4 ms·
Biggest problems I have faced for home networks : ISPs are poorly configured and do very shady things sometimes like DNS hijacking. More often than not poor ONU
by trustingtrust 3y ago
Biggest problems I have faced for home networks : ISPs are poorly configured and do very shady things sometimes like DNS hijacking. More often than not poor ONU firmware or hardware means you will see weird things like latency spikes or straight up packet drops. Sometimes IPv6 won't work if the ONU is in bridge mode etc. etc.
This post is overkill but what mostly works for home networks:
SQM - like cake sqm in openwrt - will work wonders if don't have a great ISP. I have seen as much as 5% packet loss on one ISP who said thats acceptable for a home network. Just reduce the load until a point where packet loss is really low. Then use a DNS resolver. DNS resolver will be much more reliable like unbound for your local network as packet loss has cause really problems with DNS for me. Cheap home network equipment dns is not reliable. You could really just buy a cheap Pi and run a local resolver. It would work a lot better than your home router. You may also want to consider replacing the ONU. This is rather easier than you think. The ISP ONU are really bad. A cheap NOKIA SFP GPON is like 20$ on eBay and if you can figure out the PLOAM password and Serial and Mac and VPN ID of your ISP, you will be able to simply swap it for a more stable link.
All in all I would suggest for a simple home setup: get a cheap SFP GPON and replace your ONU. Get a cheap router (either router on stick with Rpi4 for <500mbit or x86 box with SFP for hitting 1gbps with the SFP GPON) and run your own unbound resolver. Get some APs and either wire them or get a cheap mesh router 3 pack on amazon (you can get a wifi 6 3 pack for under 150$ these days on sale) and run it in AP mode.
- iptrans 3y agoObvious caveats: GPON networks are often vendor locked. This means you cannot just buy any random SFP ONU and expect it work. Even if you do get it to work, no ISP will offer you any kind of support if you do this. Some might even take to it poorly, if they find out. Generally, the best option is to ask your ISP if they offer other ONU models and choose from those.
- trustingtrust 3y agoAlmost all ISPs use Serial and (optional) PLOAM to authenticate your ONU. Nokia GPON SFPs allow you to change almost everything that is exposed to the ISP for authentication. ITU standards mean that ISPs have to work according to the spec. ISP ONUs are locked for easier management for them. They will give you 1/10th of the speed promised if it helps them deal with support calls remotely rather than visiting your place to fix it. Support calls where people complain for things like 'I forgot my wifi password' cost ISPs a lot of money. So they can basically just login to your ONU at any time remotely and change settings for you like your wifi password. They do remote firmware updates and what not remotely. This is the biggest reason why ISPs love such modem router combos. Support can be guaranteed with a phone call to fix your wifi for the average Joe. You will not get ISP support if you use your own ONU but if you are using your own ONU then you are already at that point where you know what you are doing. As far as signal issues are concerned, like I said ITU specs mean they can see the signal strength remotely. Everything else they don't have access to but you don't need them to have that access. You can always swap out the ISP provided box to troubleshoot. If you actually swap out the ONU to a better one, chances are you'll never need to call your ISP unless there is a fiber cut or some serious signal loss somewhere.
- Karrot_Kream 3y agoWhy would you use a local DNS resolver instead of using a remote well-known resolver like 1.1.1.1 or 8.8.8.8 in a home networking situation? Your systems will cache DNS entries to paper over unavailability issues, and as long as you use one as your primary and the other as a secondary, there's a very low likelihood (probably < 0.0001%) that you'll ever have issues resolving DNS.
- abwizz 3y agobecause those 3rd-party resolvers are not under your control, which is usually interesting for someone running a homelab, and lie in responses. "it's always dns" should ring a bell :)
- Karrot_Kream 3y agoFor a homelab yes, but I figured GP was referring to a robust home network, not necessarily a homelab. "it's always dns" goes both ways as I've had local resolvers add huge amounts of latency to connection establishment.
- abwizz 3y agoyea. i was also advocating against local resolvers in the name of robustness, until my isp was starting to block certain domains. not really the fact that some domains i don't care much about are blocked, but this is a dangerous precedent in deviation from facts.
- trustingtrust 3y agoIf you look at systems like Deco (and a bunch of others I've noticed recently like linksys) the devices have stopped being dns forwarders themselves to clients and instead they assign your ISP (or the ones you've set for your ISP) DNS directly to clients. This means your device now resolves dns over wifi directly. This means each device is now relying directly on google and cloudflare instead of relying on the gateway (which being wired will experience the lowest latency especially when it comes to redirects and should ideally have a robust DNS server). A local network resolver instead of forwarder on a client seems to work a lot better in my experience especially when I use root DNS on unbound. Yes a root DNS is a lot slower than something like 8.8.8.8 but you could use an upstream dns with unbound if you really want something faster. Either way, a local DNS will be lot less problematic compared to if you devices has to handle all dns over wifi including the redirects (which happen a lot). Almost every time I see a network problem, it's always a DNS problem. In a typical home network setup these days: client DNS cache -> upstream DNS -> root DNS. client DNS cache -> local DNS - > upstream DNS -> root DNS. My setup: client DNS cache -> local DNS -> root DNS. The first one works better if the network is wired. Second and third one works better on wireless. One alternative that works 'okay' is if the client directly uses DoT or DoH for DNS. TCP works little more reliably than UDP (wink) but neither Google nor Cloudflare offer signed profiles for iOS and macOS (third party is there). Stubby works good on linux and android and windows have a built in solution.