Indonesia French German Spain Italian DutchRussian Portuguese Japanese Korean Arabic Chinese Simplified Widget edited mneh by xenad1325

Guide to GSM, GPRS, 3G, EDGE, HSDPA

It can be confusing trying to understand the differences between the various mobile connectivity options listed in the specifications of smartphones and touted by the mobile networks as the best way to connect to the internet. In this guide we will try to summarise these technologies and point out the advantages and disadvantages of each technology.

GSM

GSM (Global system for mobile communications) is the standard by which the vast majority of mobile handsets work in Europe and is becoming dominant in other parts of the world with over 2 billion people currently using the system. When you purchase a mobile or smartphone it is important to understand what frequencies are used by each technology because manufacturers and networks have a tendency to quote these figures with little explanation as to what they mean.

The majority of GSM networks use 900MHz and 1800MHz but in the US the 850MHz and 1900Mhz are prominent. If these are quoted the phone will be classed as a tri-band phone and can be used in Europe, the US and many other territories (provided your SIM is enabled). If you require mobile access in the Far East and areas such as Scandanavia you will need to check with your mobile provider because at the minimum a quad-band phone will be required and in some areas only a phone purchased in the country will work.

Most GSM phones are primarily used for voice but can be used for mobile internet access via the GPRS Core Network.

GPRS

GPRS is a system used to transmit data at speeds of up to 60 kbits per second and is a battery friendly way to send and receive emails and to browse the internet but in these days of broadband connectivity it will be seen as slow by some. To set up GPRS connections on your smartphone you will need to obtain specific information from your mobile provider to input into your phone. Most are happy to provide this information and some manufacturers such as Nokia offer pre-configured files that you can install onto your phone for your network.

GPRS is a tried and tested system and is therefore very reliable for standard mobile data use and will suit people with moderate data needs. Once you have the required settings in place you can use the network whenever you like and it requires no further adjustment as it works in the background of your internet enabled applications.

EDGE

EDGE (Exchanged Data rates for GSM Evolution) is a recent development based on the GPRS system and has been classified as a '3G' standard due to the fact that it can run at up to 473.6 kbits per second. If a smartphone is EDGE compliant it can be used for heavy mobile data transmission such as receiving large email attachments and browsing complex web pages at great speed. To use EDGE cell sites must be modified to accept transmissions of this type so coverage can be patchy in certain areas- it is a technology well worth having built in to any smartphone though.

3G

3G was initially marketed as a way to make video calls on the mobile network but is also a highly efficient way of browsing the internet and communicating on your smartphone using voice over IP and by email and instant messaging. Most UK and some European networks now have 3G networks and with speeds similar to EDGE it is fast becoming a common way to connect while on the road.

In areas where 3G coverage is poor the handset will constantly try to find a 3G signal and this can have a dramatic affect on battery life. Some phones handle constant 3G enablement well but some can have their battery life reduced by up to 50% so it is worth checking that your potential purchase is able to cope with this. At this time though 3G has good coverage and enables high speed internet access from your phone and is fast becoming a standard for mobile connectivity.

HSDPA

HSDPA (High speed Downlink Packet Access) is a technology based on the 3G network which can support speeds of up to 7.2 mbits per second. In reality you will most likely get a top speed of around 3 mbits but this is useful for mobile TV streaming and other high end data transmissions. To use HSDPA your phone must be able to support the technology and of course you will need to be located within range of a cell site that has been upgraded to offer the service.


The key to all of these technologies is to understand what your typical usage will be and which of the above suit your needs. It could also be worth future proofing your needs because well connected devices often cost little more than phones with basic connectivity.

source : www.clove.co.uk

Read more...

2.5G, 3G, 3.5G and 4G technology

What is 4G?

4G takes on a number of equally true definitions, depending on who you are talking to. In simplest terms, 4G is the next generation of wireless networks that will replace 3G networks sometimes in future. In another context, 4G is simply an initiative by academic R&D labs to move beyond the limitations and problems of 3G which is having trouble getting deployed and meeting its promised performance and throughput. In reality, as of first half of 2002, 4G is a conceptual framework for or a discussion point to address future needs of a universal high speed wireless network that will interface with wireline backbone network seamlessly. 4G is also represents the hope and ideas of a group of researchers in Motorola, Qualcomm, Nokia, Ericsson, Sun, HP, NTT DoCoMo and other infrastructure vendors who must respond to the needs of MMS, multimedia and video applications if 3G never materializes in its full glory.

Motivation for 4G Research Before 3G Has Not Been Deployed?

  • 3G performance may not be sufficient to meet needs of future high-performance applications like multi-media, full-motion video, wireless teleconferencing. We need a network technology that extends 3G capacity by an order of magnitude.
  • There are multiple standards for 3G making it difficult to roam and interoperate across networks. we need global mobility and service portability
  • 3G is based on primarily a wide-area concept. We need hybrid networks that utilize both wireless LAN (hot spot) concept and cell or base-station wide area network design.
  • We need wider bandwidth
  • Researchers have come up with spectrally more efficient modulation schemes that can not be retrofitted into 3G infrastructure
  • We need all digital packet network that utilizes IP in its fullest form with converged voice and data capability.

Comparing Key Parameters of 4G with 3G


3G (including 2.5G, sub3G) 4G
Major Requirement Driving Architecture

Predominantly voice driven - data was always add on

Converged data and voice over IP

Network Architecture Wide area cell-based Hybrid - Integration of Wireless LAN (WiFi, Bluetooth) and wide area
Speeds 384 Kbps to 2 Mbps 20 to 100 Mbps in mobile mode
Frequency Band Dependent on country or continent (1800-2400 MHz) Higher frequency bands (2-8 GHz)
Bandwidth 5-20 MHz 100 MHz (or more)
Switching Design Basis Circuit and Packet All digital with packetized voice
Access Technologies W-CDMA, 1xRTT, Edge OFDM and MC-CDMA (Multi Carrier CDMA)
Forward Error Correction Convolutional rate 1/2, 1/3 Concatenated coding scheme
Component Design Optimized antenna design, multi-band adapters Smarter Antennas, software multiband and wideband radios
IP A number of air link protocols, including IP 5.0 All IP (IP6.0)


What is needed to Build 4G Networks of Future?

A number of spectrum allocation decisions, spectrum standardization decisions, spectrum availability decisions, technology innovations, component development, signal processing and switching enhancements and inter-vendor cooperation have to take place before the vision of 4G will materialize. We think that 3G experiences - good or bad, technological or business - will be useful in guiding the industry in this effort. We are bringing to the attention of professionals in telecommunications industry following issues and problems that must be analyzed and resolved:

  • Lower Price Points Only Slightly Higher than Alternatives - The business visionaries should do some economic modeling before they start 4G hype on the same lines as 3G hype. They should understand that 4G data applications like streaming video must compete with very low cost wireline applications. The users would pay only a delta premium (not a multiple) for most wireless applications.
  • More Coordination Among Spectrum Regulators Around the World - Spectrum regulation bodies must get involved in guiding the researchers by indicating which frequency band might be used for 4G. FCC in USA must cooperate more actively with International bodies like ITU and perhaps modify its hands-off policy in guiding the industry. When public interest, national security interest and economic interest (inter-industry a la TV versus Telecommunications) are at stake, leadership must come from regulators. At appropriate time, industry builds its own self-regulation mechanisms.
  • More Academic Research: Universities must spend more effort in solving fundamental problems in radio communications (especially multiband and wideband radios, intelligent antennas and signal processing.
  • Standardization of wireless networks in terms of modulation techniques, switching schemes and roaming is an absolute necessity for 4G.
  • A Voice-independent Business Justification Thinking: Business development and technology executives should not bias their business models by using voice channels as economic determinant for data applications. Voice has a built-in demand limit - data applications do not.
  • Integration Across Different Network Topologies: Network architects must base their architecture on hybrid network concepts that integrates wireless wide area networks, wireless LANS (IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, IEEE 802.15 and IEEE 802.16, Bluetooth with fiber-based Internet backbone. Broadband wireless networks must be a part of this integrated network architecture.
  • Non-disruptive Implementation: 4G must allow us to move from 3G to 4G.

Read more...

Router Review

This posting discuss about router. Many router product on the world. We never know what the peformance of it. So I compare routers review. The compare product is Linksys WRT56GS, Netgear WGT624, D-Link DI624, Dell Wireless 2300, Microsoft MN-700, and Buffalo AirStation WLA-G54. I hope you can choose the best router after read it.

