Page 1 of 1 1
Topic Options
#206511 - 2012-12-30 01:19 AM Connecting small business to Fibre Optic Broadband
Robdutoit Offline
Hey THIS is FUN
***

Registered: 2012-03-27
Posts: 363
Loc: London, England
I thought that I would just ask for some general feedback on how companies are accessing fibre optic broadband.
My dilemma is with the issue that fibre optic broadband in this country seems to require you to use a BT modem which supports VDSl for BT Infinity and then you need to either connect a router such as the BT Business Hub to connect to the modem or the other option is that you can connect a computer and configure the one network card to use PPPOE.

I suspect most companies don't set up a computer with a network card using PPPOE because most companies use a dedicated firewall which probably cannot configure a network port as a PPPOE connection, so I must assume that the scenario in most companies is this setup:

Internet - BT Modem - BT router (with own firewall) - Then the companies real firewall and then the LAN

which means that if you want to setup remote access, you have to setup the Internet router (BT business router in this example) to "forward" the traffic to your companies real firewall and then your companies real firewall needs to forward that onto the remote access server. I put "forward" in inverted commas as I realise that firewall is not actually "forwarding" the traffic as its not preforming NAT functions.

I was thinking of getting a Draytek 2850 integrated modem and router and completely bypass the BT Modem and the BT Router (less products chewing electricity and that can go wrong). However, it seems kind of silly to have a presumably good firewall on the Draytek and then still have my Linux box acting as the proper firewall - there will be no DMZ, so it would really be just duplication.

So if I can figure out how to configure Slackware Linux to setup the network card as a PPPOE connection on the Internet side, I probably will go ahead with that as the Draytek would effectively be duplicating everything that my slackware box is going to do.

But I was just wondering how other companies handle the issue of a standard firewall box not really having WAN capability and all the WAN capable devices come with their own blasted firewall, which just makes everything duplicated for no good purpose as there is no DMZ. I am looking at the whole issue from the point of view of providing remote access from outside into the LAN as the idea is to enable workers to access the Server from home so as to access their data without having to come in. This would be done via a secure VPN. But having a firewall on the broadband router and another firewall on the slackware box would make it very difficult to troubleshoot. So how do other companies handle connecting to ADSL or fibre optic. do you guys use broadband routers like Draytek or whichever manufacturer and do you only have your firewall on your "broadband router" or do you do something similar to what I am looking to do? Thanks

Hope that everyone had a great Xmas. Went way too fast for me sadly ! Oh well, New years is still to come!

Top
#206512 - 2012-12-30 01:32 AM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
ok, that just looks insane.
a) why would someone order fiber with speeds slower than dsl? you can get up 100/100 with vdsl, so this is stupid
b) they say phone socket, so it is not actual fiber after all. just another form of dsl. so why bother?
c) pppoe is the worst type of connection you can have, speaking from experience. you can have your own modem hook up to pppoe connection in a bridge modem but it needs to reauth every now and then for whatever reason and you will be waiting for connection in the middle of the day for few minutes every time.

what comes to the draytek, yes, it is just fine as a router/modem/wireless ap/firewall as any other 30 dollar device.
if you think that is all the security you need, go ahead.
lot of companies do. but don't get fooled by thinking it can in anyway compare to a real firewall, or real AP or real router or real anything.
it is a compromise from the start up.
_________________________
!

download KiXnet

Top
#206513 - 2012-12-30 02:01 AM Re: Connecting small business to Fibre Optic Broadband [Re: Lonkero]
Glenn Barnas Administrator Offline
KiX Supporter
*****

Registered: 2003-01-28
Posts: 4402
Loc: New Jersey
All I'll add to Lonk's (right-on) comment is "Just because you can, doesn't mean you should!"

FYI - refurbished Cisco ASA 5505's are $1-200 US on eBay, including VPN. No home-brew hacks.

Glenn
_________________________
Actually I am a Rocket Scientist! \:D

Top
#206514 - 2013-01-02 09:13 AM Re: Connecting small business to Fibre Optic Broadband [Re: Glenn Barnas]
Arend_ Moderator Offline
MM club member
*****

Registered: 2005-01-17
Posts: 1896
Loc: Hilversum, The Netherlands
Lonk: You're forgetting Rob is on the "Island" they don't get the speeds we get on the mainland. We're having issue's with our company as well as one of our subsidiaries (my favourite) is based there.
The fastest fiber we got over there is 30/30.

PPPoE isn't as bad as you think, most of our Fiber Optic lines here in NL are connected through that as well. At home for instance I got 50/50 Fiber using PPPoE, last time I checked I had an uptime for over 200 days, a lot of days I got constant streaming going on with no delays or hiccups.

