Home Network - What do I need?

Jan 17, 2007 61 Replies

Hi all



OK so the Mrs and rugrats are wearing me down on the old why-can't-we-get-broadband front again. So the question is what do I need? Currently I have a wired network and netgear switch, this switch being located in the loft. Also I have a telephone line from the master box in the hall to a distribution junction box in the loft from which all telephones are fed.



My intention was to get one of the face plates for the phone master box which gives both phone and original A & B connection points on the rear. (Do those face plates include a filter for the phone connections so I don't need microfilters?)



So, using my link cable to the loft, I connect the filtered phone terminals to my existing junction box and have the two unfiltered A & B feeds available also.



The key question is: what do I connect to the unfiltered connections?



What I would like to achieve is:



Wired network access to broadband internet connection. Provision of future wireless access service. Facility to VPN into work network via Checkpoint client. Sensible-to-good level of security on wireless bit.



My problem (at least the one pertinent to this question) is that I am not clear on the difference between a modem and router, what security these provide in terms of firewalling etc.



Any informed advice gratefully received The location is Hull, so I believe the provider choice is limited to Kingston Comms!


TIA



Phil


On Wed, 17 Jan 2007 13:33:04 -0000 someone who may be "TheScullster" wrote this:-

Yes, provided you wire them up properly.

One cable, four pair? This can be used with three pairs for the normal extension wiring and one pair for the unfiltered signal.

However, to get the best speeds disconnect the ringing signal from this cable, you can then use two pairs. Re-generate the ringing in the loft.

1) Connect an ADSL router (which will have a built in modem) with radio network to your ADSL socket. Programme it via a local computer. 2) When that is done and the security settings are as you want them, connect the router to the switch via a network cable. 3) Do any configuration you need to the computers on the network, usually changing the network settings from dial up. 4) Unplug any modems.

The VPN tunnel can either originate from your computer, or from the router (in which case all computers can use it). The first option means any old router can be used, the second option means a more expensive router for which

formatting link
takes some beating.

You need a wireless ADSL router. Possiobly with VPN support. (most have this)

An 'ADSL router' does

1./. The ADSL modem bit.

2/. The routing bit.

3/. The firewall bit. Blocking all incoming packets that are not from previously established sessions or otherwise as defined by the firewall rules

4/. the NAT bit (hanging all your stuff behind one IP address and sorting out the incoming packets to post them off to the machines they belong to).

5/. DHCP CLIENT to establish what public IP address its on from the ISP.

6/. A wireless hub, to act as a wirluss hub for wireless networked devices.

It may also be set to do..

7/. The VPN bit (encrypting data to another VPN target so that it is not crackable and requeres constant authentication etc)

8/. The DHCP server bit, to act as a custodian of internal IP addresses and parcel them out to stupid WinDoze machines that are set to 'assign automatic IP address'

9/. A DNS proxy, to service name to address lookups and pass them along to the ISP's DNS servers.

10/. Possibly a time server for NTP.

Not bad for a £50 box eh?

Netgear do some decent enough ones.

(cut snippet) Good answer David.

Wireless or homeplug (Data over AC Mains)?

Wireless could be a possibility. However, often the problem with that is the location of the BT master socket (or your own secondaries) are not always the best position for a wireless access point. So what I did was to use a pair of Home plug 88Meg (14 Meg would also be fine), one at the location of the BT master socket (less attenuation of the DSL DMT signals) and the other high up in my landing (I have run power into the attic off of my Water Heater spur above my airing cupboard) and come off there). I can then have a conveniently located wireless access point !! You could also use Homeplug instead of your Netgear (forget about all your Cat 5 cabling) and send all your data down the mains. It's the dogs bollocks !!! I work in networking professionally as a design consultant (CCIE #11330) and homeplug is the way to go for home networks of that I am sure. You can even get a four port Etherent switch with an homeplug connection for £50 !!! So, you buy two of these, whack them into the mains, they automatically find each other and you have two four port switches interconnected at 88 or 14 meg across the mains !!! Bloody fantastic.

