The Silence of the Packets

As part of my ongoing attempt to simplify my IT infrastructure at home I recently decided to replace my NetBSD firewall and the external DSL modem with a router appliance. The list of advantages was long:

  1. Less noise and power consumption, the firewall was a SPARCstation 20.
  2. One less UN*X system to look after.
  3. Less power bricks under my desk.
  4. No more MTU problems caused by PPPoA to PPPoE bridging.
  5. More reliable (than the Linksys DSL modem).

Unfortunately my requirement list for a DSL router was long:

  1. Normal routing for public IP address
  2. NAT for non-public IP address
  3. IPv6 support
  4. IPsec VPN support
  5. Flexible packet filter rules
  6. Proper administration interface
  7. SNMP support (for MRTG)
  8. Configuration file backup and restore
  9. ADSL 2+ support (for future use)

I searched the web for possible candidates and found exactly one: the Cisco 877W.

Cisco 877W

I was not to happy about this because my previous jobs taught me that Cisco equipment can cause a lot of trouble:

  1. The IOS version that is installed on your Cisco never supports all the features you need.
  2. The IOS version which supports all those features requires more memory and/or a larger flash card than your Cisco is equipped with.
  3. At least a part of the necessary configuration will be completely unobvious and you have to search the web or ask arround to figure it out.
  4. You will reach a point where it seems to work. Just when you enjoy your success it will break horribly.
  5. Cisco will not allow you to download a firmware update without a support contract even if it fixes a critical security hole.

I bought a Cisco 877W (with an extra 802.11g WLAN option) nevertheless. And of course things went wrong:

  1. Despite being advertised as supporting IPv6 it did not.
  2. The IOS version with IPv6 support required a larger flash card.
  3. The first flash card upgrade I received was broken. I didn’t realized that immediately of course but spent hours figuring out why format flash: wasn’t working.
  4. Configuring the DSL connection on the 877W is tricky. You can’t simply take the obvious approach and use the ATM interface. You need to create a Dialer interface (sounds archaic, doesn’t it?) and tell that to use the ATM interface for “dialing” out. Fortunately Google found a useful example configuration.
  5. When I finally got the Cisco working as a router (with the NetBSD firewall still providing packet filtering and NAT) I was pleased. But 10 minutes later the DSL connection went down. It happened again and again until I finally had to switch back to the Linksys DSL modem. Before I did that my Internet link wasn’t even stable enough to search the web for a solution. I posted a question to the Usenet and got a lot of unhelpful comments suggesting that my phone line was probably bad. Finally somebody pointed out to that Cisco is distributing firmware updates for the builtin DSL modem of the 877W on their public FTP server. I installed version 3.0.10 of the firmware,connect the phone line to the Cisco again and this time it really worked fine.

But getting basic routing functionality working was of course only half the story. I still needed to write Cisco IOS packet filter rules (for IPv4 and IPv6) and get NAT working. I had to postpone doing that several times mostly because of problems with the backup mail server for my domains. Last Friday I finally managed to write the IPv4 packet filter rules despite spending most of the day on maintenance of that backup mail server. On Saturday I found time to write the IPv6 rules, After a nice relaxing walk through the Botanic Garden I got NAT working on Sunday.

Now it was time to put the old firewall out of operation. My wife and I removed a stack of old hardware first:

SPARCstation 20, switch and DSL modem

The old Wireless Access Point had to stay because the IOS version currently installed on my Cisco 877W doesn’t support bridging IPv6 for some weird reason. There is a IOS version which does but who knows how to get it.

We set up the Cisco, connected all the cables and powered the router up. For some unknown reasons the universe showed mercy and everything just worked fine without further problems. It has worked fine ever since and I’m still enjoying The Silence of the Packets because the SPARCstation 20 is no longer making a lot of noise.

Expulsion from Paradise: The Journey Home

Our last day on Tenerife began pleasantly: we enjoyed the breakfast buffet, calmly packed our belongings and checked out in time. As we had a few hours left before we had to get to the airport we drove to El Medano, a small city on the south coast. After a walk along the beach and through the city center we had lunch in a nice cafe and wrote some postcards.

We arrived at the airport in good time and returned our rental car without problems. But when we checked the departure information display we found out that our flight would be delayed for more than an hour. After an extra long waiting time we could finally board the airplane and learned that unscheduled maintenance at London Luton Airport had caused the delay.

The flight felt less pleasant than the flight to Tenerife. There were more people than on the outward journey and therefore more noise and less space. As I didn’t like the movie and finished my book after about two hours I was bored during the second half of the flight. And by the time we finally landed in London Luton Airport arround 1:00 am I was also exhausted.

The next unpleasant surprise awaited us at the car park: our car had a flat tyre. Despite our fatigue and the freezing temperatures we managed to change the tyre although neither of us had done such a thing before. We arrived in Cambridge arround 3:30am and were very happy to finally get some sleep.

Cuty Cat on el Pico del Teide

Today was the day my wife Silke and I tried to climb the top of the Teide. Doing that was one of the main reasons that my wife wanted to visit Tenerife in the first place. After driving for about one and a half hours through the mountains on a road with a lot of the usual serpentines we arrived at the base station of the cablecar going up to the top of the Teide. We queued for about 45 minutes to get tickets and to get in the gondola.

On the way up my problems started: I got struck by Altitude Sickness (combined with a bit of vertigo). Both my feet and hands went numb and started suffering from pins and needles and I felt dizzy. With some effort and loving help from my wife I managed to stay on my feet until we reached the top station. We went outside and I sat down on a bench. After a few minutes the symptoms eased and I suggested that we try to climb up the 163m to the peak.

The path leading to the peak however was narrow and steep and I was still struggling to adapt to the altitude. We made it up about one third of the way before I had to give up. Because my wife dealt with the conditions much better I asked her to go on. Thanks to her determination she made it all the way up to the peak and took some great pictures. This one shows the crater of the original volcano Las CaƱadas. The Teide rises on the north side of this crater:

View from the top of Teide

It took Silke almost two hours to get to the peak, take a rest and climb down again. After she came back we returned via cable car and the ever present serpentines to the hotel where we enjoyed a well deserved victory feast. Being able to breathe easy again was an additional bonus.

Taking comfort in the Unfairness of the Universe