OPNsense Forum

Archive => 23.7 Legacy Series => Topic started by: Tismofied on November 30, 2023, 06:27:07 PM

Title: New AT&T fiber service with bare metal opnsense
Post by: Tismofied on November 30, 2023, 06:27:07 PM
I am currently on the latest opnsense firmware 23.7.9 using spectrum cable internet with their modem in bridged mode. Also using a couple of tp-link switches for devices and such. Sg-108e and sg-2008p. >>>tp-link eap613 mounted on ceiling in the middle of the house for multiple vlans. All working as it should Finally lol. Took me a while to get everything working as it should because I am not network savvy but I am learning everyday. Most of the things I set was due to YouTube guides.
Now, I wanted to try fiber and see if I can get symmetrical connection and maybe lowest ping I can get. My kids and I play Xbox and pc games and would love a healthy with lowest latency for some of the competitive games.
I also set up tunneling following a guide here on this very forum for bufferbloat and I managed to get A+ test multiple times.
Knowing all this and the fact that AT&T fiber modems/routers don't allow bridged modes, would ip pass through work for me fine or do I have to research more about opnatt.sh script ? I heard the latter method doesn't work with certain fiber connections.
The main thing I want to do is bypass their gateway. I want to keep using opnsense to handle everything in my network otherwise I'll be double natted and that's not the goal.
Please advise!
Title: Re: New AT&T fiber service with bare metal opnsense
Post by: MoonbeamFrame on November 30, 2023, 07:33:32 PM

If you check out their website https://www.att.com/support/article/u-verse-high-speed-internet/KM1011652 (https://www.att.com/support/article/u-verse-high-speed-internet/KM1011652) they state that the interface is Ethernet/RJ45

So you'll just need a regular network cable to connect to your firewall.
Title: Re: New AT&T fiber service with bare metal opnsense
Post by: Tismofied on November 30, 2023, 07:39:55 PM
I don't want to use their modem as a gateway also. I just want it to get me a public ip and hand it over to opnsense where I handle all my firewall rules and vlans.
Title: Re: New AT&T fiber service with bare metal opnsense
Post by: MoonbeamFrame on December 01, 2023, 12:57:25 AM

Think of the ONT as a media converter providing you with the same type of physical interface that you would have had for DSL.

Your OPNsense box will do the authentication and routing.
Title: Re: New AT&T fiber service with bare metal opnsense
Post by: Tismofied on December 01, 2023, 01:06:40 AM
Thank you for the explanation. I got a tech coming next Saturday. Hopefully everything goes smooth.
Title: Re: New AT&T fiber service with bare metal opnsense
Post by: meyergru on December 01, 2023, 01:56:01 AM
@MoonbeamFrame: I doubt that it will be that easy. While it is true that the AT&T fiber modems/routers terminate with RJ45, this is not a simple GPON ONT brdige that can be used with DHCP or PPPoE.

All AT&T normally offers is "IP Passthrough", with certain disadvantages. There is a tricky solution for pfSense (https://github.com/MonkWho/pfatt/tree/master), where the background is explained in great detail.

The mentioned script seems to work for OpnSense as well (https://jimahn.com/posts/opnsense-att-gateway-bypass/), but it sure looks complicated.
Title: Re: New AT&T fiber service with bare metal opnsense
Post by: MoonbeamFrame on December 01, 2023, 11:18:45 AM
@meyergru

Noted. Thanks. That's a good write-up.