Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Zyxel VMGxxxx - isolate Modem bridge mode from LAN/WiFi  (Read 3029 times)

Iam_TJ

  • Reg Member
  • ***
  • Posts: 103
Zyxel VMGxxxx - isolate Modem bridge mode from LAN/WiFi
« on: September 15, 2017, 01:56:25 PM »

I've been concerned for some time at how difficult it is to securely manage the authentication, remote access, and firewall aspects of combined CPE modem/router devices, and the Zyxel devices in particular since I have several.

I'd prefer to have the VDSL modem separate from the rest of the functionality as was the case with the original Openreach HG612 modem. Unfortunately these combined devices usually have better performing xDSL chipsets.

As I'm currently planning a new installation with multiple incoming VDSL links I decided to spend some time thinking about how it might be possible to create the required isolation on an existing combined modem/router.

Essentially the PPP authentication, firewall, RA/PD/DHCP, and DNS would be done on another (fully open-source) Linux device (RasPi?) as if the modem/router were in bridged mode but on the LAN side the Ethernet ports and WiFi would be used as normal (rather than being redundant as is typical in bridge mode).

This would also allow easy implementation of a VPN server on the 'edge' to prevent ISPs snooping on/mangling/blocking traffic.

My experience with configuring local VLANs on the VMG8{9,3}24 devices made me realise there might be a way to do this by isolating the ATM/PTM interface on a VLAN connected to another device for PPP authentication, etc., and the LAN/WiFi side connected via another VLAN.

So, two questions:
  • Has anyone attempted this on any combined modem/router device?
  • Is anyone interested in this functionality if I developed a custom firmware?
Logged

smf22

  • Member
  • **
  • Posts: 48
Re: Zyxel VMGxxxx - isolate Modem bridge mode from LAN/WiFi
« Reply #1 on: September 15, 2017, 02:19:49 PM »

Not entirely sure I follow, but I think what you're asking can be done based upon what's shown in ZyXEL VMG8324-B10A - Bridge Mode for FTTC.

I followed this recently and have a setup with a ZyXel VMG8924 in bridge mode connected to a Ubiquiti EdgeRouter-X. The ERX establishes the PPPoE session, is the firewall, DHCP server etc., with a number of VLANs for the private LAN, private WiFi, Guest WiFi etc. I connect a second port of the ZyXel to a spare port on the ERX so I can access the ZyXel via telnet, SSH etc., but also use its WiFi if so desired.
Logged
BT FTTC 80/20 Huawei Cab - Zyxel VMG8924-B10A bridge mode + Ubiquiti EdgeRouter X

Chunkers

  • Reg Member
  • ***
  • Posts: 526
  • Brick Wall head-banger
Re: Zyxel VMGxxxx - isolate Modem bridge mode from LAN/WiFi
« Reply #2 on: September 15, 2017, 02:29:27 PM »

Would it be easier to just bridge your VMG* to pfSense / OPNsense or other router?  You can't use your VMG ethernet pojnts but lots of people have done this and software wise they offer pretty good security (from what I have seen)

You could also maybe try a router with an open-source firmware with better security and options like OpenWRT?

Sorry if I have completely missed the point.....

Chunks
Logged

j0hn

  • Kitizen
  • ****
  • Posts: 4098
Re: Zyxel VMGxxxx - isolate Modem bridge mode from LAN/WiFi
« Reply #3 on: September 15, 2017, 02:36:28 PM »

I use both my vmg8924/vmg1312 in bridge mode, only handling the vdsl connection.
My router does the PPP/DHCP/firewall/VLANS.
I'm sure that's how most Kitz users use their ZyXELs
Logged
Talktalk FTTP 550/75 - Speedtest - BQM

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7390
  • VM Gig1 - AAISP L2TP
Re: Zyxel VMGxxxx - isolate Modem bridge mode from LAN/WiFi
« Reply #4 on: September 15, 2017, 03:31:58 PM »

when the device is bridged it is on a different ip subnet, so not accessible from the lan/wifi unless a specific configuration allows it to be.
Logged

Iam_TJ

  • Reg Member
  • ***
  • Posts: 103
Re: Zyxel VMGxxxx - isolate Modem bridge mode from LAN/WiFi
« Reply #5 on: September 15, 2017, 03:58:06 PM »

Not entirely sure I follow, but I think what you're asking can be done based upon what's shown in ZyXEL VMG8324-B10A - Bridge Mode for FTTC.

I followed this recently and have a setup with a ZyXel VMG8924 in bridge mode connected to a Ubiquiti EdgeRouter-X. The ERX establishes the PPPoE session, is the firewall, DHCP server etc., with a number of VLANs for the private LAN, private WiFi, Guest WiFi etc. I connect a second port of the ZyXel to a spare port on the ERX so I can access the ZyXel via telnet, SSH etc., but also use its WiFi if so desired.
This is interesting. The guide you link to describes the scenario I'm aiming for exactly! Thank-you.

My main aim is not to lose the router/WiFi, USB file/print server, USB 3G backup functionality.

I guess I couldn't see the wood for the trees; because I've always focused on the combined functionality and never messed about with it in Bridge mode, coupled with my experience of the bugs around configuring isolated VLANs that get saved across reboots, I assumed the configuration couldn't be saved and would need recreating manually after a reboot.

You've saved me many hours and days of re-inventing the solution  :angel:
Logged
 

anything