Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




68 posts

Master Geek


# 185576 27-Nov-2015 22:55
Send private message

hi all,
spent the evening reading numerous posts on connecting various pieces of hardware to the Chorus ONT's which threw light on the ONT setup side (I'm new to using these).

Our SME setup (very std reqmts: internet, email via own hosted Exchange, PPTP VPN for remote users).
D-Link DFL860E firewall. Need to retain use of this as is core router/firewall providing VPN, vlan, etc functionality for LAN/WAN users.
VF-supplied HG659 router. Fixed IP provided (/32). 
Chorus ONT.
No VLAN 10 tagging nor PPPoE config on firewall as HG659 providing these.

Currently have ONT --> HG659 WAN port / HG659 LAN port (serving DHCP) --> D-Link WAN port (set to reserved IP on HG659).
this is working fine for internet access. Getting 200M up/down (in AKL CBD). 
However, unable to route email / OWA / VPN traffic out or in. Firewall rules altered to route traffic through updated 192.168.1.x WAN int (to HG659). 

Vodafone tech support pretty much useless in providing any decent "corporate" support for using an ONT with a business grade firewall. 

So...
- should the firewall WAN int be set to PPPoE with DHCP? Been unable to so far do this as the physical WAN int settings on the firewall require an IP (catch 22). Yet to delete the WAN int setting and re-add as pure DHCP.
- will that int then pick up the fixed external IP? 

Previous setup at our old location was dark fibre with fixed IP. That IP was then set on the firewall WAN int and all traffic routed in/out no problem. 

how have others out there configured business setups with ONT's? I def would prefer NOT to have to use the HG659 as part of the network given its very basic consumer level functionality / throughput capability. 

thanks in advance / sorry for the extended bleat. 


Filter this topic showing only the reply marked as answer Create new topic
1609 posts

Uber Geek


  # 1436439 27-Nov-2015 23:25
One person supports this post
Send private message

Plug your firewall into the ONT. Set firewall to DHCP and VLAN 10. That should do the trick. No PPPoE required.

28142 posts

Uber Geek

Moderator
Trusted
Biddle Corp
Lifetime subscriber

  # 1436574 28-Nov-2015 08:08
Send private message

You don't want double NAT so will want to remove the HD659 from the setup.

If your existing D-link doesn't support VLAN10 tagging you'll either need to buy a new router that does or buy hardware to perform the VLAN tagging for you.



 
 
 
 




68 posts

Master Geek


  # 1436702 28-Nov-2015 10:47
Send private message

Thanks for the info.

 

Removed the HG659 from the mix.

Created a new VLAN 10 interface with DHCP on the Dlink firewall / assigned it to WAN 1 physical int.

 

VLAN 10 interface now picks up the Chorus IP and DNS so that’s good.

 


However, still unable to pass traffic in or out.

 

Question now is do I apply the firewall policies to use the Vlan 10 interface as source and destination or hard code the WAN int to use the Chorus fixed IP?



68 posts

Master Geek


  # 1436835 28-Nov-2015 13:15
Send private message

meh. Wan int had a default route conflicting with the new vlan 10 int. 
removed that and traffic flowed both ways. Now to clear our blacklisted dynamic IP. Thanks Mail Marshal...



Filter this topic showing only the reply marked as answer Create new topic



Switch your broadband provider now - compare prices


Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Intel expands 10th Gen Intel Core Mobile processor family
Posted 23-Aug-2019 10:22


Digital innovation drives new investment provider
Posted 23-Aug-2019 08:29


Catalyst Cloud becomes a Kubernetes Certified Service Provider (KCSP)
Posted 23-Aug-2019 08:21


New AI legaltech product launched in New Zealand
Posted 21-Aug-2019 17:01


Yubico launches first Lightning-compatible security key, the YubiKey 5Ci
Posted 21-Aug-2019 16:46


Disney+ streaming service confirmed launch in New Zealand
Posted 20-Aug-2019 09:29


Industry plan could create a billion dollar interactive games sector
Posted 19-Aug-2019 20:41


Personal cyber insurance a New Zealand first
Posted 19-Aug-2019 20:26


University of Waikato launches space for esports
Posted 19-Aug-2019 20:20


D-Link ANZ expands mydlink ecosystem with new mydlink Mini Wi-Fi Smart Plug
Posted 19-Aug-2019 20:14


Kiwi workers still falling victim to old cyber tricks
Posted 12-Aug-2019 20:47


Lightning Lab GovTech launches 2019 programme
Posted 12-Aug-2019 20:41


Epson launches portable laser projector
Posted 12-Aug-2019 20:27


Huawei launches new distributed HarmonyOS
Posted 12-Aug-2019 20:20


Lenovo introduces single-socket servers for edge and data-intensive workloads
Posted 9-Aug-2019 21:26



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.