Intrex Internet Services


Dialup ISDN / Ascend Pipeline

This document will review procedures for using Ascend Pipeline 50, Pipeline 75, and Pipeline 130 routers to obtain IP addresses dynamically from Intrex.Net. (The Pipeline 50, 75, and 130 are the ONLY Ascend routers that support this "NAT for a LAN" feature. The Pipeline 25-Px does support NAT, but only for a single workstation.) This document assumes your ISDN line is configured and working properly (ie. your SPIDs, switch type, switch usage, and phone numbers are correctly configured).

Single Workstation Example

The following example for setting up NAT to a single workstation is a typical setup for a connection to Intrex.Net.

Requirements:

The Pipeline MUST be on software 5.0A or better. Software upgrades are available online at ftp://ftp.ascend.com/pub/Software-Releases/Pipeline/. You must have an active ISDN dialup account with Intrex.Net.

Pipeline Configuration:

  1. Under the Configure... menu, enter your case-sensitive username in the "My Name" field.
  2. Under "My Addr" enter a bogus IP address (i.e., an unregistered address for your private network). We recommend 192.168.0.1/24.
  3. Under Rem Name, you should enter the name of Intrex.Net's ISDN dialup access server. However, as Intrex.Net's service grows, multiple access servers are put in place with different names and IP addresses making it difficult to predict exactly which one you will connect to. This being the case, we recommend entering just intrex.net.
  4. Under Rem Addr, you should enter the IP address of Intrex.Net's ISDN dialup access server. However, for the same reasons as #3 is not always known. Entering another bogus address that is NOT on your local network will work. You MUST enter something. Leaving the address at 0.0.0.0 will not work. We recommend using 209.42.192.2.
  5. Under Dial #, put in the phone number for the ISDN dialup line of the Intrex.Net POP you're connecting to. Here are a list of access numbers.
  6. Set Route=IP.
  7. Set NAT Routing=Yes and NAT Profile to the same name as you entered under Rem Name above. If you don't have these options don't panic, just skip this step and we'll take care of it at step 11.
  8. Set Send Auth=PAP and enter the case-sensitive password under the Send PW field.
  9. Set Recv Auth=None.
  10. Save your changes (ESC, then Exit and Accept).
  11. Under Ethernet->Mod Config… set NAT Routing=Yes. Then set NAT Profile to the same name as you entered under Rem Name. This option can also be found under the main configure menu on most Pipelines, but this varies depending on model and code release. If you still do not have these options your Pipeline's software version is incorrect, see the Requirements listed above.
  12. Under Ethernet->Mod Config->Ether Options... set RIP=Off. Ascend Pipelines default to using the RIP protocol to announce routing updates. This is completely unnecessary in this configuration and causes excess network traffic and many other adverse effects. One possible effect is that your router will never want to stay logged off. Each time it disconnects, it decides it needs to send a routing update to let the rest of the world know that it's no longer connected. In order to send that update, it reconnects. If your account exhibits this behavior (ie. continuous connection) Intrex.Net may terminate your account in order to preserve the dialup channels for other users, therefore it is very important that you make this change. If you need and/or want your connection to stay up continuously, you need a dedicated account.

Workstation Configuration:

The workstation must have a unique IP address on the same logical network as the Pipeline. For example, if the Pipeline has an IP address of 192.168.0.1/24 you could address the workstation as 192.168.0.2/24. The default gateway on the workstation would then be 192.168.0.1 (ie. the address of the Pipeline).

Multiple Workstation Example

Requirements:

You must satisfy a few additional requirements before using NAT for a LAN of multiple workstations. The setup for the Pipeline is exactly the same as it is for single-workstation NAT. The feature required "single-to-many NAT" is incorporated only in software release 5.0Ai10 and later. You can have no more than 4 workstations.

Pipeline Configuration:

Configure the Pipeline exactly as you would for a single-workstation application.

Workstation Configuration:

Each workstation must have a unique IP address on the same logical network as the Pipeline. For example, if the Pipeline has an IP address of 192.168.0.1/24 and you have three workstations on the same Ethernet segment, you could address the workstations as 192.168.0.2/24, 192.168.0.3/24, and 192.168.0.4/24. The default gateway on the workstations would then be 192.168.0.1 (ie. the address of the Pipeline).

How it works:

When the Pipeline first connects to Intrex.Net, it receives an initial IP address via PPP negotiation. The Pipeline then builds a table that matches each workstation's bogus address with the registered address that Intrex.Net assigns. The Pipeline re-addresses packets going to and from your workstation's bogus address with the dynamic address the Pipeline has acquired for it. This translation is transparent both to the workstation and to devices on the Internet.

Important Note:

Using this method, your workstations can access the Internet, but the Internet will have difficulty accessing them. Users of the Internet cannot access your workstations at the bogus IP addresses you've assigned because these IPs are, well, BOGUS. The REAL IP addresses of your workstations are assigned dynamically from the Intrex.Net access servers and are translated back and forth by the Pipeline. This has two major effects. First, your workstations are now safer from hackers on the Internet because the REAL IP addresses change every time your Pipeline disconnects and/or reconnects. Second, you cannot run servers on your network because they do not have consistent IP addresses for Internet users to access. If you need to run a server, or need static (ie. non-changing) rather than dynamic IP addresses, you need a dedicated account.

NAT Notes

When NAT Routing=Yes, the Pipeline 50 or 75 is NOT accessible from the WAN (i.e., you cannot telnet into it from the Internet). It is still accessible from the local network (using the private address).

Be aware that, if the ISDN connection drops (e.g., because of an idle time-out), there is no guarantee that upon reconnection you will get the same IP address assigned. For example, if you are using a web browser and the connection drops because you go idle, if you then click on a link, you might get an error message because you now have a different IP address.

Be certain that Ignore Def Rt=Yes (on the Pipeline, under Ethernet->Mod Config->Ether options...) to prevent the NAT default route from being overwritten.

Certain applications, like some UDP-based Internet game and chat client programs, will work unreliably or not at all when using NAT because they report their bogus, private IP address to the server instead of the "correct" dynamically assigned address.

There is a command in debug mode that will tell you the address assigned by Intrex.Net. Enter the command "napt" in debug mode and you will see the address.

The 4 workstation limit is imposed by Intrex.Net to insure that sufficient IP space is available to all users at all times. The Pipeline requests IP addresses from Intrex.Net for each computer on your network, hence the more computers you have, the more IP addresses you'll be using from Intrex.Net's dialup pool. If you place a 5th workstation on your network, connectivity problems for all workstations are likely. If you need simultaneous access from more than 4 workstations, you need a dedicated account.


Return to Technical Support

Home