Afrihost Business Uncapped Feedback

Status
Not open for further replies.
No matter which DSL package you are using or provider that you are paying for access, you will always receive a dynamic IP assigned to you. Telkom makes it impossible for any ISP to assign a static ip on that level, hence why all ISPs are using tunnels.

Once you have authenticated your dsl account and received a dynamic ip, you initiate a tunnel to a LNS on Afrihost's network, in order to authenticate and assign a static IP. Of course, the customer's modem/router needs to be set up correctly so that it now route all traffic over the tunnel and not the dyanmic ip.

If your network engineers setup the LNS correctly, they would only allow certain IPs to be able to authenticate the tunnel in order to receive a static IP. There should be no reason why you can not add your own mobile 'dynamic ip ranges' to the LNS so that the tunnel can be built over either DSL or GSM.

Thats now if you have your own ip address space on your APN and not using MTN's space.

Michael

I'm not sure if that is the way that our system works, though what you describe sounds more like bonded tunneling, which also sometimes requires static IP addresses

To my knowledge, when you authenticate on our our network, we assign you the same IP address for every session, and that is controlled by our & MTN's radius servers. I don't believe that Telkom is involved at all but let me check it out so I can answer more thoroughly :)
 
I'm not sure if that is the way that our system works, though what you describe sounds more like bonded tunneling, which also sometimes requires static IP addresses

To my knowledge, when you authenticate on our our network, we assign you the same IP address for every session, and that is controlled by our & MTN's radius servers. I don't believe that Telkom is involved at all but let me check it out so I can answer more thoroughly :)

Of course Telkom is involved. DSL lines terminates in the exchange. From the DSLAM/ESR authentication is sent over based on the realm to say Afrihost. You then authenticate the user, and the user gets assigned a dynamic IP from the ESR. Telkom have a set of IP ranges per ESR for every ISP that buys IPC from them.

There is no way around that. Your line still need to authenticate before you can do l2tp!

Once the user authenticated then only can they initiate the tunnel to 196.30.121.50 hosted on your network. They then authenticate a second time, in order for radius to authorize the session with a set Framed-IP-Address attribute.

But sure, go ask the technical guys ;-)


Michael
 
Yeah, only business DSL will be able to access static IP's.

We would identify the account by the 'username" and assign an IP based on this. A 3G product will not be able to be assigned an IP address that will qualify for the service, so it would be rejected.

Please ask if this could be made available on Capped Accounts, only need like 25GB per month with higher line speeds....
 
Of course Telkom is involved. DSL lines terminates in the exchange. From the DSLAM/ESR authentication is sent over based on the realm to say Afrihost. You then authenticate the user, and the user gets assigned a dynamic IP from the ESR. Telkom have a set of IP ranges per ESR for every ISP that buys IPC from them.

There is no way around that. Your line still need to authenticate before you can do l2tp!

Once the user authenticated then only can they initiate the tunnel to 196.30.121.50 hosted on your network. They then authenticate a second time, in order for radius to authorize the session with a set Framed-IP-Address attribute.

But sure, go ask the technical guys ;-)


Michael

You seem technical. My toaster doesn't always make the bread brown, even though I put it on level 9. What can I do?
 
Is IPsec being used ? and if so what is the IPsec phrase
 
Is IPsec being used ? and if so what is the IPsec phrase

Afriman we need more details regarding the VPN service used to provide the static IP's! Some of us might use an SBS server, some mikrotik routers, not all of us are going to use your routers for static IP's, if we forced to use your routers for the service then static ip's are useless to most of us. We need details !
 
Afriman we need more details regarding the VPN service used to provide the static IP's! Some of us might use an SBS server, some mikrotik routers, not all of us are going to use your routers for static IP's, if we forced to use your routers for the service then static ip's are useless to most of us. We need details !

+ 1
 
Afriman we need more details regarding the VPN service used to provide the static IP's! Some of us might use an SBS server, some mikrotik routers, not all of us are going to use your routers for static IP's, if we forced to use your routers for the service then static ip's are useless to most of us. We need details !

I'll need more specific technical information to take this forward. We don't specify a router to use, we just recommend the Billion model. Any router that can use L2TP tunneling can connect to our L2TP server. I did post the server address earlier, but I can PM it to you as well if you still need the details :)
 
Its even a PITA to do from Linux, not many things support L2TP without IPSEC and I am not buying a stupid billion router, Not even netgears prosafe stuff supports without IPSEC
 
I'll need more specific technical information to take this forward. We don't specify a router to use, we just recommend the Billion model. Any router that can use L2TP tunneling can connect to our L2TP server. I did post the server address earlier, but I can PM it to you as well if you still need the details :)

Please are you using IPsec or not ??
 
I'll need more specific technical information to take this forward. We don't specify a router to use, we just recommend the Billion model. Any router that can use L2TP tunneling can connect to our L2TP server. I did post the server address earlier, but I can PM it to you as well if you still need the details :)

That is not true, it needs to do L2TP without IPSEC, which 99% of devices will not do
 
It might actually just be easier to get a 5$ VPS and install a VPN server on there that supports IPSEC, which most routers will support
 
Last edited:
That is not true, it needs to do L2TP without IPSEC, which 99% of devices will not do

This is my point, the static IP is useless. It is ok for the guys that buy the compatible routers, but for business who already have infrastructure in place it won't work, so what is the point of it exactly ?
 
That is not true, it needs to do L2TP without IPSEC, which 99% of devices will not do

Sorry my mistake. I have done a little more research and it seems that some router do require IPSEC to be turned on. My apologies for the mistake.

I have chatted to our team and the we cannot support IPSEC at this point. We are using MTN's existing fixed IP structure which does not support it. To activate it now will affect all the existing clients using the service. For routers that require IPSEC, we know that this is an issue, but there are other models which do not.

Going forward we will look at other options so we can offer more flexibility but I can't make any promised in that regard at this stage.
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X