Keyboard Shortcuts
Likes
Search
Help FOR DSTAR DD
Perhaps we can help Maurizio with his questions below.? I've copied him on this email & invited him to join the group.? 73, Mark, WB9QZB? -----Original Message-----
From: maurizio spanio To: wb9qzb@... Sent: Sun, Jan 23, 2011 9:55 am Subject: Help FOR DSTAR DD Hello?Mark,?Maurizio?and?manage?iz3cyw?are?some?repeaters?Italians.
I also have?some?form?DD?ICOM?connected?to?repeaters?in the Veneto. In?Italy?it is not?allowed to?access the?internet?through?the?wireless network. I want to create?an?intranet?DSTAR?with?some?services?only for?amateurs,?but I'm notnetworking expert. I have?some?things?to?ask: -?Do you know?how?to?drive traffic?to?a?DD?and?intranet?to the Internet? -?Do you know?how to activate?a?server?for?intranet?email?only?DSTAR? Thanks?for?the?help. 73?de?iz3cyw Maurizio |
¿ªÔÆÌåÓýI believe that what you would need to do is to block outbound access on the router to all 10. Addresses except 10.0.0.X. This should keep DSTAR users from accessing the Internet. You can place an email (or any server) on the local 10.0.0.x subnet to allow the local D-STAR DD users to access. ? ? ? From: D-STAR_23cm@... [mailto:D-STAR_23cm@...]
On Behalf Of Mark Thompson
Sent: Sunday, January 23, 2011 10:11 PM To: D-STAR_23cm@... Cc: maurizio.spanio@... Subject: [D-STAR_23cm] Fwd: Help FOR DSTAR DD ? ? Perhaps we can help Maurizio with his questions below.? ? I've copied him on this email & invited him to join the group.? ? 73, Mark, WB9QZB? ? -----Original Message----- Hello?Mark,?Maurizio?and?manage?iz3cyw?are?some?repeaters?Italians.
?
|
I'm afraid that will not work because you have to have the 10. address
range available for other DD nodes and if you want to do any kind of
local based services.? My suggestion would be to put filters in the
Internet Router blocking everything EXCEPT 10.0.0.0 / 8 address
range.?? Another way would be to block DNS queries TCP/UDP 53
outside of Gateway PC.? This way, when you try to browse to an
address it will not go anywhere.
toggle quoted message
Show quoted text
After the SuperBowl I'll set up a test here on the 1.2G system I have for a test here at the house and find and document a way to handle just this type of scenario. Gerry W5MAY At 10:08 PM 2/1/2011, Woodrick, Ed wrote: I believe that what you would need to do is to block outbound access on the router to all 10. Addresses except 10.0.0.X. This should keep DSTAR users from accessing the Internet. |
It's really much simpler than this, just make sure you do not provide NAT service from 10.x.x.x to the Internet. NAT takes the 10.x.x.x address and replaces it with the WAN IP address in your router and keeps track of the ports and remote address used, it then uses that information to convert incoming traffic (from the Internet) back to a 10.x.x.x address. If NAT is turned off then the traffic neither leaves with the WAN IP address and returning traffic would simply be dropped.
toggle quoted message
Show quoted text
--- In D-STAR_23cm@..., "Woodrick, Ed" <ewoodrick@...> wrote:
|
¿ªÔÆÌåÓýGerry, ? I¡¯m assuming that you are referring to blocking access from Source addresses. Because, of course, routing 10. Out the router ain¡¯t going anywhere. If you block ¡°EXCEPT 10.0.0.0/8¡± then aren¡¯t you going to allow ALL of the ID-1s access to the Internet? ? I¡¯m guessing that you meant to block DNS for everything except the gateway. This indeed has an impression of working, but it doesn¡¯t restrict me from getting access. Direct IP access, or a well-populated? host table would get around it. ? Remember, this is blocking at the router to the Internet and therefore shouldn¡¯t really impact a local ID-1 to access local 10.0.0.X resources. ? Ed ? From: D-STAR_23cm@... [mailto:D-STAR_23cm@...]
On Behalf Of Gerry Dalton W5MAY
Sent: Wednesday, February 02, 2011 4:59 AM To: D-STAR_23cm@... Cc: maurizio.spanio@... Subject: RE: [D-STAR_23cm] Fwd: Help FOR DSTAR DD ? ? I'm afraid that will not work because you have to have the 10. address range available for other DD nodes and if you want to do any kind of local based services.? My suggestion would be to put filters in the Internet Router blocking everything EXCEPT 10.0.0.0
/ 8 address range.?? Another way would be to block DNS queries TCP/UDP 53 outside of Gateway PC.? This way, when you try to browse to an address it will not go anywhere.
|