As far as connecting goes, most Fiber Optic lines are working with VLAN's and PPPoE.
Personally I got a Cisco switch handling the VLAN's and a Draytek for the PPPoE & Firewall.

Top
#206515 - 2013-01-02 01:27 PM Re: Connecting small business to Fibre Optic Broadband [Re: Arend_]
Robdutoit Offline
Hey THIS is FUN
***

Registered: 2012-03-27
Posts: 363
Loc: London, England
I don't know how broadband works elsewhere in the world, but the fact is that BT's fibre optic offers the best value for money for my particular clients. My understanding is that broadband speeds in England are significantly slower than what you guys get on the mainland.
Remember everything here in privatised for efficiency of course! In reality we just pay more and get less!
a: Dsl is not cost effective - the last time that I looked.
b: Yes you connect into a phone socket because its FTTC not FTTP in other words, its fibre optic from exchange to the cabinet in your street and then plain telephone cable from the box in your street to your house. This makes a huge difference because ADSL which is the predominant type of Internet in this country suffers from speed issues because of the distance from the exchange to your house. This has made ADSL useless for business use unless your business is right on top of the exchange. I presume that DSL suffers from the same problem. So yes, its not 100% fibre optic, but the distance from the box in your street to your house is neglible compared to the distance from your house to the exchange which is the real problem with ADSL.
C: PPPOE is actually quite alright. The biggest problem with it has always been line attenuation. But that again is an ADSL issue. And the second issue is the quality of the broadband router as many of them are rubbish.

I appreciate that DSL may work for you Lonkero and Glenn, but not in England. The telephone infrastructure in this country is ridiculous. Anyway putting aside the issue of what broadband each country uses, the question was more to do with how people connect to the Internet and where their firewalls sits with regards to the lan and actual Internet.

You misunderstood me Lonkero, I don't want to use the Draytek for firewalling, I was merely considering it from the point of view of getting the PPPOE connection setup as you can't just plug the modem into the firewall and expect it to work. I may look at the PPPOE nic card solution.

My clients can expect to get between 50-76Mb download speeds which is more than 3 times faster than what they are currently getting and they will be paying significantly less, therefore fibre optic is the way to go for my clients.

Interesting that your companies use Draytek as well Arend. I don't want to use the Draytek for a firewall because I do feel that my slackware box is far better, oarticularly as the slackware box is what will drive the content filtering. So essentially speaking I think I will go with my slackware box setup for PPPoe configuration as the Draytek is just duplication.

I also use Cisco Switches as well lol. anyway thanks for all the feedback.

Top
#206516 - 2013-01-03 11:01 AM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11634
Loc: Space
Well not sure why but our satellite office in the Netherlands has a crappy slow connection too. They're supposed to get something like 50Mbps soon but I was surprised because when you look at many other parts of Europe you see where they have very fast fiber connections.

I guess maybe if you're in a pocket area - tough luck.

Top
#206519 - 2013-01-04 12:52 AM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
well, rob...
that draytek device you said you are considering IS a DSL modem!
so, no matter how much they say you get on fiber optic connection, that is BS.
you get a DSL connection.
and with that modem it is either aDSL or vDSL.

has nothing to do with fiber. how the company does their backbone or mainlines does not change your connection type.
_________________________
!

download KiXnet

Top
#206521 - 2013-01-04 02:25 PM Re: Connecting small business to Fibre Optic Broadband [Re: Lonkero]
Robdutoit Offline
Hey THIS is FUN
***

Registered: 2012-03-27
Posts: 363
Loc: London, England
I think that I understand what you are saying Lonk. It may not be true fibre optic in technical terms. I believe it uses vdsl. The point is, my clients currently pay almost twice the price for a broadband of less than 20Mb and we have no control over the firewall as my clients connect through the council. The clients that I am referring to are primary schools. I am offering them broadband speeds that are nearly 3 times faster and half the price. I have used BT's speed test which is supposed to be very accurate to determine exactly what speed the clients will end up getting. In addition, the primary schools will have me controlling their firewall and not the council. This is very important as all too often the schools cannot get certain things to work because the council refuse to allow the program access. Security is all and well, but now when a client cannot use the network properly because there is a one size fits all solution for all schools by the council.
I am happy with my slackware solution which uses iptables and is in my opinion very secure and in addition, I have the dansguardian filtering working very well. I just don't have any experience of connecting firewall boxes to fibre optic or if you prefer to call it vdsl hence the question.

Perhaps for the type of companies and countries that you work in, this solution is not much good to you, but in England, I honestly cannot see any comparable solution that offers that speed and that price.