Linksys WRT54GS
review by: Xiao Ming Wu

Editors' note: The rating and/or Editors' Choice designation for this product has been altered since the review's original publication. The reason for this is simply the general improvement of technology over time. In order to keep our ratings fair and accurate, it's sometimes necessary to downgrade the ratings of older products relative to those of newer products. (12/9/04) The Linksys WRT54GS Wireless-G Broadband Router with SpeedBooster makes it easy to set up a typical home or office network, and it comes with all the documentation you need to get it up and running. It touts a wealth of advanced networking and security features, and it's fast, especially in networks with both 802.11g and 802.11b connections.The illustrated Fast Start guide for the Linksys WRT54GS Wireless-G Broadband Router with SpeedBooster walks you through the basic setup, which includes connecting the router to your computer and broadband modem, configuring all the computers on the network to work with the router, and configuring the router. The Fast Start guide is more thorough than others we've seen, with plenty of images and screenshots illustrating the setup process. We were glad to see brief explanations of basic networking terms, such as the difference between static and dynamic IP addressing and what to do if your DSL provider uses PPPoE. The guide also describes how to connect to the WRT54GS's browser-based configuration tool if you need to tweak the router's configuration--for example, to supply the router with a static IP address. No quick-setup guide can cover all possible networking scenarios, but Linksys's step-by-step guide does an excellent job rounding up the usual suspects and making it easy for most homes and small offices to set up a network in a few minutes. In most cases, you need only to plug in the router and connect the cables. For more complicated setups, Linksys includes a thorough user guide detailing the WRT54GS's diverse features.Although the Linksys WRT54GS Wireless-G Broadband Router with SpeedBooster is easy to set up, you'll find a number of advanced features and configuration options under the hood. The Linksys WRT54GS's browser-based configuration tool gives you access to the router's networking and security settings, such as DHCP server and client settings, firewall settings, and wireless encryption settings. The router also comes with two types of firewalls. One is a Stateful Packet Inspection (SPI) firewall that makes sure packets are part of a legitimate connection; the other is a NAT firewall that effectively hides computers behind the router. You can lock your network down even tighter by configuring the router to block services such as FTP and Telnet. A DMZ function located on the configuration tool's Applications and Gaming tab lets you place one computer outside the firewall, which can be useful for Internet gaming and videoconferencing. The Linksys WRT54GS also lets you set up access-control policies that grant Internet access to specific computers on your network at predetermined times of day and days of the week. If you telecommute, the router's VPN pass-through support will help get you to work. The Linksys WRT54GS router also has good wireless security. You can configure it to use WEP or WPA. WPA is stronger than WEP, but it's important to have both options, because you may want to connect to older 802.11b devices that lack WPA support. We also like that you can turn off the beacon on the WRT54GS's integrated 802.11g access point. This helps protect you from uninvited guests by stopping the access point from advertising its presence to the world. The Linksys WRT54GS router comes with removable antennas, giving you the option of attaching high-gain antennas to the unit to increase its range. Our only gripe was that the router lacks a mounting bracket.The Linksys WRT54GS Wireless-G Broadband Router with SpeedBooster is one of a growing number of wireless routers touting proprietary speed enhancements. Like the D-Link DI-624 and the Netgear WGT624, the WRT54GS SpeedBooster router includes a technology (in this case, Broadcom's Afterburner) that substantially increases wireless network performance. The enhancements kick in only if all the devices on the network are playing by the same proprietary rules; otherwise, the device scales down to standard 802.11g speeds. We think that this limitation makes the SpeedBooster enhancement (and similar Turbo or Super-G offerings from vendors such as D-Link and Netgear) more of a marketing gimmick than a significant feature. Proprietary solutions depend on networks molded out of homogenous gear, limiting your purchase choices and tying you to a single vendor. On the other hand, the Linksys WRT54GS Wireless-G Broadband Router with SpeedBooster does a fine job supporting standards-based equipment from other vendors, even older 802.11b gear. In CNET Labs' mixed-mode tests, which measure throughput when both 802.11g and 802.11b transmissions occur simultaneously, the WRT54GS delivered the fastest speeds we've seen, clocking in at 25.8Mbps. The Linksys also went the distance, stretching as far as 200 feet in our range tests.

Netgear WGT624
review by: Allen Fear

The Netgear WGT624 108Mbps wireless firewall router is a good example of the advantages and disadvantages of bleeding-edge technology. It offers nearly double the throughput of standard 802.11g devices and increased range to boot. Plus, the WGT624's fast throughput over distance combined with its support for portions of the 802.11e draft standard make it well suited for streaming media over your wireless connection. Other advanced features, such as an SPI firewall and support for Dynamic DNS, make the WGT624 a good choice for techies who are looking for a high-performance wireless router and are willing to perform an occasional firmware upgrade. (Netgear has already released one firmware upgrade for the router that fixes some bugs and enhances performance.) If the idea of router maintenance doesn't appeal to you, consider the Dell Wireless 2300, which lacks the speed of the WGT624 but is easier to set up, or the Microsoft MN-700, which automatically checks for firmware upgrades. The Netgear WGT624 108Mbps wireless firewall router comes with all the hardware and software you'll need to set up your network. In addition to the router, the product package contains an AC power adapter, a rubber stand, an Ethernet cable, a printed installation guide, and a CD containing a comprehensive reference manual. We like the compact design of the WGT624. The router's rubber stand and built-in mounting bracket on the bottom panel help you position the device for optimum range. The LEDs on the front of the unit let you monitor data passing across the WGT624's Ethernet and wireless interfaces. Plug the router in, connect it via the Ethernet cable to your broadband modem, and you've installed the WGT624 hardware. The network installation is a little less straightforward, and the printed guide may leave some in the lurch. The guide asks you to manually reconfigure the network settings of each computer if necessary, then it refers you to an online resource to learn how to do this. In contrast, the Dell Wireless 2300 and the Microsoft MN-700 include software that automatically configures the network settings for the router and any connected computers, making these instruments better suited for those new to networking. After you connect the WGT624 to your local network, the router's browser-based Smart Wizard automatically detects the type of Internet service you have and directs you through the rest of the installation. The Netgear WGT624 108Mbps wireless firewall router has a good feature set that meets the needs of both advanced users and those with little or no networking experience. The WGT624's browser-based configuration tool is easy to navigate and offers features tailored for family networking. The tool is password-protected and includes a content-filtering section that gives you control over the types of sites your computers can access, letting you restrict access based on keywords, service types, IP addresses, and times of day. The WGT624 also displays detailed logs of the Web sites that your computers have accessed or attempted to access, which lets you police the types of traffic passing through your network. The router includes two different types of firewalls: network address translation (NAT), which hides your computers' IP addresses behind the router's IP address, and stateful packet inspection (SPI), which checks individual data packets to make sure they are part of a legitimate connection. Together, these firewalls provide strong security against most attacks originating from the Internet. The WGT624 also supports WEP and the stronger WPA encryption scheme. We wish that the WGT624 supported wireless distribution system (WDS). Limited range is a problem for many home networking environments, and WDS makes it easy to expand your coverage area by simply adding a repeater, such as the Buffalo WLA-G54C, to rooms where your signal is weak. The WGT624 has other performance enhancers under the hood that make it especially well suited for streaming media. Portions of the 802.11e draft specification are built into the router's firmware. These new features ensure that streaming media applications, such as the voice and video links in a teleconference, aren't interrupted by a simple file transfer. This means that you can participate in the teleconference over your wireless connection and download data from the Internet without suffering degradation in the audio or video quality of the links. The most noteworthy feature of the Netgear WGT624 108Mbps wireless firewall router is its inclusion of Super G Technology (link is a PDF file), which boosts the router's speed to nearly twice the tempo of standard 802.11g devices'. A recent firmware upgrade allows the router to switch dynamically to support standard 802.11g and 802.11b devices when they enter the network. CNET Labs tested the router's throughput with various adapters concurrently, and the results are impressive. The WGT624 ran circles around the U.S. Robotics USR8054. Better yet, the Netgear router delivered fantastic range in our indoor tests, providing stable connections as far as 225 feet away.

