Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Guitarchitect
Nov 8, 2003

edit:

Is it at all possible to take my computer (which is connecting to my main router via Wifi) and share that connection to a router which can then re-broadcast a new Wifi network?
Basically I have a spare router and I need to extend my wifi range, and I'm wondering if I can use my computer as an intermediary. Unfortunately it isn't practical to connect my second router via wired ethernet cable :(

Guitarchitect fucked around with this message at 15:00 on Feb 17, 2018

Adbot
ADBOT LOVES YOU

smax
Nov 9, 2009

CrazyLittle posted:

It'll support nearly any debian package recompiled for MIPS/ARM. You'll be treading far outside the GUI and CLI configuration systems. Encryption can be accelerated by the built in hardware, but routing througput will impact CPU. However the ER4 is ridiculously fast - even faster than the Edgerouter Pro.

OpenVPN cannot be hardware offloaded, only L2TP/IPSec. The ER-4 is pretty powerful so it’ll handle OpenVPN better than the other options, but I doubt throughput will be very good compared to an OpenVPN server on a computer.

MrMoo
Sep 14, 2000

OpenVPN supports acceleration, you probably mean the hardware isn’t supporting OpenSSL for it. I think you’re pretty much limited to AES-NI which rules out most embedded devices.

https://doc.pfsense.org/index.php/Are_cryptographic_accelerators_supported

MrMoo fucked around with this message at 14:32 on Feb 17, 2018

Kivi
Aug 1, 2006
I care
Has anyone tried USB powered Ethernet switches? Gigabit preferred but FE will do. I've got a location that has no free power outlets, but I could use something USB powered off the router (Asus AC66U if it makes any difference) to have few more wired ports for my devices. I found this on Amazon, https://www.amazon.com/Black-Box-Network-Services-LGB304A/dp/B0148L7YI2

Thanks Ants
May 21, 2004

#essereFerrari


Why limit yourself in that way when you could just get a socket adaptor to get more outlets?

Kivi
Aug 1, 2006
I care

Thanks Ants posted:

Why limit yourself in that way when you could just get a socket adaptor to get more outlets?
It's tight space and doesn't really fit more AC adaptors, I've got two outlets and first one is taken by the modem and second by the Asus box. I'll have to see if the local general hardware store has something I could work with, so thanks for the tip.

Thanks Ants
May 21, 2004

#essereFerrari


Maybe something like this would be an option

https://www.monoprice.com/product?p_id=9196

IOwnCalculus
Apr 2, 2003





How about one of those wall taps? Edit: yeah, that

At one point I was actually considering using an old ATX power supply and a bunch of wired adapters just to remove all the power bricks from my setup.

FlyWhiteBoy
Jul 13, 2004

CrazyLittle posted:

It'll support nearly any debian package recompiled for MIPS/ARM. You'll be treading far outside the GUI and CLI configuration systems. Encryption can be accelerated by the built in hardware, but routing througput will impact CPU. However the ER4 is ridiculously fast - even faster than the Edgerouter Pro.

That seems a bit deeper than I want to go. I'm fine with doing some CLI config. Would a Mikrotik router be easier to configure?

CrazyLittle
Sep 11, 2001





Clapping Larry

FlyWhiteBoy posted:

That seems a bit deeper than I want to go. I'm fine with doing some CLI config. Would a Mikrotik router be easier to configure?

"openvpn" is the part that makes config hard. It's the pretty much the same difficulty regardless of platform.

celewign
Jul 11, 2015

just get us in the playoffs
I got gigabit food recently and it is significantly slower than my 50/50 Comcast. YouTube buffering etc.


Google's speed test gives me about 40mbps down. :/

Rexxed
May 1, 2010

Dis is amazing!
I gotta try dis!

celewign posted:

I got gigabit food recently and it is significantly slower than my 50/50 Comcast. YouTube buffering etc.


Google's speed test gives me about 40mbps down. :/

That's not really enough information to go on to help you with, but I'd contact your ISP if it's 1/50th of the advertised speed. If you're measuring a speedtest over wifi you're going to be bandwidth limited from that. If you have old equipment it may not be beefy enough to handle gigabit. There could be other issues, but I'd imagine your ISP can walk you through the basics although we'll help if you provide some more detail about your setup. I assume food was FIOS but autocorrected?

Thanks Ants
May 21, 2004

#essereFerrari


Shove the cable that comes out the wall straight into your laptop and test again

Thermopyle
Jul 1, 2003

...the stupid are cocksure while the intelligent are full of doubt. —Bertrand Russell

celewign posted:

I got gigabit food recently and it is significantly slower than my 50/50 Comcast. YouTube buffering etc.


