Community discussions

MikroTik App
 
JustinG
just joined
Topic Author
Posts: 1
Joined: Wed Feb 19, 2014 11:05 pm

AT&T U-verse w/ RB750

Mon Feb 24, 2014 7:23 am

Ok, so I need some help, I need to setup a RB750 behind a U-verse router. The U-verse router needs to stay due to the TV service running through it. After some searching I found some instructions below. Shouldn't I turn off DHCP in the U-verse router? Any special setting in the RB750? Keep in mind this is my first time setting up a Mikrotik router, I will be messing around with the RB750 tomorrow to see if I can find my way around it. Thanks in advance for any help you can provide.

To do so:
With a computer directly connected to the U-verse router, go to http://192.168.1.254
Click on Settings
Click on Firewall
Click on Applications, Pinholes and DMZ (it may ask you for a system password, this is located on your U-verse router)
From the list of devices under Select a computer, choose your apple time capsule. If you do not see it, you will need to check the connections on your apple time capsule, and be sure you have it setup correctly to work with our U-verse router. You may need to change it DHCP.
Click on the option at the bottom that states "Allow all applications (DMZplus mode)"
Click Save
Reboot your apple time capsule.

---------

There is no true bridge mode on the 2Wire routers. However, you can still configure it such that almost all functions of your own router will work properly.

1. Set your router's WAN interface to get an IP address via DHCP. This is required at first so that the 2Wire recognizes your router.
2. Plug your router's WAN interface to one of the 2Wire's LAN interfaces.
3. Restart your router, let it get an IP address via DHCP.
4. Log into the 2Wire router's interface. Go to Settings -> Firewall -> Applications, Pinholes, and DMZ
5. Select your router under section (1).
6. Click the DMZPlus button under section (2).
7. Click the Save button.
8. Restart your router, when it gets an address via DHCP again, it will be the public outside IP address. At this point, you can leave your router in DHCP mode (make sure the firewall on your router allows the DHCP renewal packets, which will occur every 10 minutes), or you can change your router's IP address assignment on the WAN interface to static, and use the same settings it received via DHCP.
9. On the 2Wire router, go to Settings -> Firewall -> Advanced Configuration
10. Uncheck the following: Stealth Mode, Block Ping, Strict UDP Session Control.
11. Check everything under Outbound Protocol Control except NetBIOS.
12. Uncheck NetBIOS under Inbound Protocol Control.
13. Uncheck all the Attack Detection checkboxes (7 of them).
14. Click Save.

Your router should now be able to route as if the 2Wire was a straight bridge, for the most part.

Inbound port 22 might be blocked, and inbound ports 8000-8015 might also be blocked, and there's nothing that can be done about it.

This is how I have my 2Wire configured, and I have a Cisco 2811 behind it doing IPSec, IPv6 tunnels, etc.

--------------
 
jandafields
Forum Guru
Forum Guru
Posts: 1515
Joined: Mon Sep 19, 2005 6:12 pm

Re: AT&T U-verse w/ RB750

Wed Feb 26, 2014 6:38 am

Also keep in mind that U-Verse will give you a PRIVATE 10.x.x.x ip address (on their WAN side)... not a public ip address. I think that even if you pay for a static ip address, they will map a static ip address to a private 10.x.x.x address. Any port forwarding you want to do has to be done through the main AT&T network (through your AT&T customer portal), and not the U-Verse modem.

So, your connection is already NAT'd regardless of bridge-mode with CNAT (Carrier Grade NAT). Unless you are needing incoming connections for servers on your network, just do a regular NAT in Mikrotik so Mikrotik gets an address from U-Verse, and then Mikrotik hands out addresses in another network to the clients. That will be double-nat, but most applications will work with double if they can work with single anyway.

U-Verse is horrible when it comes to trying to get a "real" connection to the Internet. And, don't call AT&T for help on this, they read you a canned response "try unplugging for 30 seconds", "reboot your computer", "disable your Anti-Virus program", "we don't support your operating system", "hold the reset button", "we can see your connection just fine from our side".

Who is online

Users browsing this forum: akakua, Amazon [Bot], che, unhuzpt and 68 guests