Jump to content

Recommended Posts

Posted (edited)

Got BT Infinity at home but want to use a Virtual based Firewall. Do not want double NAT so would rather present the public IP direct to the firewall.

 

Got a BT OpenReach modem on the way as this might provide solution but are there any other products, was considering the Vigor 130 but going off draytek.

 

I have a dedicated NIC for the external traffic.

Edited by Davit2005
Posted

I'd have to agree, not really had any problems at all with Draytek kit.

 

Used their products for a few of the small businesses I work with and no problems at all.

Posted (edited)

The only thing that bugs me is a reboot for most things is required. Specially when you are setting up, jus a bit annoying.

 

And I too have had experience of DrayTeks since 2006 (Vigor 2600's) so know they are reliable. We prob had 5000 customers and I replaced 4 in my time there but these were all used in commercial environment.

 

The Vigor 130 also seems a bit pricey but I will test the BT OpenReach and see how it goes.

 

Has anyone had experience configuring a Vigor to act as Modem only??????

Edited by Davit2005
Posted
I use a Vigor 130 with a Mikrotik router, it's a transparent bridge, so you should just be able to plug it into your routing device and be good to go. I also set up a NAT rule on my router so I could still access the web config page from my internal network when connected to the internet (useful to see modem stats). I'm very happy with the performance and reliability.
  • Thanks 1
Posted (edited)
I use a Vigor 130 with a Mikrotik router, it's a transparent bridge, so you should just be able to plug it into your routing device and be good to go. I also set up a NAT rule on my router so I could still access the web config page from my internal network when connected to the internet (useful to see modem stats). I'm very happy with the performance and reliability.

 

Might go the whole hog and go Vigor. Does it present as a Public IP or Private to the MikroTik or can it do both??

 

I may go for a few Public IP's so would want these passed thru to the firewall to deal with i.e. NAT rules to different internal servers and then a different public IP for Internal to External traffic.

Edited by Davit2005
Posted
Might go the whole hog and go Vigor. Does it present as a Public IP or Private to the MikroTik or can it do both??

 

I may go for a few Public IP's so would want these passed thru to the firewall to deal with i.e. NAT rules to different internal servers and then a different public IP for Internal to External traffic.

 

"Bridge (pass) a single IP address or a whole public subnet"

 

Vigor 130 ADSL/VDSL Modem

 

I do this in school without the Vigor. Eclipse Internet > Openreach Modem > Sophos UTM. Passes our public IP block through fine.

Posted (edited)

If I plug straight into this device I get a public IP. I would connect PFsesne to this, and use that for NAT and routing. You get a firewall as you wanted, can do it virtual machine and no double NAT. Draytek is ok but its not really a Firewall. Its more or a router with some firewall features and not massively better than Netgear in that respect.

 

This is the only solution suggested that is virtual as you requested :)

 

http://www.increasebroadbandspeed.co.uk/wp-content/uploads/2013/12/bt-openreach-modem.jpg

Edited by FN-GM
  • Thanks 1
Posted (edited)

The Openreach modem arrived yesterday. Was a doodle to install, jus worked. On the Firewall I setup the PPPoE client and apart from a few minor changes have even managed to get the SSL VPN client working on the Firewall.

 

Speeds not that much different.

 

The only issue I am having is getting the NAT rules setup for my internal personal web server which sits in a DMZ as I have no public static IP. The firewall is a PaloAlto VM-100, I've tried setting up loopback interfaces but to no avail. I can see traffic coming in through the interface in a packet capture to the right port but no joy on the NAT. On the firewall unfortunately you have to specify an IP for the Translation to work doesn't accept an FQDN.

 

Apart from a Software upgrade on the firewall I can't think of anything else to try, may have to pay the extra £10 per month for a static IP :-( . Got a dedicated NIC for the WAN traffic going straight to the Virtual firewall.

 

The DrayTek IS limited as a firewall and on some customer sites we used to pass all the traffic through to an alternative firewall instead if they ran internal services or SIP trunks.

 

@FN-GM , is yours a Huawei or ECI Modem. Wish I done my research and bought a Huawei which are easier to hack.

 

Also I believe that BT will stop replacing the BT Openreach modem in 20017

Edited by Davit2005
Posted
@FN-GM , is yours a Huawei or ECI Modem. Wish I done my research and bought a Huawei which are easier to hack.

 

If i am honest I don't have a clue, I will check though :)

Posted

The only issue I am having is getting the NAT rules setup for my internal personal web server which sits in a DMZ as I have no public static IP. The firewall is a PaloAlto VM-100, I've tried setting up loopback interfaces but to no avail. I can see traffic coming in through the interface in a packet capture to the right port but no joy on the NAT. On the firewall unfortunately you have to specify an IP for the Translation to work doesn't accept an FQDN.

 

Apart from a Software upgrade on the firewall I can't think of anything else to try, may have to pay the extra £10 per month for a static IP :-( . Got a dedicated NIC for the WAN traffic going straight to the Virtual firewall.

 

You need to set up a dynamic DNS updater:

 

http://chasechristian.com/blog/2013/02/palo-alto-networks-using-a-dynamic-public-ip-address/

Posted (edited)

 

You are a lifesaver :-) . knew it was simple NAT issue but that article, what a find I was searching for hours and the one thing I didn't try.

 

Already use a Dynamic DNS service so a minor change and all working thanks a MILLION :rolleyes: :cool:

Edited by Davit2005
Posted
+1 for draytek 130, great bit of kit. Also make sure you have installed an NTE5c (mk4) faceplate to get the max out of your connection.
Posted
If I plug straight into this device I get a public IP. I would connect PFsesne to this, and use that for NAT and routing. You get a firewall as you wanted, can do it virtual machine and no double NAT. Draytek is ok but its not really a Firewall. Its more or a router with some firewall features and not massively better than Netgear in that respect.

 

This is the only solution suggested that is virtual as you requested :)

 

http://www.increasebroadbandspeed.co.uk/wp-content/uploads/2013/12/bt-openreach-modem.jpg

This is exactly what I do except physically, but you could virtualise - https://forum.pfsense.org/index.php?PHPSESSID=69ql6sbcqnb81f8t60p6bgcd41&board=37.0

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...