Google's speed test gives me about 40mbps down. :/

It sounds like you may need to post in Goons With Spoons.

astral
Apr 26, 2004

celewign posted:

I got gigabit food recently and it is significantly slower than my 50/50 Comcast. YouTube buffering etc.


Google's speed test gives me about 40mbps down. :/

As mentioned, try directly connecting a computer to the new connection and see if you're still only getting the appetizer, or if that lets you access the main course.

Bad Munki
Nov 4, 2008

We're all mad here.



Basically realized:



The US-8-60W "House PoE Switch" might get moved to the shop, as per the original plan, but that will wait until I get a camera or two, my cnc router computer, and a few other things on line. At that point, since I'll then need a new switch for the house, I might go nuts and get a US-16-150W, because I'm just about out of ports and would actually like to have some more PoE ports available, as there's a bunch of other poo poo I'm going to be tying in soon. Love PoE, though, that's such an awesome way to run this stuff! Or I'll just use my old netgear switch, but where's the fun in that.

Anyhow, I guess the problem with doing a nice cleanup of an installation is that it just doesn't look like there's that much going on afterward.



Thanks for the help on the unifi stuff, it's freakin' awesome.

Bad Munki fucked around with this message at 05:04 on Feb 19, 2018

Odette
Mar 19, 2011

How are these network graphs being drawn? I've only got Linux, if that helps.

Bad Munki
Nov 4, 2008

We're all mad here.


I used https://www.draw.io/ for the first one, with the generic "network" set of icons, but the second is spit out by the Unifi controller itself under Maps->Topology.

politicorific
Sep 15, 2007
I could use a sanity check for my plans.

I'm home for a family event and have been given carte blanche to rebuild the home network so that there is more coverage and things work better. The property is a 2400 square foot, 2 story home+ basement. Everything is made out of wood and dry wall. There are a lot of doors and enclosed spaces. 20 years ago I pulled 3 strands of category 5 cable from the basement to rooms on the second floor. Internet is provided by Frontier (was Verizon), at approximately 30/30 through an Actiontec MI424 Rev. E (6 or 7 year old router) connected via coax/moca. The router uptime is approximately 280 days. I attempted to get a cheap TP-Link E200 wireless extender working (no AP mode), but it just killed all the Wi-Fi. I've also been given the green light to cancel the cable tv and return the set top boxes. There will be approximately 5 mobile phones, 3 tables, 3 computers, 4 gaming systems, various video streaming boxes, and a Linksys VOIP box.

I'm leaning toward getting Ubiquiti equipment, but am concerned how maintainable everything will be once I leave. I use an EdgeRouter Lite, which I set up once and have never had to touch since, but haven't used ubiquiti wireless products.

I'm planning on buying 3-4 UAP-AC-LITE access points, and letting family expand the system if necessary.

I have some questions:
  • Do I need to run Unifi 24x7? Does 802.11vkr/hotspot transitioning work fine without it?
  • Will the Cloudkey allow me to remotely manage the network?
  • Should I get an EdgeRouterX + Cloud Key or a Unifi Security Gateway?
  • Should I re-run new CAT5e/CAT6 cable?
  • Should I consider getting a POE switch?

Photex
Apr 6, 2009




politicorific posted:

I could use a sanity check for my plans.

I'm home for a family event and have been given carte blanche to rebuild the home network so that there is more coverage and things work better. The property is a 2400 square foot, 2 story home+ basement. Everything is made out of wood and dry wall. There are a lot of doors and enclosed spaces. 20 years ago I pulled 3 strands of category 5 cable from the basement to rooms on the second floor. Internet is provided by Frontier (was Verizon), at approximately 30/30 through an Actiontec MI424 Rev. E (6 or 7 year old router) connected via coax/moca. The router uptime is approximately 280 days. I attempted to get a cheap TP-Link E200 wireless extender working (no AP mode), but it just killed all the Wi-Fi. I've also been given the green light to cancel the cable tv and return the set top boxes. There will be approximately 5 mobile phones, 3 tables, 3 computers, 4 gaming systems, various video streaming boxes, and a Linksys VOIP box.

I'm leaning toward getting Ubiquiti equipment, but am concerned how maintainable everything will be once I leave. I use an EdgeRouter Lite, which I set up once and have never had to touch since, but haven't used ubiquiti wireless products.

I'm planning on buying 3-4 UAP-AC-LITE access points, and letting family expand the system if necessary.