I have looked into matter further, and I will go with the PPPoe Network card setup in the slackware box connecting to the BT Modem as the router is the prime problem. I will get back to you in two months time with feedback on how it works out.

Eventually we will get true fibre optic as in fibre to the premises, but for now we will settle for FTTC.

Top
#206522 - 2013-01-04 05:23 PM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
ok, if it is a vdsl PPPoE setup, you should be able to get a simple modem that can be configured in bridge mode. in the price range of 60-80 sterlings.

this way, you can set the connection and PPPoE crap on that modem and hook it up to the slackware eth0 and keep that box separate from the connection handling.

this approach separates connection and connectivity, if that makes sense.
if the connection is up but something isn't working, you know it's in slackware and if connection is down altogether... you know.
this way troubleshooting and replacing equipment is fast.

just a thought.
_________________________
!

download KiXnet

Top
#206523 - 2013-01-05 01:10 PM Re: Connecting small business to Fibre Optic Broadband [Re: Lonkero]
Robdutoit Offline
Hey THIS is FUN
***

Registered: 2012-03-27
Posts: 363
Loc: London, England
Which brings us back to the original question lol. As far as I can see you cannot buy a modem that handles the VDSL connection AND the PPPoe config. As far as I can find out, you have to have a modem that handles the VDSL part and a router that handles the PPPoe part. As with the draytek, you can get a router that handles both the VDSL and PPPoe parts, but its not a modem and hence comes with its own firewall thus creating the problem of two firewalls on the network - hence the question. Even BT who are supplying the fibre optic do not sell any modems that handle the PPPoe part as well. I think the problem is that you are looking at modems that can handle ADSL and PPPoe, but as far as I am aware there are no modems that support VDSL and PPPoe. I speak under correction of course.
Alos by having PPPoe on the modem, you effectively have a double NAT situation as the modem and the slackware box would be providing NAT. I would rather keep the modem as a dumb terminal and leave the slackware box to handle the configuration as this would be less complicated to troubleshoot methinks.


Edited by Robdutoit (2013-01-05 01:26 PM)
Edit Reason: added extra info

Top
#206524 - 2013-01-05 04:01 PM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
Glenn Barnas Administrator Offline
KiX Supporter
*****

Registered: 2003-01-28
Posts: 4402
Loc: New Jersey
Why would you double-NAT?

If the Draytek does NAT, it should have a private IP (ie - 192.168.0.1) on the inside. Configure your inside firewall to route, with 192.168.0.2 on the outside and another private network address on the inside. This effectively creates a DMZ whether you want it or not, but prevents the double-NAT situation. I have used ISA or TMG firewalls in such a configuration in the past when business Internet service was not available. Have the Draytek forward all ports/protocols to the inside firewall and let that device forward to or publish inside servers as appropriate.

My earlier comment was more to using a home-brew firewall in a business environment and the potential exposure to you. With commercial equipment available used/refurbished at $200 US, why build a PC (even an old desktop), take time to install the O/S and iptables module, and subject you and your company to the potential risk that everything you've used and configured is 100%? If you choose a well-known and respected commercial product, the customer cannot bring into question the integrity of the design. Your liability exposure is limited to the configuration of the device, and even then your exposure is minimal unless you grossly misconfigure it.

We use refurbished equipment at many smaller businesses to provide enterprise quality at bargain prices. We buy an extra device or module and pay for it through maintenance contracts to insure same-day recovery for clients, even though in 5 years we've not had a single failure. We also maintain copies of any config files in-house to pre-load the spares to minimize on-site time. It might take 30 minutes to set up and load it at the office, but when we walk in and swap the box and things work, the client "sees a duck" - moving gracefully on the water but doesn't see how hard we're paddling below. It's an appearance that breeds confidence.. other vendors arrive and take an hour or more to install and configure a replacement, we do it in 10-15 minutes because of the back-office preparation and standards across clients.

Another perspective is control - the more you have, the less risk you take on. Control comes through standards across clients, recognized equipment, and learning how to "say no - but..." when appropriate. Also, if a new client has technology that we don't consider appropriate, we'll suggest a replacement. If they choose not to, they must sign a "hold-harmless" document stating that we don't recommend that device or configuration and cannot be held responsible for any effect that may result from its continued use.