D-Link DI624
Review By: Allen Fear

Editor's note: The rating and/or Editors' Choice designation for this product has been altered since the review's original publication. The reason for this is simply the general improvement of technology over time. In order to keep our ratings fair and accurate, it's sometimes necessary to downgrade the ratings of older products relative to those of newer products. (12/14/04) When we first reviewed the D-Link DI-624 AirPlus Xtreme G router a year ago, we were unimpressed, but that was then, and this is now. The new DI-624 is about half the size of the original and twice as fast. It also comes with an improved quick-installation guide, a more comprehensive manual, stronger security features, and an excellent support package that includes a long, three-year warranty. Few routers are as easy to set up as the DI-624, but if the thought of typing an IP address into your browser's address bar makes you sweat, then consider the less powerful but easier to use, Microsoft MN-700. On the other hand, if you're looking for a fast router with excellent range and a bushel of features, such as a configurable firewall, parental controls, top-notch wireless security, and VPN pass-through support, then look no further. With a current street price of about $70, the DI-624 is a great buy for both home and small office networks. For a router with such an advanced feature set, the D-Link DI-624 AirPlus Xtreme G router is easy to set up. The package includes everything you'll need: the router; a CD-ROM containing a manual and warranty info; an Ethernet cable; and a 5V DC power adapter. The new DI-624 is compact, about the size of a medium-size paperback, and its bottom panel doubles as a mounting bracket, making it easy to attach to a wall or the ceiling. Unfortunately, the DI-624 doesn't come with a stand for vertical positioning, which is a feature we like in the Netgear WGT624. The hardware setup is a snap, literally. Connect the DI-624 to your broadband modem with the cable that came with your modem, use the Ethernet cable in the package to connect the router to your computer, and you're done. Although D-Link doesn't offer an automated configuration routine like the one you'll find with the Dell Wireless 2300 and the Microsoft MN-700, the DI-624's network setup is about as easy as it gets; it's one of the smoothest setup routines we've seen. The printed quick-installation guide walks you through every step of the installation process, with screen shots and instructions for both Mac OS X and Windows XP that show you how to connect to the DI-624's browser-based configuration tool. The browser-based tool itself includes a five-step setup wizard that automatically detects your Internet connection and configures security for your wireless network. The explanations and instructions in the printed quick-installation guide seamlessly complement the wizard, addressing each step in the process. The D-Link DI-624 AirPlus Xtreme G router is chock-full of features for both homes and small offices. Auto MDI/MDIX ports in the router's Ethernet switch eliminate the need for costly crossover cables and make the DI-624 easy to connect to other hubs and switches. The router also comes with a removable antenna, so you can expand your coverage area by adding an antenna. The router also features parental controls that include URL filtering, domain blocking, and access scheduling by day of the week and time of day. If you play games over the Internet, you can use the DI-624's special gaming mode, which adjusts the firewall to allow for network entertainment. For connections that demand even less restrictive access, such as videoconferencing, you can use the router's DMZ feature, which lets you place a single computer outside the router's firewall. If you telecommute, the DI-624 also supports VPN pass-through for both PPTP and IPSec. With a firewall that is more configurable than most we've seen, the DI-624's security is top-notch for a consumer router. You can turn the firewall on and off, a feature missing from the Microsoft MN-700 and one that can be important for troubleshooting and allowing certain types of connections. You can also create a list of rules that let you allow or deny specific types of traffic between your internal network and the Internet. For example, you can block UDP traffic from the Internet targeted for a specific port on one of your computers. The DI-624 heaps on wireless security features. The router supports not only 64- and 128-bit WEP encryption, but also WPA and ironclad 802.1x authentication via a RADIUS server. The D-Link DI-624 AirPlus Xtreme G router is one of the best-performing routers we've seen. Like the Netgear GT624, the D-Link DI-624 comes equipped with an Atheros AR5002 chipset, the secret to its blazing throughput and great range. If you already have a DI-624, you can upgrade the router's firmware to the latest version to take advantage of the new performance enhancements. The so-called 108Mbps firmware is currently available only for DI-624s with a label on the bottom that reads "H/W Ver.:C1." At close range, the DI-624 clocked in at 44.4Mbps. That's about twice as fast as a typical 802.11g router and just under the Netgear WGT624's speed of 47.1Mbps. The DI-624 also matched the WGT624 in range, surpassing other 802.11g performers with a record-setting 225 feet. We were less impressed with the DI-624's performance in a mixed environment with 802.11b devices. Here, the router was able to eke out only 11.6Mbps at close range, noticeably less than the 18.2Mbps demonstrated by the Dell Wireless 2300.

Dell Wireless 2300
Rreview By: Patrick Unnold

Editors' note: The rating and/or Editors' Choice designation for this product has been altered since the review's original publication. The reason for this is simply the general improvement of technology over time. In order to keep our ratings fair and accurate, it's sometimes necessary to downgrade the ratings of older products relative to those of newer products. Dell's Wireless 2300 broadband router offers superior performance and a well-rounded feature set suited for the home user. Windows 2000 and XP users, as well as novices, will like the streamlined installation, which nearly runs itself (other operating systems are supported, but not as seamlessly). The Wireless 2300 supports both 802.11b and 802.11g and touts an excellent array of security options, including WPA, WEP, SSID blocking, stateful packet inspection (SPI) firewall, and parental controls. You can also link the router to two additional Wireless 2300 routers to increase your 802.11g coverage area. This is the most polished 802.11g router we have seen to date. The initial setup of the Wireless 2300 is simple and quick, especially for those with Windows 2000 or XP systems. Inserting the accompanying CD starts the Setup Wizard. After a quick scan of your network, the Setup Wizard automatically configures the settings for both your computer and the Wireless 2300. With the Setup Wizard making all of the networking changes for us, we connected quickly and were surfing within just a few minutes. The process takes a bit longer with other OSs, but the included user guide walks you through the process. Changing the router's configuration requires the Web-based configuration tool; unfortunately, it's a little convoluted. For example, the Setup Wizard warns you to lock down the wireless network by changing the SSID, enabling WEP or WPA, and turning off SSID broadcasts. The first two items are easily found in the Basic section of the configuration tool, but users must make their way to the wireless settings of the Advanced section to turn off SSID broadcasts. The Wireless 2300 is packed with features and security, and it supports 802.11g and boasts an eye-pleasing exterior design. The sleek, silver-and-black chassis has wall-mounts built into its base. The clearly labeled indicator lights show activity for the Internet connection, each of the four ports on the built-in 10/100 switch, and the wireless LAN. The Wireless 2300 offers the latest in security options for wireless networking. It supports the new WPA encryption scheme as well as the older 64/128-bit WEP standard. There's no support for 802.1x authentication, but the router does offer an expansive MAC address feature that can be applied to all clients of the Wireless 2300, whether wired or wireless. Stateful Packet Inspection, NAT, packet filtering, and intruder-detection alerts offer a high level of Internet security. Additional security features include port forwarding, which allows for both a DMZ computer and the forwarding of specific packets to specific computers. The well-rounded parental-control feature lets you block Internet access for specific computers by time of day. You can also limit Internet access completely or restrict it to a list of Web sites. Another great feature is the router's ability to create a wireless bridge with up to two additional Wireless 2300s. This lets it function as a bridge and a repeater, similar to the Buffalo WLA-G54. The Dell Wireless 2300 offers some of the best 802.11g throughput rates we've seen to date, second only to the U.S. Robotics USR8054. In our tests, the throughput rates for 802.11g peaked at 23.5Mbps for 802.11g, and those for mixed-mode (with both 802.11g and 802.11b clients transmitting simultaneously) reached 18.2Mbps. The throughput degradation over distance is also very good. Most notably, both the Wireless 2300 and the USR8054 outperform their competitors in mixed-mode performance by more than a factor of two. The Wireless 2300 has a few limitations. The user guide indicates that the Wireless 2300 can support only 16 wireless clients or 64 NAT clients; in addition, having more than 20 simultaneous users of any type degrades the device's overall performance. Most home users will never stress the Wireless 2300 to this extent, but small offices could begin to hit the performance ceiling if their network grows large enough.

Microsoft MN-700
review by: Patrick Unnold

Microsoft's new 802.11g MN-700 wireless broadband router is designed so that even a novice user can expand a home network easily, but it has a few shortcomings compared to the Editors' Choice-winning Dell TrueMobile 2300. The setup process and the configuration utility are very user-friendly, and Microsoft's support options will help with most problems you might encounter. It offers most features that home users need, and the Setup Wizard automatically turns on wireless security--a unique and much-needed detail. Its range is excellent. Experienced users will be frustrated by the lack of advanced configuration options and wireless bridge support, however. Like the Dell TrueMobile 2300's streamlined installation routine, the MN-700's Setup Wizard gathers the necessary network information automatically before configuring both your wireless network adapter and the MN-700. The Setup Wizard supports all Windows platforms; a nonautomated, browser-based interface is available for other OSs. We uncovered a bug in the Setup Wizard software that prevented the application from completing normally when we attempted to use a workgroup name that contained a period. Microsoft tech support worked quickly to determine the cause and promised a fix in a future release. The MN-700's documentation is excellent. In addition to the printed installation guide, you get a thorough, printed user guide with a lengthy troubleshooting section, as well as detailed instructions for nonstandard installations, such as using the MN-700 as an access point instead of as a router. You use the Broadband Network Utility, which you install on one of your networked machines during setup, to check network status and adjust the MN-700's configuration. Like the Setup Wizard, the Broadband Network Utility is novice-friendly; it's easy to navigate, with clear help information on each screen. The utility also checks automatically for updates, making it simple to keep the firmware current. The MN-700's impressive security setup includes one unique and much-needed touch: wireless security is enabled during setup--no other product we've seen does this--and other security features, such as Stateful Packet Inspection (SPI) firewall and NAT, are always on. Additional security features include parental controls, client filtering, 64/128-bit WEP, 256-bit WPA, DMZ, MAC address filtering, and detailed logging. While the MN-700 boasts 802.11b/g Wi-Fi certification and an impressive feature set for home users, it doesn't offer much advanced configurability. For instance, it lacks options such as support for RADIUS and wireless bridging, which are available on similarly priced products, such as the Buffalo AirStation router. Also, you cannot control the output wattage for the wireless network or adjust the security level of the firewall. The only option available for configuring the firewall is a check box for enabling ICMP blocking. The Dell TM2300 gives you more control of the firewall. The MN-700's hardware features mirror those of most other home routers. The device sports a rotating external antenna and a four-port 10/100 Ethernet switch that autosenses crossover cables as well as the line speed. The MN-700 is designed for the desktop and is not well suited for mounting on a wall or a ceiling. With a healthy throughput of 21Mbps in 802.11g mode and nearly 12Mbps in mixed 802.11b/g mode, the MN-700 outperforms many of the wireless broadband routers we've tested. However, the MN-700 still falls short of the throughput we've seen in the broadband routers released since the 802.11g specification was ratified, specifically the US Robotics 8054 and the Dell TrueMobile 2300. Thanks no doubt to its rotating external antenna, the MN-700 showed solid performance over distance, outperforming even the US Robotics 8054 and the Dell TrueMobile 2300. In our tests, the MN-700 achieved a throughput of nearly 6Mbps at a whopping 175-foot distance in 802.11g mode, and it didn't completely drop off until it approached 200 feet. That gives it about a 25-foot advantage over the Dell and US Robotics products. The extra distance could be important, because unlike the Dell TM2300, the MN-700 cannot be linked via a wireless bridge.