I have some questions:
  • Do I need to run Unifi 24x7? Does 802.11vkr/hotspot transitioning work fine without it?
  • Will the Cloudkey allow me to remotely manage the network?
  • Should I get an EdgeRouterX + Cloud Key or a Unifi Security Gateway?
  • Should I re-run new CAT5e/CAT6 cable?
  • Should I consider getting a POE switch?

1. You don't have to run it 24x7 but if you're getting a cloud key...
2. Yes so you'll want to run it 24x7
3. If I was planning to remotely manage it then USG + Cloud key (you still need one)
4. Since you already have the runs it would be inexpensive and easy to pull some Cat6
5. If you're doing 4 AC Lites then probably, it'll be messy with 4 POE Injectors.

IOwnCalculus
Apr 2, 2003





Last, Ubiquiti gear tends to be very, very reliable. I'd be surprised if you have to log back into it within six months of getting it all live.

MrMoo
Sep 14, 2000

I would recommend comparing with a simple Google WiFi or Eero mesh network, less components to break and pretty simple all around.

Eero was supposed to be self monitoring, but they did add a reboot option into their iphone app and once over December I caught their firewall blocking all my Wemo switches for some reason. Odd.

Harveygod
Jan 4, 2014

YEEAAH HEH HEH HEEEHH

YOU KNOW WHAT I'M SAYIN

THIS TRASH WAR AIN'T GONNA SOLVE ITSELF YA KNOW
Our office (small family business) wifi keeps dropping and we have an old Verizon router. I was going to swap it with something new, but there's a cryptic sticker on it warning me not to. Is this bullshit? It's only being used as a router, not a gateway.



It's got a few switches with about a 10 things running off it right now (2 printers, server, about 6 computers). The wifi only services a small room, so the wireless shouldn't have to be too powerful. I was going to get an Archer C9. I got a C7 last month and it works pretty well for my house.



NOTE: I did NOT run any of this awful wiring.

Am I way out?

Harveygod fucked around with this message at 16:00 on Feb 19, 2018

redeyes
Sep 14, 2002

by Fluffdaddy
Only a router not a gateway? That means it is both!

I think you must mean it isn't the wifi AP? Get a Mikrotik or Ubiquiti.

Harveygod
Jan 4, 2014

YEEAAH HEH HEH HEEEHH

YOU KNOW WHAT I'M SAYIN

THIS TRASH WAR AIN'T GONNA SOLVE ITSELF YA KNOW

redeyes posted:

Only a router not a gateway? That means it is both!

I think you must mean it isn't the wifi AP? Get a Mikrotik or Ubiquiti.

It is the wifi AP. I mean that the (visible) coaxial input on the router isn't being used. There's a "Network Interface Device" that seems to perform the gateway function (wire from street goes in, ethernet comes out :downs:).



CAT5 (6?) goes from that to the router (pictured earlier) which broadcasts the wifi signal and then that's connected to some switches. I don't think there will be a problem with simply swapping Verizon's routers with a new one, but my only experience has been with smaller home networks and the warning label spooked me a bit.

Twerk from Home
Jan 17, 2009

This avatar brought to you by the 'save our dead gay forums' foundation.

Harveygod posted:

It is the wifi AP. I mean that the (visible) coaxial input on the router isn't being used. There's a "Network Interface Device" that seems to perform the gateway function (wire from street goes in, ethernet comes out :downs:).



CAT5 (6?) goes from that to the router (pictured earlier) which broadcasts the wifi signal and then that's connected to some switches. I don't think there will be a problem with simply swapping Verizon's routers with a new one, but my only experience has been with smaller home networks and the warning label spooked me a bit.

If this operates anything like AT&T's common fiber gateway setup, then there may be some type of hardware key inside of the Verizon router that means no other device will be able to function in that role. If you're on FIOS, that thing on the wall is a fiber modem, but they may not do authentication in the fiber modem. If their router is doing authentication, then you can't just plug another router into that fiber modem and have it work.

Harveygod
Jan 4, 2014

YEEAAH HEH HEH HEEEHH

YOU KNOW WHAT I'M SAYIN

THIS TRASH WAR AIN'T GONNA SOLVE ITSELF YA KNOW

Twerk from Home posted:

If this operates anything like AT&T's common fiber gateway setup, then there may be some type of hardware key inside of the Verizon router that means no other device will be able to function in that role. If you're on FIOS, that thing on the wall is a fiber modem, but they may not do authentication in the fiber modem. If their router is doing authentication, then you can't just plug another router into that fiber modem and have it work.

