After three months of installation and extensive testing, I put NAT into production on November 5, 1997. This system provides network address translation, routing, and firewall functions. As of today (December 8), there have been no problems with the production system. I had a serious networking problem during my testing, but that was strictly a hardware issue (an old, perhaps flakey 3C503 NIC), not a NAT problem. This problem took almost a month to eradicate. Because my NAT setup is somewhat complex and because I have restrictions on the use of static routes in our routers, I created an ARP patch so that Linux would generate proxy ARPs for my "virtual hosts". You can find a discussion of the ARP patch on this forum at /~mha/HyperNews/get/linux-ip-nat/22.html. |