Glenn
_________________________
Actually I am a Rocket Scientist! \:D

Top
#206525 - 2013-01-05 04:11 PM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
the pppoe dictates nat? didn't know that. as far as I know it's just for auth purposes.
now, the ISP might require certain type of connection. like in finland we had a ISP that required a routed (non-bridged) connection for home user connections. the bizz connections didn't have that requirement but the price went up ten fold \:\)

it's been few years since I was installing connections myself so can't say I'm on top of the game anymore. but from stability and cheapness perspective telewell was the choice as backup always carry on device. was the cheapest and provided really good flexibility. and if it didn't work it didn't hurt moneywise to swap it.
oh, and I think Billion was the other brand.

just checked on one finnish site and the cheapest vdsl2 device you can get is a zyxel:
http://www.verkkokauppa.com/fi/product/4...porttinen-VDSL2

which has pppoe support. and it doesn't have wireless like the 5 euros more expensive telewell. and that is a good thing.
_________________________
!

download KiXnet

Top
#206526 - 2013-01-05 07:53 PM Re: Connecting small business to Fibre Optic Broadband [Re: Lonkero]
Robdutoit Offline
Hey THIS is FUN
***

Registered: 2012-03-27
Posts: 363
Loc: London, England
Glenn, it may not look like it, but we are actually more in agreement than not. I could not agree with you more with regards to control and standardisation. This is what I have been busy doing with my clients over the last couple of years. The first step was getting similar client desktops e.g. Fujitsu Esprimo, and the same type of servers, e.g. Fujitsu Primergy. I also use as much as possible the same switches from Cisco taking the size of the network into account and whether the client requires power of ethernet etc. So yes, I agree with you 100%. Standardisation is absolutely critical. I want the same Servers, laptops, desktops, switches, routers etc etc etc. And this is actually why I want the Slackware box as this box is the most important one to standardise. Even with the broadband supplied by the council, the schools broadband connectivity equipment differs from school to school precisely because as equipment died out/phased out over the years, the council replaced them with the result that for most schools, the connection is broadly similar but not identical as some schools have a router setup through a very old switch and other schools use a white box for the router. The problem is if I buy 10 cisco whatever firewalls now, what happens in three years time, when I have new clients on board and I can't get these particular Cisco firewalls anymore. I have two choices. I can either replace all existing firewalls with something different so that everything matches and works identically or I can have slightly different equipment in each client as I get new clients on board. I intend to replace the firewall equipment every x number of years, but I cannot buy hundreds of Cisco firewalls for new clients that I have not yet got on board. My slackware box gives me complete control as the Slackware software is easy to image onto the machine. The difference in motherboards etc would not really affect anything as Linux is largely driver independent. but the same version of the OS is very important.

To your first question, the way I intend to address the confidence issue in my box, is to
a: submit it to testing using port scanners and firewall testing software to look for any weaknesses
b: By default, only certain incoming ports will be accepted. All the other ports will be set to drop all incoming connections. So I will only have potential weaknesses on an extremely small number of ports.
c: By default only certain outgoing ports will be accepted. All the other ports will be set to drop all outgoing connections. So I will only have potential weaknesses on an extremely small number of ports.
d: Slackware is a very rarely used (in comparison) OS compared to Cisco Firewalls etc. You look upon that as a weakness in terms of credentials, but I actually look upon it as a strength, as Cisco will have known weaknesses, but Slackware will be far more hack proof as most hackers have never even heard of the distro. I understand your case about not re-inventing the wheel, but it is a bit unfair to compare Slackware to a homebrew. It has been built purposely for business use. It is the most stable Linux distro out there and is absolutely brilliant with regards to control of what is installed with the OS. It is in my opinion more than fit for purpose. In addition, using the firewall on the Slackware box along with Dansguardian filtering, it means that I have one box which I can fine tune the customisation to such a level that it is a far better product than any other product at that price. While the firewall is very important, for my clients, the content filtering is actually a higher priority to them because schools are required by law to ensure that children are protected. This is the prime reason for the Slackware box.

With regards to your second point, this is another thing that is brilliant about Slackware. It primarily uses scripts. So all I have to do is copy about a dozen files that will be slightly different for each client. It will take me all of two minutes to copy the files, which means that like yourself I can setup the box in my office, in less than 30 minutes as all I will be doing is imaging the OS onto a new box, and then copy the client specific files. This is one of my biggest reasons like yourself for standardisation. This is why I have selected Slackware as it allows me to standardise the firewalling, content filtering, proxy boxes for all clients as the only real changes I have to make are to about a dozen different files. So man, we are definitely in agreement there.

But thank you for your advice in the first paragraph. I think it makes sense to use a device like the Draytek for Nat and get the Slackware box to act as a simple router, rather than doing Nat itself. I like your suggestion for setting it up. However I am not convinced that using the Draytek is a good idea because I can accomplish the same thing with the Slackare box in that I can setup Nat on the box by seting up a second network card to act as the PPPoe device. But I am still keeping it in mind. Once I get the first client setup by the end of January, I will have time to play with my options and see what gives. Essentially I need to ensure that I can get remote access to the Server, so whatever solution I come up with has to have my remote access working.

