Search This Blog

Thursday, March 3, 2022

Optus NBN 4G VPN Fiasco

 We have Optus NBN with 4G backup.  The mains is off in the whole suburb so the HFC is down and the router has dropped back to 4G.

The problem is that no one can work remotely.  They can not VPN in.

Windows VPN works on port 1723 and this is open on the router and was working back when the HFC was operational.  But when I use whatsmyip to scan from outside, the port shows as closed.  This means that it is being blocked inside Optus.

I have attempted to contact Optus and this has stumped them.  I finally got contact via the ap and also separately by putting a comment on their web page.  They get fixated on irrelevancies such as:
"this is a NBN issue and the NBN is down because the power is off."
Is the 4G even working and the good old "please reset your router"

4-3-2022 UPDATE
It appears that because of a shortage of IP addresses, the mobile networks put all the mobile customers effectivly on their own private LAN.  So when we access the internet from our mobile phone, we go out through a thing called CGNAT.  

OPTIONS
1.  Get Optus to move the sim out from behind the CGNAT
2.  Switch to another ISP who will.
3.  Set up a tunnel between us and an ISP and then host the VPN at the ISP.
4.  Hamachi or something similar.  Hamachi Gateway is $US839.99 for 5 computers.  (Not happening)

13-MAR-2022 Update
Ross has gotten ZeroTier working.  This is a free competitor to Hamchi which we couldn't get to work anyway.

 

 

 

This is the network






A really long and drawn-out communication on the ap that ended up with an appointment for NBN to visit me. 

3-3-2022 Optus called me as a result (I think) Spoke to "Loy"
She said call back on 133 343 and ask for "NBN Premium Business Support Team"

 

OTHER OPTIONS

 SIM outside the CGNAT and exposed to the public internet.
tunnel from inside here to the cloud and host the VPN in the cloud.
Hamachi/ logmein / whatever they are called now $800USD for 5 connections.

7-3-2022 Contacted Vodafone to see if they can do a SIM that is not behind the CGNAT and is exposed to the public internet.  








No comments:

Post a Comment