Buffalo AirStation WLA-G54
Reviewed by: Patrick Unnold

A single wireless router or access point can't always cover every room in a house. The Buffalo WLA-G54 wireless bridge gives you a plethora of features and options for expanding your home or office network without stringing cable. It includes a four-port switch for wired clients, and it supports both 802.11b and 802.11g standards. Because it's externally identical to the Buffalo AirStation 54Mbps wireless broadband router we've previously reviewed, it suffers from the same flaws, including limited mounting options and hard-to-see LEDs for the four-port switch. The Buffalo WLA-G54 installs easily to a wired network, but connecting it to another Buffalo AirStation to create a bridge is harder than it should be. When you start the initial configuration, you can designate either a wired or wireless connection; the quick-setup guide has decent instructions for both. In either case, you have the option of connecting to the WLA-G54 via the Client Manager software included on the CD-ROM or a browser such as Internet Explorer or Netscape. Once you've connected a computer to the WLA-G54, you're ready to integrate it into your network by assigning IP addresses and the ESS-ID and configuring security options. The browser-based configuration tool includes wizards for WEP settings and MAC address restrictions, plus an advanced-configuration page that gives you direct access to all of your options. If you use the WLA-G54 to create a wireless bridge to another Buffalo AirStation, you must register the MAC address of each Buffalo access point, router, or bridge on your network under the WDS section of the configuration screen. The terse documentation fails to cover this process thoroughly. The Buffalo WLA-G54 wireless bridge distinguishes itself from other bridges, such as the Linksys WET54G, with its Wireless Distribution System (WDS) support. This lets the WLA-G54 act as a wireless repeater with up to six Buffalo WDS-enabled AirStations, such as the Buffalo AirStation router on a single network, making it an ideal solution for large houses or apartment buildings. Because WDS is not a standard, however, it doesn't work with non-Buffalo products. A swivel cover on the top of the back panel conceals an MMX connector. For larger sites, the WLA-G54 also works as a point-to-point or point-to-multipoint bridge that's capable of communicating with up to six other Buffalo base stations--a quick, easy way to extend your wired network or improve your existing WLAN coverage. The WLA-G54 is packed with the latest security options to lock down your network. It offers both 64- and 128-bit WEP encryption, but the WLA-G54 also supports WPA and 802.1x. Remembering some of the WLA-G54's more complicated settings is easy because the bridge lets you save its configuration on a local PC. This feature, along with the recessed reset/initialization button on the back of the WLA-G54 that resets it to factory defaults, is very handy in case you find yourself locked out of the device. The only feature we didn't like were the unit's LEDs, which are positioned on the bridge's side and difficult to see. The performance of your Buffalo WLA-G54 will depend greatly on how you've configured it and what it is doing on your network. As an 802.11g access point, the WLA-G54 offers good range, with consistent and decent throughput up to around 100 feet before a swift decline. The Linksys WET54G performs better, but the WLA-G54 offers WDS, which the WET54G lacks. Assume a throughput hit when you configure the WLA-G54 (or most any wireless bridge) as both a bridge and an access point for wireless clients. That's because in a bridged network, configuration packets have to be transmitted over the WLAN once to get to the WLA-G54 bridge, then again from the bridge to the next Buffalo AirStation or client adapter connected to your wireless network.

source:www.review.cnet.com

Read more...

Introduction Linux Networking

Now that you have a firm grasp of many of the most commonly used networking concepts, it is time to apply them to the configuration of your server. Some of these activities are automatically covered during a Linux installation, but you will often find yourself having to know how to modify these initial settings whenever you need to move your server to another network, add a new network interface card or use an alternative means of connecting to the Internet.

In "Introduction to Networking", we started with an explanation of TCP/IP, so we'll start this Linux networking chapter with a discussion on how to configure the IP address of your server.


How to Configure Your NIC's IP Address

You need to know all the steps needed to configure IP addresses on a NIC card. Web site shopping cart applications frequently need an additional IP address dedicated to them. You also might need to add a secondary NIC interface to your server to handle data backups. Last but not least, you might just want to play around with the server to test your skills.

This section shows you how to do the most common server IP activities with the least amount of headaches.
Determining Your IP Address

Most modern PCs come with an Ethernet port. When Linux is installed, this device is called eth0. You can determine the IP address of this device with the ifconfig command.

[root@bigboy tmp]# ifconfig -a

eth0 Link encap:Ethernet HWaddr 00:08:C7:10:74:A8
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:11 Base address:0x1820

lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:787 errors:0 dropped:0 overruns:0 frame:0
TX packets:787 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:82644 (80.7 Kb) TX bytes:82644 (80.7 Kb)

wlan0 Link encap:Ethernet HWaddr 00:06:25:09:6A:B5
inet addr:192.168.1.100 Bcast:192.168.1.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:47379 errors:0 dropped:0 overruns:0 frame:0
TX packets:107900 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:4676853 (4.4 Mb) TX bytes:43209032 (41.2 Mb)
Interrupt:11 Memory:c887a000-c887b000

wlan0:0 Link encap:Ethernet HWaddr 00:06:25:09:6A:B5
inet addr:192.168.1.99 Bcast:192.168.1.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
Interrupt:11 Memory:c887a000-c887b000

[root@bigboy tmp]#


In this example, eth0 has no IP address because this box is using wireless interface wlan0 as its main NIC. Interface wlan0 has an IP address of 192.168.1.100 and a subnet mask of 255.255.255.0

You can see that this command gives good information on the interrupts, or PCI bus ID, used by each card. On very rare occasions you might find that your NIC card doesn't work because it shares both an interrupt and memory access address with some other device. You can look at the contents of the /proc/interrupts file to get a listing of all the interrupt IRQs used by your system. In the example below we can see that there are no conflicts with each IRQ from 0 to 15 having only a single entry. Devices eth0 and eth1 use interrupts 10 and 5, respectively:

[root@bigboy tmp]# cat /proc/interrupts
CPU0
0: 2707402473 XT-PIC timer
1: 67 XT-PIC i8042
2: 0 XT-PIC cascade
5: 411342 XT-PIC eth1
8: 1 XT-PIC rtc
10: 1898752 XT-PIC eth0
11: 0 XT-PIC uhci_hcd
12: 58 XT-PIC i8042
14: 5075806 XT-PIC ide0
15: 506 XT-PIC ide1
NMI: 0
ERR: 43
[root@bigboy tmp]#

If there are conflicts, you might need to refer to the manual for the offending device to try to determine ways to either use another interrupt or memory I/O location.
Changing Your IP Address

If you wanted, you could give this eth0 interface an IP address using the ifconfig command.

[root@bigboy tmp]# ifconfig eth0 10.0.0.1 netmask 255.255.255.0 up

The "up" at the end of the command activates the interface. To make this permanent each time you boot up you'll have to add this command in your /etc/rc.local file which is run at the end of every reboot.

Fedora Linux also makes life a little easier with interface configuration files located in the /etc/sysconfig/network-scripts directory. Interface eth0 has a file called ifcfg-eth0, eth1 uses ifcfg-eth1, and so on. You can place your IP address information in these files, which are then used to auto-configure your NICs when Linux boots. See Figure 3-1 for two samples of interface eth0. One assumes the interface has a fixed IP address, and the other assumes it requires an IP address assignment using DHCP.