Lonkero, its not the PPPoe itself that dictates Nat per se - well at least how I understand it. But the device that supports PPPoe must support NAT otherwise the Internet would not work. Therefore the PPPoe modem/router has to support NAT, otherwise there is no way for the return traffic to get back as it cannot find the internal IP address obviously.

I have also heard good things of Billion. Draytek and Billion seem to be highly recommended in the home market. I looked at the Zyxel, and it looks like a router, not a modem and as it comes with its own firewall, it is in essence no different from the Draytek.

I better stop writing now. I am getting RSI lol.

Top
#206527 - 2013-01-05 10:04 PM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
the point being, I know for sure in most of these devices, billion, telewell and lot of cases zyxel you can disable the nat and the firewall. all of them have some sort of functions built in, but keep them off and dedicate the box to just PPPoE and connection.

again, you gotta get one of them devices and see what you can turn off and can you do a PPPoE setup in one of these lines without NAT.
and no, modem/router does not have to support nat, again routing and NAT is not the same thing.
not so long ago when the IP addresses weren't so scarce, we used to setup networks without NAT altogether!

and I have to comment on the standardization... you have gone backwards with your setup. making a brand choice on a desktop is the least significant part.
just as well as making a brand choice on the switches is the second. I do prefer HP over cisco in network and over fujitsu or ibm in the servers. I can still work with all of them and know their weaknesses.
and given the choice, I would remove all our cisco routers for something better.
in standardization the software is more important than the equipment. and that's why your slackware idea seems ok with me. not the hardware but getting the actual processing nailed down right and copying that. that's the bomb.

usage policies and security rules are the most important things though.
getting that to the head of your client and making it an agreement is the next step.
everything else falls into place after that.
_________________________
!

download KiXnet

Top
#206530 - 2013-01-07 10:45 AM Re: Connecting small business to Fibre Optic Broadband [Re: Lonkero]
Robdutoit Offline
Hey THIS is FUN
***

Registered: 2012-03-27
Posts: 363
Loc: London, England
This is one area where I find Internet forums frustrating. We are very often agreeing, but not realising that because the conversation is not two way in real time. Yes you are absolutely right. You can disable the Nat and firewall on most of these devices. But my whole beef with the thing, is why they don't make a device that does not include the NAT and firewall as standard. Anyway, not to worry.
I understand that routing and Nat are not the same thing. I did study networking. What I meant was that the device that provides PPPoe ability is usually the one that handles the NAT.
You misunderstood me with regards to why I am making a brand choice for desktops and servers. The reason that I am doing that is because of which companies I have found to offer good after sales service in my country as well as the fact that the drivers for a certain brand are broadly similar which means that I only have to have a small limited number of drivers for my clients instead of having hundreds of drivers for different manufacturers etc. It is not the most important criteria, but sticking with certain manufacturers for example Netgear wireless access points to use a silly example means that I am familiar with their interface, so it saves time. They tend to use the same internal IP address etc. So documenting clients networks is simpler if they mostly have similar switches. I realise that everyone has preferences, I personally hate HP as the support in England is really bad. Won't touch an HP !

I am glad that my slackware box meets with your approval ! Yes, you do understand the point I am making with the slackware box, the software is the important part. Agreed.

I am very pleased that this discussion has generated so much interest. I was not expecting so much feedback, but thats whats so great about KORG. I realise that my ideas don't necessarily meet with the approval of a number of users here. I seem to be very much in the minority especially when it comes to avoidance of using active directory group policy, but I prefer my scripts over group policy any day!
but as Doc or somebody said. All roads lead to Rome as in we all do things differently.

Top
#206531 - 2013-01-07 03:26 PM Re: Connecting small business to Fibre Optic Broadband [Re: Robdutoit]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
yea, you are perfectly correct that HP support sucks.
if you are unlucky enough that the stuff is not DOA, you might get in a limbo for months. happened to me with one server and it never got totally fixed before it got decommissioned.

but I do like their hardware and most time it works perfect.
like I said, I know few of the brands and have come to know some of their drawbacks. for HP it certainly is support.

anywho... let us know how it goes with what ever you choose.
_________________________
!

download KiXnet

Top
Page 1 of 1 1


Moderator:  Arend_, Allen, Jochen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 2220 anonymous users online.
Newest Members
Viginette, ManuvdWielNL, Sir_Barrington, batdk82, StuTheCoder
17888 Registered Users

Generated in 0.065 seconds in which 0.029 seconds were spent on a total of 13 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org