Ah, okay. Thank you.

derk
Sep 24, 2004
@Harveygod
so, I have Verizon FiOS and do NOT use their modem/router. I have the ethernet line coming from that box in my basement right into my own router. I did have a verizon router/modem when i had it installed which i own and i just clone the MAC of that with any router i have hooked up since (avoids extra steps). Now, i only have FiOS data, no tv sub from verizon that is why i can do that because i have no need for MoCA which their router would take care of for there STBs to talk to the network and what not.

Thermopyle
Jul 1, 2003

...the stupid are cocksure while the intelligent are full of doubt. —Bertrand Russell

Is there a specific type of Cat6 I should get for aerial usage? I assume something UV-resistant.

I've got 2 buildings 10 feet apart with concrete between them so no trenching. So, I guess I'll suspend the cable between them.

Inept
Jul 8, 2003

Thermopyle posted:

Is there a specific type of Cat6 I should get for aerial usage? I assume something UV-resistant.

I've got 2 buildings 10 feet apart with concrete between them so no trenching. So, I guess I'll suspend the cable between them.

About 6 years ago I worked for a company that wanted to do something similar. We ended up paying someone to run aerial fiber.

Thanks Ants
May 21, 2004

#essereFerrari


derk posted:

@Harveygod
so, I have Verizon FiOS and do NOT use their modem/router. I have the ethernet line coming from that box in my basement right into my own router. I did have a verizon router/modem when i had it installed which i own and i just clone the MAC of that with any router i have hooked up since (avoids extra steps). Now, i only have FiOS data, no tv sub from verizon that is why i can do that because i have no need for MoCA which their router would take care of for there STBs to talk to the network and what not.

I might be talking complete poo poo but isn't there an option to get your Internet feed via the coax port on the FiOS box, or the ethernet, and Verizon need to switch you between them if you want to change? Maybe that was the early installs where they wanted to avoid running new lines into the house.

derk
Sep 24, 2004

Thanks Ants posted:

I might be talking complete poo poo but isn't there an option to get your Internet feed via the coax port on the FiOS box, or the ethernet, and Verizon need to switch you between them if you want to change? Maybe that was the early installs where they wanted to avoid running new lines into the house.

Correct, I had them use ethernet port since I have just data no TV or Phone. 150/150 is fairly priced, I would love to try the 500/500 plan but too rich for my blood.

calandryll
Apr 25, 2003

Ask me where I do my best drinking!



Pillbug

Thanks Ants posted:

I might be talking complete poo poo but isn't there an option to get your Internet feed via the coax port on the FiOS box, or the ethernet, and Verizon need to switch you between them if you want to change? Maybe that was the early installs where they wanted to avoid running new lines into the house.

For FiOS the coax connection is required for TV and Phone to work correctly, which means unfortunately using their routers. As derk said if you are only using internet you can use the ONT (ethernet) port on their box and connect your own router. If you require Phone or TV you can setup a bridge with their router to your own stuff and not suffer any issues. I did this for my old place, and had no issues.

Olothreutes
Mar 31, 2007

My router is old and having beef with my wife's i-devices so I'm looking at upgrading to a C7. At the same time we're about to move into a new place, which is ~2000 sqft and L shaped. Would a single C7 be enough to cover that if I place it at the corner of the L? Walls will obviously be a problem, but the alternative is probably putting an AP in each side of the house and that sounds both more expensive than I'd like and also a pain to try and set up physically.

Laranzu
Jan 18, 2002
Running into an issue where the Unifi Security Gateway seems to lose its ability to route on the WAN side.

Setup is:
Xfinity 100mb -> Motorola MB7420 (Only gets an IPv6 Address) -> USG -> TP-Link Switch -> UAP AC-Lite

When I notice the issue I SSH into the USG and get the following:
code:
Tue Feb 20 18:09:31 EST 2018
ping 8.8.8.8
From 68.33.113.xxx icmp_seq=4 Destination Host Unreachable

traceroute 8.8.8.8
 1  68.33.113.xxx (68.33.113.xxx)  475.739 ms !H  *  2993.471 ms 

This is a segment of pings where it finally starts responding again:
From 68.33.113.xxx icmp_seq=1490 Destination Host Unreachable
From 68.33.113.xxx icmp_seq=1491 Destination Host Unreachable
From 68.33.113.xxx icmp_seq=1492 Destination Host Unreachable
64 bytes from 8.8.8.8: icmp_req=1494 ttl=58 time= 1019 ms
64 bytes from 8.8.8.8: icmp_req=1495 ttl=58 time=19.1 ms
64 bytes from 8.8.8.8: icmp_req=1493 ttl=58 time=2018 ms
64 bytes from 8.8.8.8: icmp_req=1496 ttl=58 time=10.2 ms
68.33.113.xxx/23 is the IPV4 address/subnet of the WAN Port on the USG.