Figure 3-1 - File formats for network-scripts
Fixed IP Address

[root@bigboy tmp]# cd /etc/sysconfig/network-scripts
[root@bigboy network-scripts]# cat ifcfg-eth0

#
# File: ifcfg-eth0
#
DEVICE=eth0
IPADDR=192.168.1.100
NETMASK=255.255.255.0
BOOTPROTO=static
ONBOOT=yes
#
# The following settings are optional
#
BROADCAST=192.168.1.255
NETWORK=192.168.1.0

[root@bigboy network-scripts]#

Getting the IP Address Using DHCP

[root@bigboy tmp]# cd /etc/sysconfig/network-scripts
[root@bigboy network-scripts]# cat ifcfg-eth0

#
# File: ifcfg-eth0
#
DEVICE=eth0
BOOTPROTO=dhcp
ONBOOT=yes

[root@bigboy network-scripts]#


As you can see eth0 will be activated on booting, because the parameter ONBOOT has the value yes and not no. You can read more about netmasks and DHCP in "Introduction to Networking", that acts as an introduction to networking.

The default RedHat/Fedora installation will include the broadcast and network options in the network-scripts file. These are optional.

After you change the values in the configuration files for the NIC you have to deactivate and activate it for the modifications to take effect. The ifdown and ifup commands can be used to do this:

[root@bigboy network-scripts]# ifdown eth0
[root@bigboy network-scripts]# ifup eth0

Your server will have to have a default gateway for it to be able to communicate with the Internet. This will be covered later in the chapter.
How DHCP Affects the DNS Server You Use

Your DHCP server not only supplies the IP address your Linux box should use, but also the desired DNS servers. When using DHCP for an interface, make sure your /etc/resolv.conf file has the servers configuration lines commented out to prevent any conflicts.
Multiple IP Addresses on a Single NIC

In the previous section "Determining Your IP Address" you may have noticed that there were two wireless interfaces: wlan0 and wlan0:0. Interface wlan0:0 is actually a child interface wlan0, a virtual subinterface also known as an IP alias. IP aliasing is one of the most common ways of creating multiple IP addresses associated with a single NIC. Aliases have the name format parent-interface-name:X, where X is the sub-interface number of your choice.

The process for creating an IP alias is very similar to the steps outlined for the real interface in the previous section, "Changing Your IP Address":

* First ensure the parent real interface exists
* Verify that no other IP aliases with the same name exists with the name you plan to use. In this we want to create interface wlan0:0.
* Create the virtual interface with the ifconfig command

[root@bigboy tmp]# ifconfig wlan0:0 192.168.1.99 netmask 255.255.255.0 up

* You should also create a /etc/sysconfig/network-scripts/ifcfg-wlan0:0 file so that the aliases will all be managed automatically with the ifup and ifdown commands. Here is a sample configuration:

DEVICE=wlan0:0
ONBOOT=yes
BOOTPROTO=static
IPADDR=192.168.1.99
NETMASK=255.255.255.0

The commands to activate and deactivate the alias interface would therefore be:

[root@bigboy tmp]# ifup wlan0:0
[root@bigboy tmp]# ifdown wlan0:0

Note: Shutting down the main interface also shuts down all its aliases too. Aliases can be shutdown independently of other interfaces.

After completing these four simple steps you should be able to ping the new IP alias from other servers on your network.
IP Address Assignment for a Direct DSL Connection

If you are using a DSL connection with fixed or static IP addresses, then the configuration steps are the same as those outlined earlier. You plug your Ethernet interface into the DSL modem, configure it with the IP address, subnet mask, broadcast address, and gateway information provided by your ISP and you should have connectivity when you restart your interface. Remember that you might also need to configure your DNS server correctly.

If you are using a DSL connection with a DHCP or dynamic IP address assignment, then the process is different. Your ISP will provide you with a PPP authentication over Ethernet (PPPoE) username and password which will allow your computer to login transparently to the Internet each time it boots up. Fedora Linux installs the rp-pppoe RPM software package required to support this.

Note: Unless you specifically request static IP addresses, your ISP will provide you with a DHCP based connection. The DHCP IP address assigned to your computer and/or Internet router will often not change for many days and you may be fooled into thinking it is static.

Downloading and installing RPMs isn't hard. If you need a refresher, "Installing Linux Software", on RPMs, covers how to do this in detail. When searching for the file, remember that the PPPoE RPM's filename usually starts with the word rp-pppoe followed by a version number like this: rp-pppoe-3.5-8.i386.rpm.

After installing the RPM, you need to go through a number of steps to complete the connection. The PPPOE configuration will create a software-based virtual interface named ppp0 that will use the physical Internet interface eth0 for connectivity. Here's what you need to do:

* Make a backup copy of your ifcfg-eth0 file.

[root@bigboy tmp]#
[root@bigboy tmp]# cd /etc/sysconfig/network-scripts/
[root@bigboy network-scripts]# ls ifcfg-eth0
ifcfg-eth0
[root@bigboy network-scripts]# cp ifcfg-eth0 DISABLED.ifcfg-eth0

* Edit your ifcfg-eth0 file to have no IP information and also to be deactivated on boot time.

DEVICE=eth0
ONBOOT=no

* Shutdown your eth0 interface.

[root@bigboy network-scripts]# ifdown eth0
[root@bigboy network-scripts]#

* Run the adsl-setup configuration script

[root@bigboy network-scripts]# adsl-setup

It will prompt you for your ISP username, the interface to be used (eth0) and whether you want to the connection to stay up indefinitely. We'll use defaults wherever possible.

Welcome to the ADSL client setup.� First, I will run some checks on

your system to make sure the PPPoE client is installed properly...

LOGIN NAME

Enter your Login Name (default root): bigboy-login@isp

INTERFACE

Enter the Ethernet interface connected to the ADSL modem
For Solaris, this is likely to be something like /dev/hme0.
For Linux, it will be ethX, where 'X' is a number.
(default eth0):

Do you want the link to come up on demand, or stay up continuously?
If you want it to come up on demand, enter the idle time in seconds
after which the link should be dropped.� If you want the link to
stay up permanently, enter 'no' (two letters, lower-case.)
NOTE: Demand-activated links do not interact well with dynamic IP
addresses. You might have some problems with demand-activated links.

Enter the demand value (default no):

It will then prompt you for your DNS server information. This step edits your /etc/resolv.conf file. If you're running BIND on your server in a caching DNS mode then you might want to leave this option blank. If you want your ISP to provide the IP address of its DNS server automatically then enter the word server.

Please refer to "Configuring DNS", for more information on BIND and DNS.

DNS

Please enter the IP address of your ISP's primary DNS server.
If your ISP claims that 'the server will provide dynamic DNS addresses', enter 'server' (all lower-case) here.
If you just press enter, I will assume you know what you are doing and not modify your DNS setup.
Enter the DNS information here:

The script will then prompt you for your ISP password

PASSWORD

Please enter your Password:
Please re-enter your Password:


Then it will ask whether you want regular users (not superuser root) to be able to activate/deactivate the new ppp0 interface. This may be required if non-root members of your family or home office need to get access to the Internet:

USERCTRL

Please enter 'yes' (two letters, lower-case.) if you want to allow normal user to start or stop DSL connection (default yes):

The rp-pppoe package has two sample iptables firewall scripts located in the /etc/ppp directory named firewall-standalone and firewall-masq. They are very basic and don't cover rules to make your Linux box a web server, DNS server, or mail server. I'd recommend selecting none and using a variant of the basic script samples in "Linux Firewalls Using iptables", or the more comprehensive one found in Appendix II, "Codes, Scripts, and Configurations".

FIREWALLING

Please choose the firewall rules to use. Note that these rules are very basic. You are strongly
encouraged to use a more sophisticated firewall setup; however, these will provide basic security.
If you are running any servers on your machine, you must choose 'NONE' and set up firewalling
yourself. Otherwise, the firewall rules will deny access to all standard servers like Web, e-mail,
ftp, etc. If you are using SSH, the rules will block outgoing SSH connections which allocate a
privileged source port.

The firewall choices are:

0 - NONE: This script will not set any firewall rules. You are responsible
for ensuring the security of your machine. You are STRONGLY
recommended to use some kind of firewall rules.
1 - STANDALONE: Appropriate for a basic stand-alone web-surfing workstation
2 - MASQUERADE: Appropriate for a machine acting as an Internet gateway
for a LAN

Choose a type of firewall (0-2): 0

You'll then be asked whether you want the connection to be activated upon booting. Most people would say yes.

Start this connection at boot time

Do you want to start this connection at boot time?
Please enter no or yes (default no):yes

Just before exiting, you'll get a summary of the parameters you entered and the relevant configuration files will be updated to reflect your choices when you accept them:

** Summary of what you entered **


Ethernet Interface: eth0

User name: bigboy-login@isp
Activate-on-demand: No
DNS: Do not adjust
Firewalling: NONE
User Control: yes
Accept these settings and adjust configuration files (y/n)? y

Adjusting /etc/sysconfig/network-scripts/ifcfg-ppp0
Adjusting /etc/ppp/chap-secrets and /etc/ppp/pap-secrets
(But first backing it up to /etc/ppp/chap-secrets.bak)
(But first backing it up to /etc/ppp/pap-secrets.bak)

At the very end it will tell you the commands to use to activate /deactivate your new ppp0 interface and to get a status of the interface's condition.

