the time Wingate was the only
connection sharing software that included a DHCP server. This was
a convenient cost effective solution. However over time
shortcomings of this approach became apparent.
Software Proxy Limitations:
Each application must be configured to use the proxy. This
makes moving a laptop between LANs difficult. We wanted to replace the Proxy with NAT.
Wingate had a NAT version of the software but we had trouble getting an early version to work
with our hardware.
Streaming services such as Windows Media Player and Real Audio player do not work well
behind a proxy.
Even though connection sharing software does a good job protecting PCs on the LAN the machine
connected to the Internet is still vulnerable. If that machine is compromised the attacker has access
to everything on the LAN. To protect the directly connected PC I ran a software firewall. This
tended to be fragile. Often installing the latest Microsoft patch broke the firewall.
When one factors in the total cost for the software solution, second NIC card, sharing software and
firewall very little difference exists between software and hardware solutions.
Our router requirements:
Ethernet port for DSL
RS232 Serial port for dialup modem
Automatic fallback to analog modem if broadband fails
NAT using single public IP address
4 port 10/100 Ethernet Switch
DHCP server for LAN addresses
Dynamic and static IP address assignment on LAN
IPsec pass through for VPN
Port mapping to run servers
Good tech support
Figure 24 Broadband Router