03-30-2011, 09:02 PM | #1 | ||
Pro Starter
Join Date: Oct 2000
Location: Cary, NC
|
Routers, Firewall, and RoadRunner
I have upgraded to Road Runner Extreme. Along with this came a new modem / router combo, the Ubee DDW3611. This includes 4 gigabit ports for the router side, and 802.11n wireless networking. I can set this up in bridge mode so it works just like a cablemodem and then connect my old router, but with new smartphones in the house I like having the wireless capability. Plus gigabit ports on the router can't hurt as I move forward wiring the house.
The problem is that the firewall in this thing is pretty pathetic. There is an IP Flood Detection setting that if you leave it on causes major packet loss. I've turned that off, and almost everything is working fine, except most video streaming seems to want to cut off after around 20 minutes with a dropped connection. If I retry a minute or two later, it reconnects and goes fine for another 20 minutes. There is another setting called "Firewall Protection". From reading that I just assume that means turning the firewall on and off, but the description is more narrow and claims it helps prevent denial of service attacks. I'm also hearing that this should be turned off, but that may just be a suggestion for bridge mode, and I get very nervous about turning the firewall off completely. So there's a mix of "does this really turn the whole firewall off?" and "do I need the setting anyway?". So my first question is, with a router doing NAT for the rest of the network, how important is having a firewall active? And second, is anyone familiar enough with this modem to know if that setting deactivates the whole thing, or just some specific feature of it? There is no manual for the modem, and TWC is not supporting any other DOCSIS 3 modems right now (they have a Motorola that includes voice but is not fully supported yet, and they won't support you getting your own DOCSIS 3 modem), so I'm a bit stuck at finding answers about this thing. Any networking gurus with any suggestions here that will prevent me from putting it in bridge mode and going back to my old router?
__________________
-- Greg -- Author of various FOF utilities |
||
03-30-2011, 09:06 PM | #2 |
Pro Starter
Join Date: Oct 2000
Location: Cary, NC
|
And apparently the thing has four operating modes: Bridge Mode, NAT mode, Router mode, and NAT router mode. I understand that Bridge Mode is just a pass-through, but I did not know you could have NAT and Router mode as two separate thing. Right now it's set to NAT mode, I wonder if it should be NAT and Router mode?
__________________
-- Greg -- Author of various FOF utilities |
03-30-2011, 09:07 PM | #3 |
Death Herald
Join Date: Nov 2000
Location: Le stelle la notte sono grandi e luminose nel cuore profondo del Texas
|
If you are worried about security, I tend to shy away from "all in one" solutions. If any part gets compromised, then the whole unit is compromised. The way I have my network set up is:
Cable ----> Cable Modem ------> Firewall -----> Switch From the switch I have lines going to other switches and wireless access points.
__________________
Thinkin' of a master plan 'Cuz ain't nuthin' but sweat inside my hand So I dig into my pocket, all my money is spent So I dig deeper but still comin' up with lint |
03-30-2011, 09:17 PM | #4 | |
Grizzled Veteran
Join Date: Nov 2003
Location: MA
|
I think the NAT will be enough for what you are doing, that was going to be my recommendation before you mentioned it. That said I'm not at all familiar with that router.
Quote:
Unless your access points are routers(in which case only wireless will be buffered) or you are running fancy enterprise switching all that needs to be compromised there is the firewall and you're done. No different from an all-in-one. Modems, switches and vanilla access points aren't going to stop anything. Last edited by jeff061 : 03-30-2011 at 09:18 PM. |
|
03-30-2011, 09:26 PM | #5 |
Death Herald
Join Date: Nov 2000
Location: Le stelle la notte sono grandi e luminose nel cuore profondo del Texas
|
True, but NAT itself isn't a firewall. Plus, once a vulnerability is found in a particular cable modem device, script kiddies go to town hacking for the hell of it since the vast majority of people rely solely on the cable modem to provide all of the protection, and they know which providers use which model devices. I like having a beefier independent firewall in place, and put the effort into locking down that, as I have more control there than I do at the cable modem.
__________________
Thinkin' of a master plan 'Cuz ain't nuthin' but sweat inside my hand So I dig into my pocket, all my money is spent So I dig deeper but still comin' up with lint |
03-30-2011, 09:32 PM | #6 |
Grizzled Veteran
Join Date: Nov 2003
Location: MA
|
Nope, NAT isn't a firewall, but it's not going to allow inbound connections through without having port forwarding configured. Which is good enough for most people.
|
03-30-2011, 09:37 PM | #7 | |
Pro Starter
Join Date: Oct 2000
Location: Cary, NC
|
Quote:
That's what I was wondering about, and whether I should turn off the "Firewall Protection" setting because it may be blocking stuff it shouldn't be. But I don't want to go wide open, either. The answer may be to go back into Bridge mode and stick my old router (an RP614 from Netgear) back in the as the main connection for internal network. Or optionally something beefire, my searching for info has turned up some interesting options from Sonicwall (saw that separately in a different discussion here) and Netgear. Not sure if that means losing the wireless though, although we mostly leave that turned off and only turn it on when we want to download an app to the smartphone.
__________________
-- Greg -- Author of various FOF utilities |
|
03-30-2011, 10:26 PM | #8 |
Grizzled Veteran
Join Date: Nov 2003
Location: MA
|
Sonicwall may be a little overkill for the home, though maybe they have a really cheap model, not sure
I'm happy with my D-Link, Netgear I believe is fine as well. Linksys has tanked over the last few years. Last edited by jeff061 : 03-30-2011 at 10:26 PM. |
03-31-2011, 08:58 AM | #9 |
Pro Starter
Join Date: Oct 2000
Location: Cary, NC
|
Thanks for all the advice folks. Going to play around with some stuff and see if I can pin down the issues.
__________________
-- Greg -- Author of various FOF utilities |
03-31-2011, 02:11 PM | #10 |
Coordinator
Join Date: Nov 2003
Location: The Great Northwest
|
I wish I could help you on this one, but all we are handing out in the LA West area are the Motorola SBG6580, which I'm not very fond of either. My only experience with the Ubee was when I went to North Carolina for training on our Signature Home/Service product. I will email the company from my TWC address and see if they can give me a manual (since their site has nothing).
|
03-31-2011, 07:00 PM | #11 | |
Pro Starter
Join Date: Oct 2000
Location: Cary, NC
|
Quote:
See the fun part is most stuff is working fine, so even pinning this down on the router is just a shot in the dark. I still need to test streaming on another device, because the Sony Blu-Ray that started giving problems goes through Sony's servers which sometimes have issues, and my wife's machine (connected through same router) is not having the PuTTY issues mine is, so we'll see. But yeah, figuring out the firewall / router settings is a PITA on this Ubee.
__________________
-- Greg -- Author of various FOF utilities |
|
04-01-2011, 10:45 AM | #12 |
Coordinator
Join Date: Nov 2003
Location: The Great Northwest
|
I was able to get a User Guide from Ubee, if you like I can post it somewhere for you to download or email it to you. If you have a specific question that isn't covered in it I think I can get some answers from the advanced solutions engineer that wrote me back.
__________________
Los Angeles Dodgers Check out the FOFC Groups on Facebook! and Reddit! DON'T REPORT ME BRO! Last edited by DanGarion : 04-01-2011 at 10:46 AM. |
04-01-2011, 12:31 PM | #13 | |
Pro Starter
Join Date: Oct 2000
Location: Cary, NC
|
Quote:
You da man! gstelmack AT nc DOT rr DOT com
__________________
-- Greg -- Author of various FOF utilities |
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
Thread Tools | |
|
|