To me this looks like the WAN port is timing out for some reason.

The Cable Modem doesn't lose sync, but does have a few of these errors in the log:
code:
No Ranging Response received - T3 time-out
Timing of the modem error log is sometimes correlated with the issue. Sometimes it doesn't seem to be. Really need to get more testing on this.

It seems some people were having issues with a /32 address being assigned as well as DNS issues or DHCP issues with double NAT. I haven't been able to find anything that really explains this one.


Edit: Motherfucker. It finally happened and showed me it might be my upstream channels
code:
Tue Feb 20 20:27:09 2018  	 Critical (3) 	 16 consecutive T3 timeouts while trying to range on upstream..

Laranzu fucked around with this message at 02:33 on Feb 21, 2018

IOwnCalculus
Apr 2, 2003





T3 timeouts are absolutely your modem losing sync upstream. I just went through a bunch of poo poo dealing with them on my connection and they finally vanished "on their own" despite Cox claiming no wrong-doing and three techs confirming everything at my house is fine.

CrazyLittle
Sep 11, 2001





Clapping Larry
1) don't use pings to google dns as your heartbeat / keepalive target. It's not one server and there's zero guarantee of reachability over a single route.
2) A public IP with packet loss at hop 1 of a traceroute likely means there's an issue with the cablemodem. Check the logs on the cablemodem to see if you're losing sync. Also check the system logs (CLI command: "show log tail" ) to see if the port itself is dropping or if it's a software issue
3) If you're not actually using failover connections, don't turn on any WAN2 / failover config in the USG because it will take down your internet connection if the heartbeat target doesn't respond.

Laranzu
Jan 18, 2002
Yeah I just made an edit to my question with the 16 consecutive T3 timeouts while it was happening basically putting the nail in the issue. Now I get to fight with Xfinity phone techs to try to get them to understand what that means enough to get the infrastructure people on it.

1) Google DNS is good enough for testing loss of connectivity for this purpose really. Its not a real heartbeat/keepalive, and its dying at the first hop anyway.
2) Modem never actually loses sync entirely. Still reports connected fine. It just eats poo poo on upstream ranging.
3) Failovers are off. Thanks for the warning though.

El Jebus
Jun 18, 2008

This avatar is paid for by "Avatars for improving Lowtax's spine by any means that doesn't result in him becoming brain dead by putting his brain into a cyborg body and/or putting him in a exosuit due to fears of the suit being hacked and crushing him during a cyberpunk future timeline" Foundation

CrazyLittle posted:

1) don't use pings to google dns as your heartbeat / keepalive target. It's not one server and there's zero guarantee of reachability over a single route.
2) A public IP with packet loss at hop 1 of a traceroute likely means there's an issue with the cablemodem. Check the logs on the cablemodem to see if you're losing sync. Also check the system logs (CLI command: "show log tail" ) to see if the port itself is dropping or if it's a software issue
3) If you're not actually using failover connections, don't turn on any WAN2 / failover config in the USG because it will take down your internet connection if the heartbeat target doesn't respond.

If 8.8.8.8 isn't a good heartbeat/keepalive, what is? I’ve had a few instances recently of trouble and I’d like to be able to do something similar. I’ve got to iron everything down at home first to make sure my issues aren’t on my end, though.

Also, thanks to those who recommended the hardware offload, it appears to have helped but now I am sure the builders of this home were drunk when they ran the lines so I need to fix that before I can get everything where I want it.

Adbot
ADBOT LOVES YOU

CrazyLittle
Sep 11, 2001





Clapping Larry

El Jebus posted:

If 8.8.8.8 isn't a good heartbeat/keepalive, what is? I’ve had a few instances recently of trouble and I’d like to be able to do something similar. I’ve got to iron everything down at home first to make sure my issues aren’t on my end, though.

If you're testing uptime for a specific link, the best monitor would be either the ISP's own DNS servers, or perhaps the hop after the local node/public gateway address. Otherwise you would do well to pick the DNS A record for a website that's near you and expected to answer every time.

The problem with 8.8.8.8 as a heartbeat is that it's an "anycast" address which means the routing path and destination changes on the fly, and is served by multiple servers from lots of different providers. For example, AT&T has servers that can answer for 8.8.8.8 in the CA bay area, even though Google's got a huge datacenter presence here. So the ping you send out might not make it back. This is less of a problem for DNS queries which are frequently cached by the local computer or perhaps even your router/firewall, but is not a good measure for something that's monitoring whether your link is up or down.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply