8 ms·
You can take those routers and use it as a modem only. Then put your own router in front of it.
by deanclatworthy 5y ago
You can take those routers and use it as a modem only. Then put your own router in front of it.
- buggeryorkshire 5y agoIt's still not really modem-only mode. They do routing in there, mainly for their management layer.
- Semaphor 5y agoI must admit, I don’t know much about networking. But do you have some more information there? My German cable router is in modem-mode, and I’d be interested in knowing what kind of routing it still does.
- lxgr 5y agoDOCSIS networks usually assign some management IP address that the provider can access to perform remote diagnostics on the modem directly. It's usually invisible and inaccessible to the user. Also, in many cases there is a specific that the "modem" listens on, serving a web interface that allows switching back to "router" mode. This also wouldn't be possible with a "pure" modem (as it shouldn't have any concept of the IP layer).
- Semaphor 5y agoThat makes sense. After all, I weirdly had to use their webinterface to even put it into modem mode. Thanks. Though now that I’m thinking of it, are you sure it uses IP? It’s not as if they can’t use other layers.
- LilBytes 5y agoCan't speak for all Telco's but in Australia, DOCSIS modems are registered by their MAC address on the modem it's self. Not by IP address. I can't imagine this is different else where so it's likely the replying comment above yours is incorrect. Source: I was previously a network engineer for a national Telco. Other sources: DOCSIS 3.0 registration info: https://volpefirm.com/docsis-3-0-cable-modem-registration/ https://volpefirm.com/docsis-3-0-cable-modem-registration/
- dangerface 5y agoVirgin used to just use the mac address with their old modems, you could flash the firmware and change the mac so you could buy their cheapest package and flash the mac of a modem with unlimited gbit internet. They craked down on that a few years ago tho so I don't think this is possible anymore.
- lxgr 5y agoModern DOCSIS also uses certificate-based authentication. Only the owner of a given MAC OUI is able to create a certificate covering MACs under it that will be accepted by the CMTS.
- lxgr 5y agoRegistration/network access and management are two different things, no?
- LilBytes 5y agoNot always, with Telstra the MAC address was also responsible for authentication. Though I believe it's since changed, my last interaction with DOCSIS was 4-5 years ago. I seem to recall there's a captive portal involved now but previously it was solely MAC.
- thrashh 5y agoNote that even many actual DOCSIS modems have management interfaces and are not pure. I have always been able to view the management page for my Arris/Motorola Surfboard modems.
- gruez 5y agoBut that's fine right? If your ISP wants to send you bad packets having your own equipment isn't going to stop them either
- kevin_thibedeau 5y agoWhich then burdens you with a double NAT which shouldn't ever be necessary if the industry had their shit together.
- nly 5y agoNo you don't. In modem mode the VM routers only issue a single IP (the internet facing IP) over DHCP to a single host (your router)
- guipsp 5y agoFwiw not all modems support this (and some do but the ISPs disable it).
- mugsie 5y agoVirgin Media allows you to use "modem mode" on their service, which is great, because it also turns off the CGNat crap, and gives you a real IPv4 address via DHCP on your own equipment
- stordoff 5y agoI haven't tried it myself, but this chain of comments at /r/netsec[1] suggests it doesn't help: > I'm guessing a workaround is to use a 3rd party router and block traffic to 192.168.100.1 which is the IP of the management UI when in modem only mode, presumably the external IP can still be retrieved in modem only mode > If it's still active in modem-only mode, it essentially precludes use of these routers entirely for any sensitive comms. > The web interface is still available in bridge mode with Liberty Global's Arris modems, yes. > Just tried it on my device in modem-mode and it does indeed still expose the snmpGet endpoint. As suggested above, i've firewalled all traffic to 192.168.100.1 on my own firewall. [1] https://www.reddit.com/r/netsec/comments/pnzs0n/silently_unmasking_virgin_media_vpn_users_in/ https://www.reddit.com/r/netsec/comments/pnzs0n/silently_unm...