Read this:

formatting link
for the text wrap

Yes. The best way to do it is to filter with a faceplate at the master socket and put your ADSL modem/router next to it on a short (custom made) cable. Then run ethernet from the modem/router to your switch.

ONLY your ADSL modem/router device, see above. The filtered output is for your ordinary phones. But I think you know that. If running a CAT5 from the loft to the master socket and filtered faceplate isn't an option, use the existing telephone cable and take just the A & B wires up to the loft and use the filtered faceplate up there (the back half of NTE5's are available).

I'd not get a wireless ADSL modem/router, eggs and baskets. Also your master socket is not likely to be in the best place for the wireless side. Have the two as different boxes means you can place both in the best places for each.

A modem would take the ethernet and convert it to ADSL and vice versa it would do nothing else. A router does all the fancy packet handling, NAT, firewalling etc. Marketing as always has muddied the water and the terms are used incorrectly a lot of the time.

"Kaiser Sose" wrote

I already have wireless heating controls and would be concerned about cross talk between these and wireless network devices. Also, if I say with wired I can better control where the kids can work!!!

Phil

Agreed mate - same with me and my kids. However, homeplug is worth looking at if you want to make a new connection and having difficulty getting a Cat5 cable.

"David Hansen" wrote

Can you clarify this please? Do you mean simply connect both conductors of a twisted pair to one terminal, and both conductors of another twisted pair to another? e. g. increasing the area of conductor(s) used to carry the signal?

Phil

A couple more questions arise here:

How do you test a broadband connection? With standard phone, you take off the faceplate, plug a phone in and check for dial tone. If the phone and broadband service stops, how do you trouble shoot?

Back to the original question:

I would like to locate the modem and router in the loft. Is there a removable face plate which simply duplicates terminals A & B? If so, and I think this is what Dave L was driving at, can I take A & B into the loft and connect to a master box up there for splitting phone and ADSL? Will the length of phone cable between ground floor and loft degrade signal?

Pros and cons please?

TIA

Phil

its easy enough to run a twisted pair phone line from the phone socket to the router. And cheaper than running two boxes with cat 5 between them. And much less critical on cable quality.

Log into your router - it has diagnostics.

Using the router. If you have phone, but no broadband, the cble to the exchange is OK. you then have one of three generic problems

1/. The xchg DSLAM is down. That gives you and ADSL error. 2/. The frame relay backhaul to the ISP is down. That gives a frame relay error. 3/. The ISP frame relay link is OK but you can't log in. Thats an ISP issue. Usually teh radius servers are borked.

If all of those are OK but connectivity is still shot iot may be internet links in or adjoining your ISP.

I wouldn't..not good for radio..

Not at all. Its generally come a mile or two already.

I would stick the router as near to where the computers are as possible, and route the PHONE cable to it.

Your most unreliable link is wireless. Keep it short. CAT 5 is far more predictable.

Difficult without specialist test gear. There are two components to a successful DSL Internet connection:

  1. The DSL physical line must be up. Your router should have some sort of "status" menu where you can check this. This is the actual wired connection from the output of your router to the DSLAM (pronounced D-SLAM) in the telephone exchange (Digital Subscriber Line Access Multiplexor)
  2. The datalink layer needs to be established. This is normally some kind of PPP over ATM connection on PVC 0/38 normally. This should be in the "UP" state and you should have received an IP address from your provider automatically upon successful negotiation. This will all happen automatically. If this is not "up" then you could have entered the wrong username/password etc. It goes without saying that this will not enter the up state unless the DSL physical layer is up too. Again your router should show you that you have an IP address and it should also have learned the DNS servers and default gateway by either IPCP or DHCP, depending on the provider you use. If you see this information you may be assured that you have established an Internet connection. The result of what I am saying is that your DSL router itself is a great bit of test equipment.

A good test is to see whether you can ping one of your IPS's DNS Servers, or any device in their domain. That will rule out the rest of the Internet and any peering problems your ISP may be encountering with an hofher level Internet backbone provider (Tier 1).

