Internet-Box, mode bridge, ip passthrough

Hello,

I’m making a topic again because I would like a swisscom manager to respond on the subject!

I don’t understand why we don’t have access to the “ip passthrough” option on the internet box when with the old version of fiber, the centro grand, the option was there!

Don’t tell me about the “DMZ” option which redirects all ports to a NAT address…because I don’t want to do double NAT!!!!!

I looked into changing the box, because I don’t use these functions… there is the gs110tp switch which would allow me to replace it, but that makes me buy a device, which may work less well, whereas the box does it natively!

So my question:

Why did you remove the ability to do it or why not activate telnet and give us the access to do it?

Thanks in advance

Show original language (French)

Hello lololo,

The Internet-Box software does not yet support this option. Swisscom created a function similar to the DMZ function and it has always provided solutions and resolved many problems for our customers.

We need to understand under what circumstances would you need to install a second router behind the Internet-Box in order to consider developing an IP Passthrough solution.

In the meantime, we wish you a very good rest of your day.

Cordialement

Show original language (French)

Hello and thank you for taking the time to answer me!

It’s not a second router that I installed but a firewall (pfsense). This works in double NAT but it takes resources and is more complicated to configure and debug in the event of a problem.

What obviously doesn’t work is the IPV6 attribution in 6RD hard firewall since it is calculated on the Private address 😞

Furthermore, a big advantage with IP Passthrough is that you can put the TV boxes directly on the router (because you don’t need a firewall) and not clog up the firewall.

here it is

Thank you in advance for your help.

Show original language (French)
19 days later

+1

I would also like to have this option, because I use a private router behind to manage security/routing/vlan/firewall/vpn + open sip myself…

in short, everything that the box doesn’t do, or that I don’t know how…

with the recent stories of line tapping and data leaks between Swisscom and the NSA (see Siligence! 🙂… in this situation if you know how to cope, you are better served by yourself!

in short otherwise a proposal for a fiber modem only?

Show original language (French)
16 days later

Hello everyone,

We thank you for this information. At the moment, we have no plans to add the IP Passthrough option to the Internet-Box. However, we continue to study this possibility and we will inform you directly from this channel if it will be available in the future.

We wish you a very good day and a good start to the school year.

Cordialement

Show original language (French)
9 days later

+1 too!

I would like to install a Sophos UTM firewall to be able to filter the Internet, just to protect my children as little as possible… They are still too young for certain content 😉

Show original language (French)

I have a solution for this problem, but it includes purchasing replacement hardware.

- A Media Converter for around 30.-

- optical interest can be taken from the Swisscom Internet box

- purchase of a high-performance router (personally I have an ASUS AC66U).

Swisscom TV possible with activation of an IGMP function in the router, however I have not done any research regarding telephony and everything is only theoretical for the moment. I have the sources (in German) if you are ever interested!

Show original language (French)

Yes I looked into doing that too!

I tried with a Netgear GS110TP switch which has two SFP ports connected directly to the firewall and it works well. (But I would like the TV not to go through the firewall)

SO I told myself that I was going to install a new router…but finding one that supports my gigabyte connection is a hassle! There is the Ubiquiti Edge Router Lite which supports 1 million packets per second thanks to its hardware acceleration but as soon as you bridge two ports this deactivates the acceleration and in any case it does not do passthrough.

Then there is MikroTik-RB2011UIAS-2HND-IN which has a direct SFP port but the performance is poor…

in short, the purpose of this story is that it makes us buy gear while all they have to do is activate this option! (which, I repeat, was available BEFORE!)

Show original language (French)

What did you put as GBIC of the SFP port?

I use Cisco SG300-10PP switches at home which are also equipped with two SFP ports, but you still need to know the exact type of GBIC to put in them, not to mention that the price of these little adapters is not cheap!

Afterwards it would be enough to make a small VLAN which arrives on my Shuttle or runs my VM which acts as a firewall and that’s it!

Show original language (French)

I used the GBIC from the box, it is compatible with Netgear!

Afterwards, don’t forget to put option 60 when requesting a lease on Vlan10

send vendor-class-identifier “100008,0001,Debian”;

Show original language (French)

Thank you for this information, what is annoying is this “DHCP option 60”, after a quick consultation of my UTM interface, it does not seem possible to specify this option. I guess if this setting is omitted it doesn’t work?

Show original language (French)

I just found the answer on a forum, it seems that it is possible with this manipulation:

edit /var/chroot-dhcpc/etc/ you iface file
add the following line
send vendor-class-identifier VALUE IN HEX;

example:
send vendor-class-identifier 49:50:54:56:5f:52:47;

On the other hand, is the HEX value important? Yes or do you know how to find it?

Show original language (French)

For DHCP Option 60, I found the ID to use on a pfsense Firewall, I don’t know if that helps:

send dhcp-class-identifier “100008,0001,pfSense dhclient 2.1”;

Source: [https://www.skv-net.ch/user/blog1-s-master/entry15-swisscom-glasfaser-mein-ftth-tagebuch-5-update-10-01-2014/] (https://www.skv-net.ch/user/blog1-s-master/entry15-swisscom-glasfaser-mein-ftth-tagebuch-5-update-10-01-2014/)

Show original language (French)

This hexadecimal value is necessary for the All IP product from Swisscom.

The following line should be fine

send vendor-class-identifier 31:30:30:30:30:38:2C:30:30:30:31:2C:55:54:4D;

Show original language (French)
4 days later

Good morning,

I’ve also been sending messages to Swisscom for a while now to add this function to your box routers. Cablcom has this option, and I find it really unfortunate that you’re not doing anything about it.

I have a late Zyxel behind my Box and it’s just crap to do double Nat.

Anyway, I hope this comes to light.

My best regards

PS: This will also be a plus on a commercial level, more customers……….

Show original language (French)
6 days later
5 days later