Live data from Hacker News

A detailed look at the router provided by my ISP

0x90.psaux.io

21–30 of 184 posts

Re: A detailed look at the router provided by my ISP

#21
post #15

Earlier quoted context omitted.

The box in people's home's colloquially known as a router actually commonly combines a lot of functions into one: * router * firewall * NAT device * modem * switch * access point * DNS resolver * DHCP server And probably others I'm not thinking of :-)

ONT in the case of fiber. Don't know if it technically counts as a modem.

Media converter maybe? (Like those $100 or so fiber to ethernet converters, I say this as it’s usually a modem/router plugged into the ONT‘s ethernet port that does isp to cpe authentication, tunneling, etc. so the ONT is just converting fiber (from isps OLT) to ethernet for something more common to plug into)

Re: A detailed look at the router provided by my ISP

#23
post #19
post #5

...and that's why my ISPs router is running in modem mode with a non-ISP-controlled router from Ubiquiti behind it - which I may replace with a pfSense box in the future. I'm pretty happy that my cable ISP is allowing this mode so I don't have to double-NAT in my setup.

If your ISP didn't have that feature, could you just replace the cable modem too? My ISP's router is running EuroDOCSIS 3.0 and I'm wondering if I could replace the router with a modem + router of my own.

if you happened to live in Germany there is a law in place that force ISPs to allow that. But if you would live in Germany you would probably know about this. That said there is no technical reason making it impossible. If you connect an unknown device here, you get access to the customer web panel only and can register your device using it. Afterwards it gets provisioned as usual (with caveats [no PacketCable for example])

Re: A detailed look at the router provided by my ISP

#24
post #19
post #5

...and that's why my ISPs router is running in modem mode with a non-ISP-controlled router from Ubiquiti behind it - which I may replace with a pfSense box in the future. I'm pretty happy that my cable ISP is allowing this mode so I don't have to double-NAT in my setup.

If your ISP didn't have that feature, could you just replace the cable modem too? My ISP's router is running EuroDOCSIS 3.0 and I'm wondering if I could replace the router with a modem + router of my own.

Yes, you could, but the new router+modem needs to be "accepted" by the DOCSIS provisioning. Talk to the support about it.

Re: A detailed look at the router provided by my ISP

#25
post #19
post #5

...and that's why my ISPs router is running in modem mode with a non-ISP-controlled router from Ubiquiti behind it - which I may replace with a pfSense box in the future. I'm pretty happy that my cable ISP is allowing this mode so I don't have to double-NAT in my setup.

If your ISP didn't have that feature, could you just replace the cable modem too? My ISP's router is running EuroDOCSIS 3.0 and I'm wondering if I could replace the router with a modem + router of my own.

Sadly I could not, since the ISP is defining the router as the endpoint of it's network so there is no freedom to choose different models.

Re: A detailed look at the router provided by my ISP

#26
post #4

Trivia: Strictly speaking a box that does NAT is not a router in the IP protocol sense, it's a kind of proxy. The router requirements RFC explicitly forbids altering most fields (incl the address field) in the IP header.

...an RFC that was written in 1995, before NAT was really necessary. My view: If it forwards IP between different networks, it's a router.

Nat existed in somewhat wide use in 95, PIX had come out recently. It's not necessary today either.

Re: A detailed look at the router provided by my ISP

#27
It's funny to think that if you were to report all of your findings to your local newspaper (Turkish newspaper in this case), as to how Turkish ISPs have complete access to your router or how Huawei (China) has an SSH key for your router, people would go absolutely ballistic. But for us it's just another day of expected craziness and we're tired of talking about it

Re: A detailed look at the router provided by my ISP

#28

A while back, I was playing around with the cable modem / router the ISP gave me because I was curious and an idiot. After screwing around a bit, I managed to find a vulnerability that exposed technician credentials plaintext and they actually worked. Had no idea where to report it though, because the manufacturers contact page could be summed up as fuck you we don't talk directly to consumers . I dont think the vuln…

The right thing to do in such circumstances is to publish the vulnerability.

Re: A detailed look at the router provided by my ISP

#29
Apparently a polish carrier called Multimedia has recently introduced a new, revolutionary service for some customers. It's called "set up a custom wi-fi configuration", and it's just 5 pln (a little over $1)! It lets you think up of a ssid and password, and configure your router to use those! That's an amazing invention, isn't it? /s

Some customers apparently have absolutely no access to their routers, not even to the web interface, and they can't use their own either. All reconfiguration must be done through the customer service portal or by phone. That means the carrier can change for every little thing, including changing the Wi-Fi config! I'm not sure if you can even bridge, but I guess not. Note that this does not affect all customers of that carrier, just a minority.

Re: A detailed look at the router provided by my ISP

#30
In the Netherlands we now have a law where ISPs must allow your own choice of network equipment. This means they must give you the required information on how to connect your own device with their network.

I have a fiber connection, which I connected directly to a Ubiquity router through a suitable SFP module. My ISP supplied the information on the fiber type and which VLAN ID's to setup for internet, TV and telephony.

This way I have my own equipment, that I control myself. The 'modem' [0] which my ISP supplied is still in its original, unopened box.

Post reply on HN