So, I have been trying for the last couple of months to come up with an optimal solution for improving my CenturyLink Gigabit fiber.
I have the CL ZyXel C1100Z. Terribly slow interface, but accelerates PPPoE well and if all I was doing was browsing the web, this might be good along with a wireless AP. However, I have 7 kids, 4 Xboxes, 3 gaming PCs and a plethora of other items and Strict or Moderate NAT don't cut it. The firewall policies options on this thing are either disable or contain a host of things I don't want going on if you set it to low, medium or high. If you disable a built in policy and try to replace it with your own, it is sporadic in how it works. I am trying to disable UDP port 3074 - this gets all the Xboxes Open NAT in most cases as long as uPnP is on.
So, for a long time I had a Fortigate 60D sitting in front of the ZyXel, in the DMZ and that was OK, but more and more Xbox services need IPv6 to work along with open NAT. Not to mention, IoT devices needed IPv6 and double NAT wouldn't allow for proper operation. The IPv6 config in the Fortigate wouldn't work quite right with the 6rd setup that CL has.
So, I had an old Edgeroute Lite on the shelf and I configured that. Not bad, except I found a ton of packet loss issues. If you understand the PPPoE setup with CenturyLink, you may know the Cavium in the ERL has a bug with PPPoE offloading. Long story short - nope, not a solution.
So, I read reviews and got Eero, Orbi, Google Wifi and Velop to try out their configs. None of them handle PPPoE and VLAN well enough to make the main router. However, I did find that Orbi has amazing WiFi and works with its satellite even in bridge mode. It has now replaced my Apple Airport Extreme and the whole house has fast WiFi. Google Wifi was close - but unless it is the router, its mesh doesn't work and it doesn't do VLAN tagging.
But, to remove the NAT issue, I still need a replacement router - so I tried a pfSense box with igb nics. If you know igb nics and PPPoE, you know that there is a queue bug that drops packets like the ERL above. Processor barely registers activity, but 10% packet loss occurs. Great little device - if it worked with PPPoE well, I think it would be the winner.
So, I am kind of back at square one. C1100Z is running the fiber connection, but little issues make it less than ideal. Orbi is now the choice for WiFi, but I am not 100% locked into it.
Does anyone know of a wireless or wired router that can support gigabit speed with PPPoE, VLAN tagging on, 6rd support and doesn't have a bug that drops packets like crazy with an extensive and controllable firewall? And finally, can support Open NAT for multiple Xboxes(really just the ability to block port 3074)
I have the CL ZyXel C1100Z. Terribly slow interface, but accelerates PPPoE well and if all I was doing was browsing the web, this might be good along with a wireless AP. However, I have 7 kids, 4 Xboxes, 3 gaming PCs and a plethora of other items and Strict or Moderate NAT don't cut it. The firewall policies options on this thing are either disable or contain a host of things I don't want going on if you set it to low, medium or high. If you disable a built in policy and try to replace it with your own, it is sporadic in how it works. I am trying to disable UDP port 3074 - this gets all the Xboxes Open NAT in most cases as long as uPnP is on.
So, for a long time I had a Fortigate 60D sitting in front of the ZyXel, in the DMZ and that was OK, but more and more Xbox services need IPv6 to work along with open NAT. Not to mention, IoT devices needed IPv6 and double NAT wouldn't allow for proper operation. The IPv6 config in the Fortigate wouldn't work quite right with the 6rd setup that CL has.
So, I had an old Edgeroute Lite on the shelf and I configured that. Not bad, except I found a ton of packet loss issues. If you understand the PPPoE setup with CenturyLink, you may know the Cavium in the ERL has a bug with PPPoE offloading. Long story short - nope, not a solution.
So, I read reviews and got Eero, Orbi, Google Wifi and Velop to try out their configs. None of them handle PPPoE and VLAN well enough to make the main router. However, I did find that Orbi has amazing WiFi and works with its satellite even in bridge mode. It has now replaced my Apple Airport Extreme and the whole house has fast WiFi. Google Wifi was close - but unless it is the router, its mesh doesn't work and it doesn't do VLAN tagging.
But, to remove the NAT issue, I still need a replacement router - so I tried a pfSense box with igb nics. If you know igb nics and PPPoE, you know that there is a queue bug that drops packets like the ERL above. Processor barely registers activity, but 10% packet loss occurs. Great little device - if it worked with PPPoE well, I think it would be the winner.
So, I am kind of back at square one. C1100Z is running the fiber connection, but little issues make it less than ideal. Orbi is now the choice for WiFi, but I am not 100% locked into it.
Does anyone know of a wireless or wired router that can support gigabit speed with PPPoE, VLAN tagging on, 6rd support and doesn't have a bug that drops packets like crazy with an extensive and controllable firewall? And finally, can support Open NAT for multiple Xboxes(really just the ability to block port 3074)