Congratulations, it should be all set up!

Type '/sbin/ifup ppp0' to bring up your xDSL link and '/sbin/ifdown ppp0'to bring it down.
Type '/sbin/adsl-status /etc/sysconfig/network-scripts/ifcfg-ppp0' to see the link status.


Note: This example recommends using the adsl-status command with the name of the PPPoE interface configuration file. This command defaults to show information for interface ppp0, and therefore listing the ifcfg-ppp0 filename won't be necessary in most home environments.

After you have completed installing rp-pppoe you should be able to access the Internet over your DHCP DSL connection as expected.


Some Important Files Created By adsl-setup

The adsl-setup script creates three files that will be of interest to you. The first is the ifcfg-ppp0 file with interface's link layer connection parameters

[root@bigboy network-scripts]# more ifcfg-ppp0
USERCTL=yes
BOOTPROTO=dialup
NAME=DSLppp0
DEVICE=ppp0
TYPE=xDSL
ONBOOT=yes
PIDFILE=/var/run/pppoe-adsl.pid
FIREWALL=NONE
PING=.
PPPOE_TIMEOUT=20
LCP_FAILURE=3
LCP_INTERVAL=80
CLAMPMSS=1412
CONNECT_POLL=6
CONNECT_TIMEOUT=60
DEFROUTE=yes
SYNCHRONOUS=no
ETH=eth0
PROVIDER=DSLppp0
USER= bigboy-login@isp
PEERDNS=no
[root@bigboy network-scripts]#

The others are the duplicate /etc/ppp/pap-secrets and /etc/ppp/chap-secrets files with the username and password needed to login to your ISP:

[root@bigboy network-scripts]# more /etc/ppp/pap-secrets
# Secrets for authentication using PAP
# client server secret IP addresses
"bigboy-login@isp" * "password"
[root@bigboy network-scripts]#


Simple Troubleshooting

You can run the adsl-status command to determine the condition of your connection. In this case the package has been installed but the interface hasn't been activated.

[root@bigboy tmp]# adsl-status
Note: You have enabled demand-connection; adsl-status may be inaccurate.
adsl-status: Link is attached to ppp0, but ppp0 is down
[root@bigboy tmp]#

After activation, the interface appears to work correctly.

[root@bigboy tmp]# ifup ppp0
[root@bigboy tmp]# adsl-status
adsl-status: Link is up and running on interface ppp0
ppp0: flags=8051 mtu 1462 inet
...
...
[root@bigboy tmp]#

For further troubleshooting information you can visit the Web site of rp-ppoe at Roaring Penguin (www.roaringpenguin.com). There are some good tips there on how to avoid problems with VPN clients.
IP Address Assignment for a Cable Modem Connection

Cable modems use DHCP to get their IP addresses so you can configure your server's Ethernet interface accordingly.
How to Activate/Shut Down Your NIC

The ifup and ifdown commands can be used respectively to activate and deactivate a NIC interface. You must have an ifcfg file in the /etc/sysconfig/network-scripts directory for these commands to work. Here is an example for interface eth0:


[root@bigboy tmp]# ifdown eth0
[root@bigboy tmp]# ifup eth0

How to View Your Current Routing Table

The netstat -nr command will provide the contents of the touting table. Networks with a gateway of 0.0.0.0 are usually directly connected to the interface. No gateway is needed to reach your own directly connected interface, so a gateway address of 0.0.0.0 seems appropriate. The route with a destination address of 0.0.0.0 is your default gateway.

* In this example there are two gateways, the default and one to 255.255.255.255 which is usually added on DHCP servers. Server bigboy is a DHCP server in this case.

[root@bigboy tmp]# netstat -nr

Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
255.255.255.255 0.0.0.0 255.255.255.255 UH 40 0 0 wlan0
192.168.1.0 0.0.0.0 255.255.255.0 U 40 0 0 wlan0
127.0.0.0 0.0.0.0 255.0.0.0 U 40 0 0 lo
0.0.0.0 192.168.1.1 0.0.0.0 UG 40 0 0 wlan0
[root@bigboy tmp]#

* In this example, there are multiple gateways handling traffic destined for different networks on different interfaces.

[root@bigboy tmp]# netstat -nr

Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
172.16.68.64 172.16.69.193 255.255.255.224 UG 40 0 0 eth1
172.16.11.96 172.16.69.193 255.255.255.224 UG 40 0 0 eth1
172.16.68.32 172.16.69.193 255.255.255.224 UG 40 0 0 eth1
172.16.67.0 172.16.67.135 255.255.255.224 UG 40 0 0 eth0
172.16.69.192 0.0.0.0 255.255.255.192 U 40 0 0 eth1
172.16.67.128 0.0.0.0 255.255.255.128 U 40 0 0 eth0
172.160.0 172.16.67.135 255.255.0.0 UG 40 0 0 eth0
172.16.0.0 172.16.67.131 255.240.0.0 UG 40 0 0 eth0
127.0.0.0 0.0.0.0 255.0.0.0 U 40 0 0 lo
0.0.0.0 172.16.69.193 0.0.0.0 UG 40 0 0 eth1
[root@bigboy tmp]#

How to Change Your Default Gateway

Your server needs to have a single default gateway. DHCP servers will automatically assign a default gateway to DHCP configured NICs, but NICs with configured static IP addresses will need to have a manually configured default gateway. This can be done with a simple command. This example uses a newly installed wireless interface called wlan0, most PCs would be using the standard Ethernet interface eth0.

[root@bigboy tmp]# route add default gw 192.168.1.1 wlan0

In this case, make sure that the router/firewall with IP address 192.168.1.1 is connected to the same network as interface wlan0!

Once done, you'll need to update your /etc/sysconfig/network file to reflect the change. This file is used to configure your default gateway each time Linux boots.

NETWORKING=yes
HOSTNAME=bigboy
GATEWAY=192.168.1.1

Note: In Debian based systems the default gateway is permanently defined in the /etc/network/interfaces file. See the section "Debian / Ubuntu Network Configuration" later in this chapter for more details.

Some people don't bother modifying network specific files and just place the route add command in the script file /etc/rc.d/rc.local which is run at the end of each reboot.

It is possible to define default gateways in the NIC configuration file in the /etc/sysconfig/network-scripts directory, but you run the risk of inadvertently assigning more than one default gateway when you have more than one NIC. This could cause connectivity problems. If one of the default gateways has no route to the intended destination, every other packet will become lost. Firewalls that are designed to block packets with irregular sequence numbers and unexpected origins could also obstruct your data flow.
How to Configure Two Gateways

Some networks may have multiple router/firewalls providing connectivity. Here's a typical scenario:

* You have one router providing access to the Internet that you'd like to have as your default gateway (see the default gateway example earlier)

* You also have another router providing access to your corporate network using addresses in the range 10.0.0.0 to 10.255.255.255. Let's assume that this router has an IP address of 192.168.1.254

The Linux box used in this example uses interface wlan0 for its Internet connectivity. You might be most likely using interface eth0, please adjust your steps accordingly.

There are a number of ways to add this new route.


Adding Temporary Static Routes

The route add command can be used to add new routes to your server that will last till the next reboot. It has the advantage of being univeral to all versions of Linux and is well documented in the man pages. In our example the reference to the 10.0.0.0 network has to be preceded with a -net switch and the subnet mask and gateway values also have to be preceded by the netmask and gw switches respectively.

[root@bigboy tmp]# route add -net 10.0.0.0 netmask 255.0.0.0 gw 192.168.1.254 wlan0

If you wanted to add a route to an individual server, then the "-host" switch would be used with no netmask value. (The route command automatically knows the mask should be 255.255.255.255). Here is an example for a route to host 10.0.0.1.

[root@bigboy tmp]# route add -host 10.0.0.1 gw 192.168.1.254 wlan0

A universal way of making this change persistent after a reboot would be to place this route add command in the file /etc/rc.d/rc.local, which is always run at the end of the booting process.
Adding Permanent Static Routes

In Fedora Linux, permanent static routes are added on a per interface basis in files located in the /etc/sysconfig/network-scripts directory. The filename format is route-interface-name so the filename for interface wlan0 would be route-wlan0.

The format of the file is quite intuitive with the target network coming in the first column followed by the word via and then the gateway's IP address. In our routing example, to set up a route to network 10.0.0.0 with a subnet mask of 255.0.0.0 (a mask with the first 8 bits set to 1) via the 192.168.1.254 gateway, we would have to configure file /etc/sysconfig/network-scripts/route-wlan0 to look like this:

#
# File /etc/sysconfig/network-scripts/route-wlan0
#
10.0.0.0/8 via 192.168.1.254

Note: The /etc/sysconfig/network-scripts/route-* filename is very important. Adding the wrong interface extension at the end will result in the routes not being added after the next reboot. There will also be no reported errors on the screen or any of the log files in the /var/log/ directory.

You can test the new file by running the /etc/sysconfig/network-scripts/ifup-routes command with the interface name as the sole argument. In the next example we check the routing table to see no routes to the 10.0.0.0 network and execute the ifup-routes command, which then adds the route:

[root@bigboy tmp]# netstat -nr

Kernel IP routing table

Destination Gateway Genmask Flags MSS Window irtt Iface
192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 wlan0
169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 wlan0
0.0.0.0 192.168.1.1 0.0.0.0 UG 0 0 0 wlan0
[root@bigboy tmp]# ./ifup-routes wlan0
[root@bigboy tmp]# netstat -nr
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 wlan0
169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 wlan0
10.0.0.0 192.168.1.254 255.0.0.0 UG 0 0 0 wlan0
0.0.0.0 192.168.1.1 0.0.0.0 UG 0 0 0 wlan0
[root@bigboy tmp]#

Note: In Debian based systems, permanent static routes are configured using the /etc/network/interfaces file. See the section "Debian / Ubuntu Network Configuration" later in this chapter for more details.
How to Delete a Route

Here's how to delete the routes added in the previous section.

[root@bigboy tmp]# route del -net 10.0.0.0 netmask 255.0.0.0 gw 192.168.1.254 wlan0

The file /etc/sysconfig/network-scripts/route-wlan0 will also have to be updated so that when you reboot the server will not reinsert the route. Delete the line that reads:

10.0.0.0/8 via 192.168.1.254

Changing NIC Speed and Duplex

There is no better Linux investment than the purchase of a fully Linux compatible NIC card. Most Linux vendors will have a list of compatible hardware on their Web sites: read this carefully before you start hooking up you machine to the network. If you can't find any of the desired models in your local computer store, then a model in the same family or series should be sufficient. Most cards will work, but only the fully compatible ones will provide you with error-free, consistent throughput.

Linux defaults to automatically negotiating the speed and duplex of it's NIC automatically with that of the switch to which it is attached. Configuring a switch port to auto-negotiate the speed and duplex often isn't sufficient because there are frequently differences in the implementation of the protocol standard.

Typically, NICs with failed negotiation will work, but this is usually accompanied by many collision type errors being seen on the NIC when using the ifconfig -a command and only marginal performance. Don't limit your troubleshooting of these types of errors to just failed negotiation; the problem could also be due to a bad NIC card, switch port, or cabling.


Using mii-tool

One of the original Linux tools for setting the speed and duplex of your NIC card was the mii-tool command. It is destined to be deprecated and replaced by the newer ethtool command, but many older NICs support only mii-tool so you'll need to be aware of it. Issuing the command without any arguments gives a brief status report, as seen in the next example, with unsupported NICs providing an Operation not supported message. NICs that are not compatible with mii-tool often will still work, but you have to refer to the manufacturer's guides to set the speed and duplex to anything but auto-negotiate.

[root@bigboy tmp]# mii-tool
SIOCGMIIPHY on 'eth0' failed: Operation not supported
eth1: 100 Mbit, half duplex, link ok
[root@bigboy tmp]#


By using the verbose mode -v switch you can get much more information. In this case, negotiation was OK, with the NIC selecting 100Mbps, full duplex mode (FD):

[root@bigboy tmp]# mii-tool -v
eth1: negotiated 100baseTx-FD, link ok
product info: vendor 00:10:18, model 33 rev 2
basic mode: autonegotiation enabled
basic status: autonegotiation complete, link ok
capabilities: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD
advertising: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD
link partner: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD flow-control
[root@bigboy tmp]#


Setting Your NIC's Speed Parameters with mii-tool

You can set your NIC to force itself to a particular speed and duplex by using the -F switch with any of the following options: 100baseTx-FD, 100baseTx-HD, 10baseT-FD, or 10baseT-HD. Remember that you could lose all network connectivity to your server if you force your NIC to a particular speed/duplex that doesn't match that of your switch:

[root@bigboy tmp]# mii-tool -F 100baseTx-FD eth0

Unfortunately there is no way to set this on reboot permanently except by placing it the command in the /etc/rc.local file to let it be run at the very end of the booting process or by creating your own startup script if you need it set earlier. Creating your own startup scripts is covered in "The Linux Boot Process".
Using ethtool

The ethtool command is slated to be the replacement for mii-tool in the near future and tends to be supported by newer NIC cards.

The command provides the status of the interface you provide as its argument. Here we see interface eth0 not doing autonegotiation and set to a speed of 100 Mbps, full duplex. A list of supported modes is also provided at the top of the output.

[root@bigboy tmp]# ethtool eth0
Settings for eth0:
Supported ports: [ TP MII ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
Supports auto-negotiation: Yes
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
Advertised auto-negotiation: No
Speed: 100Mb/s
Duplex: Full
Port: MII
PHYAD: 1
Transceiver: internal
Auto-negotiation: off
Supports Wake-on: g
Wake-on: g
Current message level: 0x00000007 (7)
Link detected: yes
[root@bigboy tmp]#


Setting Your NIC's Speed Parameters with ethtool

Unlike mii-tool, ethtool settings can be permanently set as part of the interface's configuration script with the ETHTOOL_OPTS variable. In our next example, the settings will be set to 100 Mbps, full duplex with no chance for auto-negotiation on the next reboot:


#
# File: /etc/sysconfig/network-scripts/ifcfg-eth0
#
DEVICE=eth0
IPADDR=192.168.1.100
NETMASK=255.255.255.0
BOOTPROTO=static
ONBOOT=yes
ETHTOOL_OPTS="speed 100 duplex full autoneg off"


You can test the application of these parameters by shutting down the interface and activating it again with the ifup and ifdown commands. These settings can also be changed from the command line using the -s switch followed by the interface name and its desired configuration parameters.

[root@bigboy tmp]# ethtool -s eth1 speed 100 duplex full autoneg off
[root@bigboy tmp]#

The Linux man pages give more details on other ethtool options, but you can get a quick guide by just entering the ethtool command alone, which provides a quicker summary.

[root@bigboy tmp]# ethtool
...
...
ethtool -s DEVNAME \
[ speed 10|100|1000 ] \
[ duplex half|full ] \
[ port tp|aui|bnc|mii|fibre ] \
...
...
[root@bigboy tmp]#

A Note About Duplex Settings

By default, Linux NICs negotiate their speed and duplex settings with the switch. This is done by exchanging electronic signals called Fast Link Pulses (FLP). When the speed and duplex are forced to a particular setting the FLPs are not sent. When a NIC is in auto-negotiation mode and detects a healthy, viable link but receives no FLPs, it errs on the side of caution and sets its duplex to half-duplex and sometimes it will also set its speed to the lowest configurable value. It is therefore possible to force a switch port to 100 Mbps full duplex, but have the auto-negotiating server NIC set itself to 100Mbps half-duplex which will result in errors. The same is true for the switch if the switch port is set to auto-negotiate and server NIC is set to 100 Mbps full duplex. It is best to either force both the switch port and server NIC to either auto-negotiate or the same forced speed and duplex values.
How to Convert Your Linux Server into a Simple Router

Router/firewall appliances that provide basic Internet connectivity for a small office or home network are becoming more affordable every day, but when budgets are tight you might seriously want to consider modifying an existing Linux server to do the job.

Details on how to configure Linux firewall security are covered in "Linux Firewalls Using iptables", but you need to understand how to activate routing through the firewall before it can become a functioning networking device.


Configuring IP Forwarding

For your Linux server to become a router, you have to enable packet forwarding. In simple terms packet forwarding enables packets to flow through the Linux box from one network to another. The Linux kernel configuration parameter to activate this is named net.ipv4.ip_forward and can be found in the file /etc/sysctl.conf. Remove the "#" from the line related to packet forwarding.

Before:

# Disables packet forwarding
net.ipv4.ip_forward=0

After:

# Enables packet forwarding
net.ipv4.ip_forward=1


This enables packet forwarding only when you reboot at which time Linux will create a file in one of the subdirectories of the special RAM memory-based /proc filesystem. To activate the feature immediately you have to force Linux to read the /etc/sysctl.conf file with the sysctl command using the -p switch. Here is how it's done:

[root@bigboy tmp] sysctl -p
sysctl -p
net.ipv4.ip_forward = 1
net.ipv4.conf.default.rp_filter = 1
kernel.sysrq = 0
kernel.core_uses_pid = 1
[root@bigboy tmp]#


Please refer to Appendix I for more information on adjusting kernel parameters.


Configuring Proxy ARP

If a server needs to send a packet to another device on the same network, it sends out an ARP request to the network asking for the MAC address of the other device.

If the same server needs to send a packet to another device on a remote network the process is different. The server first takes a look at its routing table to find out the IP address of the best router on its network that will be able to relay the packet to the destination. The server then sends an ARP request for the MAC address that matches the router's IP address. It then sends the packet to the router using the router's MAC address and a destination IP address of the remote server.

