So after Mark [1] and I helped John the paper millionaire of a dotcom get connected, I downloaded a network monitor I wrote and installed it on his system (some problems due to some changes in the way dlopen() works internally that I was relying on).
It was interesting to see some of the network activity he gets at his end of the connection. It seems his cable provider uses private IP addresses for something. I'm not sure all of what was flowing through since the monitor only shows packet headers and not the data, but it would be interesting to find out.