TIP: Be aware that your "Internet connection" is just your means of connecting to the cloud that represents the Internet. The Internet itself is the vast web of servers, networks and computers that comprise the web.

question:

As I said in an earlier post, I would connect the router at the BT master socket (ignoring the built in wireless) and use homeplug networking to get to your Ethernet switch in the loft. Use one of the Ethernet ports on the switch to connect to the Homeplug device in the loft and likewise on your router near the BT socket. All your network will then be protected by the firewall built into your router. Any VPN tunnels you create will establish and protect all your network. You could use split tunnelling so that traffic destined to your workplace gets sent down the tunnel but your kids traffic goes straight out to the Internet (i.e. not encrypted down the tunnel).

I've got wireless heating controls (Honeywell CM67NG) and a wireless LAN, and there are no problems. It's easy to get the wireless router to use different channels.

On Wed, 17 Jan 2007 16:00:37 -0000 someone who may be "TheScullster" wrote this:-

Set to different channels.

You are the one who spoke about radio networks:-)

You can turn the radio network off as and when you want. As others have said there are advantages and disadvantages of having both in the same box. However, as you are trying to fit something into an existing arrangement then the ideal becomes more difficult to achieve.

By the sounds of it, just an ADSL router plus suitable filtering to start with.

Yes.

You can get master versions (designed to replace the front of a BT style NTE/5 box), and you can also get secondary extension socket types.

Yup it does that

You can either fit a wireless router now, and turn off the wireless until you need it, or suppliment a non wireless one with a wireless access point later.

If you don't want to have the matching server running on a computer inside the LAN then you will need a router with VPN termination capability. Note that most *do not* have this. Many will talk about having VPN passthrough etc, which means that they will allow a VPN to worth through them, but this is not the same as VPN termination or a VPN server.

You can get routers that support the termination directly (although check the checkpoint compatibility before you buy), or you can get sepearate VPN termination devices that can sit behind a "normal" router.

Having an external box terminate the VPN also means that the VPN client by default has access to the whole LAN usually...

Something that supports WPA2 then.

A modem in its simplest form just does the translation to the ADSL domain and offers no additional facilities in many cases. Mostly these tend to be USB devices, although there are some that have ethernet as well (the things blueyonder and telewest give out to cable customers are often like this).

An ADSL router includes a modem, typically a firewall (packet filtering at the simplest level - some also support statefull inspection), a routing capability, and usually Network Address Translation (NAT) - which in itself offers some firewall like capabilities of its own.

Sounds likely.

Beware that the "support" on most, does not include providing the server side termination of the VPN - only passthrough of the VPN packets.

(usually privided by a web server (and possibly tlenet server) built into the router)

Many routers have separate ADSL and PPP status lights these days, which will help identify which problem you have... i.e. 1) DSL light is off or flashing, 2 & 3) DSL light on, PPP light off.

Or sometimes just lack of DNS resolution.

I have not found a router in the £100 and sub £100 class that can do worthwhile VPN termination in any reliable sense of the word. Most of them can only just about manage to stay up without a weekly reboot. The quality of their firmware and its support is just not up to the job. The Linksys RV042 is purported to do the job, but user experiences seem to be mixed.

For a worthwhile solution, one really needs to go into the realms of lower end Cisco routers (e.g. a secondhand 2600 etc.) or a PC configured with Linux or a packaged Linux firewall.

On Thu, 18 Jan 2007 07:56:29 +0000 someone who may be Andy Hall wrote this:-

I would venture that such routers are designed to terminate VPNs from people who work from home sometimes and occasionally need to transfer a file or get e-mail. Linking two offices together permanently is a different thing altogether.

In general I would agree with you if the application were to link office to office. However, the vendors do advertise VPN termination capability and it should therefore work properly and reliably.

The RV042 is just about under £100 and is advertised as a VPN termination for users accessing small/home offices while on the road. Results seem to be quite mixed from comments I've heard and read about them.

OTOH, I've used a FreeBSD box for several years for various forms of VPN termination. Apart from the occasional security related patch, it stays up for months on end and is only rebooted in the event of a complete system upgrade.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required