If there is no suitable router on its network, the server will then send out an ARP request for the MAC address of the remote server. Some routers can be configured to answer these types of ARP requests for remote networks. This feature is called proxy ARP. There are some disadvantages with this. One of the most common problems occurs if two routers are on the network configured for proxy ARP. In this scenario there is the possibility that either one will answer the local server's ARP request for the MAC address of the remote server. If one of the routers has an incorrect routing table entry for the remote network, then there is the risk that traffic to the remote server will occasionally get lost. In other words you can lose routing control.

Note: It is for this and other reasons that it is generally not a good idea to configure proxy ARP on a router. It is also good to always configure a default gateway on your server and use separate routing entries via other routers for all networks your default gateway may not know about.

Some types of bridging mode firewalls need to have proxy ARP enabled to operate properly. These devices are typically inserted as part of a daisy chain connecting multiple network switches together on the same LAN while protecting one section of a LAN from traffic originating on another section. The firewall typically isn't configured with an IP address on the LAN and appears to be an intelligent cable capable of selectively blocking packets.

If you need to enable proxy ARP on a Linux server the /proc filesystem comes into play again. Proxy ARP is handled by files in the /proc/sys/net/ipv4/conf/ directory. This directory then has subdirectories corresponding to each functioning NIC card on your server. Each subdirectory then has a file called proxy_arp. If the value within this file is 0, then proxy ARP on the interface is disabled; if the value is 1 then it is enabled.

You can use the /etc/sysctl.conf file mentioned in Appendix II to activate or disable proxy ARP. The next example activates proxy ARP, first for all interfaces and then for interfaces eth0 and wlan0.

#
# File: /etc/sysctl.conf
#

# Enables Proxy ARP on all interfaces
net/ipv4/conf/all/proxy_arp = 1

# Enables Proxy ARP on interfaces eth1 and wlan0
net/ipv4/conf/eth1/proxy_arp = 1
net/ipv4/conf/wlan0/proxy_arp = 1


You can then activate these settings with the sysctl command.

[root@bigboy tmp] sysctl -p

Configuring Your /etc/hosts File

The /etc/hosts file is just a list of IP addresses and their corresponding server names. Your server will typically check this file before referencing DNS. If the name is found with a corresponding IP address then DNS won't be queried at all. Unfortunately, if the IP address for that host changes, you also have to also update the file. This may not be much of a concern for a single server, but can become laborious if it has to be done companywide. For ease of management, it is often easiest to limit entries in this file to just the loopback interface and also the server's own hostname, and use a centralized DNS server to handle most of the rest. Sometimes you might not be the one managing the DNS server, and in such cases it may be easier to add a quick /etc/hosts file entry till the centralized change can be made.

192.168.1.101 smallfry


In the example above server smallfry has an IP address of 192.168.1.101. You can access 192.168.1.101 using the ping, telnet or any other network aware program by referring to it as smallfry. Here is an example using the ping command to see whether smallfry is alive and well on the network:

[root@bigboy tmp]# ping smallfry
PING zero (192.168.1.101) 56(84) bytes of data.
64 bytes from smallfry (192.168.1.101): icmp_seq=0 ttl=64 time=0.197 ms
64 bytes from smallfry (192.168.1.101): icmp_seq=1 ttl=64 time=0.047 ms


--- smallfry ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 2017ms
rtt min/avg/max/mdev = 0.034/0.092/0.197/0.074 ms, pipe 2
[root@bigboy tmp]#


You can also add aliases to the end of the line which enable you to refer to the server using other names. Here we have set it up so that smallfry can also be accessed using the names tiny and littleguy.

192.168.1.101 smallfry tiny littleguy


You should never have an IP address more than once in this file because Linux will use only the values in the first entry it finds.

192.168.1.101 smallfry # (Wrong)
192.168.1.101 tiny # (Wrong)
192.168.1.101 littleguy # (Wrong)


The loopback Interface's localhost Entry

Usually the first entry in /etc/hosts defines the IP address of the server's virtual loopback interface. This is usually mapped to the name localhost.localdomain (the universal name used when a server refers to itself) and localhost (the shortened alias name). By default, Fedora inserts the hostname of the server between the 127.0.0.1 and the localhost entries like this:

127.0.0.1 bigboy localhost.localdomain localhost


When the server is connected to the Internet this first entry after the 127.0.0.1 needs to be the fully qualified domain name (FQDN) of the server. For example, bigboy.mysite.com, like this:

127.0.0.1 bigboy.my-site.com localhost.localdomain localhost


Some programs such as Sendmail are very sensitive to this and if they detect what they feel is an incorrect FQDN they will default to using the name localhost.localdomain when communicating with another server on the network. This can cause confusion, as the other server also feels it is localhost.localdomain.

Note: You must always have a localhost and localhost.localdomain entry mapping to 127.0.0.1 for Linux to work properly and securely.
Debian / Ubuntu Network Configuration

Many of the core Fedora / Redhat commands and configuration files covered in this chapter can be used in Debian based operating systems, but there are some key differences.
The /etc/network/interfaces File

The main network configuration file is the /etc/network/interfaces file in which all the network interface parameters are defined. The file is divided into stanzas:
The auto Stanza

The auto stanza defines the interfaces that should be automatically initialized when the system boots up.
The mapping Stanza

This stanza maps configuration parameters for an interface depending on the output of a script. For example, on booting the script could prompt you as to whether your laptop Linux system is at home or work with the mapping statement using the answer to configure the appropriate IP address.

By default the much simpler hotplug system is used which assumes that the interfaces will have only one purpose. Typical hotplug configurations simply assign each physical interface with a matching logical interface name (nick name).

mapping hotplug
script grep
map eth0 eth0
map eth1

In this case interface eth0 is specifically given the logical name eth0, while the logical name for eth1 is implied to be the same.
The iface Stanza

The iface stanza defines the characteristics of a logical interface. Typically the first line of these stanzas starts with the word iface, followed by the logical name of the interface, the protocol used, and finally the type of addressing scheme to be used, such as DHCP or static. Protocol keywords include inet for regular TCP/IP, inet6 for IPv6, ipx for the older IPX protocol used by Novell, and loopback for loopback addresses.

Subsequent lines in the stanza define protocol characteristics such as addresses, subnet masks, and default gateways. In this example, interface eth1 is given the IP address 216.10.119.240/27 while interface eth0 gets its IP address using DHCP.

# The primary network interface
auto eth1
iface eth1 inet static
address 216.10.119.240
netmask 255.255.255.224
network 216.10.119.224
broadcast 216.10.119.255
gateway 216.10.119.241
dns-nameservers 216.10.119.241

# The secondary network interface
auto eth0
iface eth0 inet dhcp

Note: When static IP addresses are used, a default gateway usually needs to be defined. Remember to place the gateway statement in the correct stanza with the appropriate router IP address.
Creating Interface Aliases

IP aliases can be easily created in the /etc/network/interfaces file once the main interface has already been defined. A modified duplicate of the main interfaces' iface stanza is required. A colon followed by the sub interface number needs to be added to the first line, and only the subnet mask and the new IP address needs to follow as can be seen in this example for interface eth1:1 with the IP address 216.10.119.239.

auto eth1:1
iface eth1:1 inet static
address 216.10.119.239
netmask 255.255.255.224

Adding Permanent Static Routes

The up option in the appropriate iface stanza of the /etc/network/interfaces file allows you to selectively run commands once the specified interface becomes activated with the ifup command. This makes it useful when adding permanent static routes.

In this example, a route to the 10.0.0.0/8 network via router address 216.10.119.225 has been added. Remember, the up option and the command must reside on the same line of the stanza.

# The primary network interface
auto eth1
iface eth1 inet static
...
...
...
up route add -net 10.0.0.0 netmask 255.0.0.0 gw 216.10.119.225 eth1

A complete /etc/network/interfaces file

We can now construct a complete file based on the previous examples we discussed. Just like in Fedora, interfaces can be activated with the ifup and ifdown commands.

#
# Debian / Ubuntu
#

#
# File: /etc/network/interfaces
#

# The loopback network interface
auto lo
iface lo inet loopback

# This is a list of hotpluggable network interfaces.
# They will be activated automatically by the hotplug subsystem.
mapping hotplug
script grep
map eth0 eth0
map eth1 eth1

# The primary network interface
auto eth1
iface eth1 inet static
address 216.10.119.240
netmask 255.255.255.224
network 216.10.119.224
broadcast 216.10.119.255
gateway 216.10.119.241
# dns-* options are implemented by the resolvconf package, if installed
dns-nameservers 216.10.119.241
wireless-key 98d126d5ac
wireless-essid schaaffe

up route add -net 10.0.0.0 netmask 255.0.0.0 gw 216.10.119.225 eth1

auto eth1:1
iface eth1:1 inet static
address 216.10.119.239
netmask 255.255.255.224

# The secondary network interface
auto eth0
iface eth0 inet dhcp


For more information on the /etc/network/interfaces file just issue the command man interfaces from the command line.


source : www.linuxnetworking.com

Read more...
dh@nex_sucks2008
Back to TOP