The Huawei B593 LTE discussion thread

Edit: I've been told my idea isn't possible so I'm retracting my post to save face.
 
Last edited:
I am using B593 601 on roaming. Cell C card using Vodacom 3G. There is no LTE yet on the area. I get it connecting, sometimes battling with it, but every time I switch off the router it goes back from manual to auto network selection. Cell C signal is too poor to use. I do have antenna. Huawei B315 keeps the setting and works fine.

Has anybody experienced the same? And is there a solution outside buying an other B315?
 
Hi Guys,

We are using the Huawei B593S-601 LTE Router at work.

Currently there are no real security/firewell restrictions on outgoing stuff, so employees are having a field day with Facebook, Youtube etc.

I want to restrict access to these (and other) sites, but allow access to everything for certain MAC IDs - fairly straightforward Firewalling, but I don't see a way of doing that on this router.

Could someone please tell me if I'm wrong on this, and how to go about doing so?

I don't run through a server so don't have the option of software based firewalling, and we don't use a different router - everything runs through the Huawei.

Help?
 
Hi Guys,

We are using the Huawei B593S-601 LTE Router at work.

Currently there are no real security/firewell restrictions on outgoing stuff, so employees are having a field day with Facebook, Youtube etc.

I want to restrict access to these (and other) sites, but allow access to everything for certain MAC IDs - fairly straightforward Firewalling, but I don't see a way of doing that on this router.

Could someone please tell me if I'm wrong on this, and how to go about doing so?

I don't run through a server so don't have the option of software based firewalling, and we don't use a different router - everything runs through the Huawei.

Help?
I don't think these LTE routers are robust enough to handle all that custom stuff. If you want to do proper internet policing you'll probably need to bridge a more capable utm device to the B593. A few free solutions are available out there that you can run on a spare PC
 
I think your only real option on the B593 UI is to blacklist those sites, outright.
 
We are using the Huawei B593S-601 LTE Router at work.
Currently there are no real security/firewall restrictions on outgoing stuff, so employees are having a field day with Facebook, Youtube etc.
I want to restrict access to these (and other) sites, but allow access to everything for certain MAC IDs - fairly straightforward Firewalling, but I don't see a way of doing that on this router.
Could someone please tell me if I'm wrong on this, and how to go about doing so?
The B593 is an all-in-one device containing a modem, router, firewall, 4-port switch and Wireless Access Point WAP). The performance of the LTE modem is excellent, but as with all such "combo" devices, the functionality of the other add-on bits is basic at best. That is certainly true of the B593's router/firewall subsystems - they provide only the most basic functionality. Most folks with more "serious" network requirements will rapidly find they need a "proper" router downstream of the B593 to do the heavy lifting.

With that said, you can configure some (very) basic rules in the B593 as follows :
  1. Go to Security / Firewall level and set the level to at least Medium or High (or custom). This enables URL and IP filtering.
  2. Under Security / URL FIltering, enter the URL strings for the sites you want to block access to (eg www.facebook.com)

My understanding is that this filtering only works at the DNS level, ie when a LAN client requests DNS resolution of a URL that's "banned" in the blacklist, that DNS request will be blocked, preventing access.
This will fail if the LAN client specifies the site's IP address directly, or if the actual IP address has been previously resolved and cached somewhere. However it could complicate navigation within a site to such an extent that it serves as an adequate deterrent.
You could go one step further and blacklist specific destination IP addresses (under Security / IP Filtering), but with big sites mirrored at multiple locations, this could get complicated.
As regards the "supervisor" machines, you could experiment with additional MAC filtering to see if entering a MAC Whitelist will override any blocking performed at the URL and IP level. However I suspect you will very rapidly find yourself spending a large part of your life managing URLs, IPs and MAC addresses!
This is indeed "fairly straightforward firewalling", but the B593 provides only basic tools to implement it.


I don't run through a server so don't have the option of software based firewalling, and we don't use a different router - everything runs through the Huawei. Help?
Particularly for a small business, you probably want to look at getting a more capable router/gateway/firewall device to provide more sophisticated router functionality and URL filtering.
As a start, you could look at hardware-based solutions (security "Gateways"). You could also look at software solutions like pfsense and MikroTik's RouterOS. The latter can run either as a software solution on a dedicated PC, or on a pre-configured hardware device. They can also provide a lot of additional benefits in the form of traffic statistics, bandwidth limiting, user accounting etc.
At the upper end of the scale, traditional firewall/routers and "network security appliances" from the likes of Netgear might fit the bill. Many of these use an online service to keep abreast of security threats and changing profiles for "banned" sites, eg translating the instruction "prevent access to Facebook, YouTube and known adult sites" into a host of different rules, much more effectively than you can.
 
Last edited:
Does router make a difference to lte speeds?

Hi, I purchased a lte month to month contract from telkom. When the agent was here to sell me the uncapped contract, he was able (with his router, I think it was Huawei B315 with bunny ears / two little antennas) to get 35mbps download and something like 12 mbps upload. But I went in store to get it activated as I did not require a long term contract. I then purchased a Broadcom zte mf253 lte router, and was promised it would do just fine as the previous owner was getting 55mbps for the same telkom lte product. But ever since I plugged it in I have only been getting 2,3,5 maybe 8 if I'm lucky download and with a connection that is CONSTANTLY dropping. I live next to a "quiet" railway line with the stop quite close to us and trains stop by every 20-30 minutes . And so does the connection I see. We are also directly in the path of the airplanes to Cape Town airport.

Do you think it could be that the router is the issue?

I put the sim into my Huawei laptop modem, and although I am constantly dropping/connecting at least I'm getting far more work done that the zte router, but speeds around 2-3mbps or less it seems. I have logged a technical call with Telkom but they say it will take upto 27 days to just even look at the problem.

Any advice? Need the internet for work and at these speeds and connection issues, it is so frustrating.
 
I then purchased a Broadcom zte mf253 lte router, and was promised it would do just fine as the previous owner was getting 55mbps for the same telkom lte product. But ever since I plugged it in I have only been getting 2,3,5 maybe 8 if I'm lucky download and with a connection that is CONSTANTLY dropping.
If you suspect that technician was using B315s, why you are posting in B592 thread? :)

Anyway, my comment apply to both Huawei routers. They are CAT 4 LTE routers, while MF253 is CAT 3. Maximum 3G speed is DC-HSPA+ which can be a twice of MF253. Comparable ZTE product is MF283+.

In LTE mode maximum speed difference is not so big, so I suspect your router is dropping to 3G. For Telkom you need a modem with support for TDD 2300MHz frequency.
 
Hey guys
Hoping someone can help me with port forwading on the B593 and a Lenovo ix4-300d NAS device that I would like to access remotely. Router is B593-601.

Its my first time doing this sort of thing but I have tried but it doesnt seem to be working, perhaps Im missing something.
I will upload pics of what the lenovo says to do and what I did shortly.
 
Hey guys
Hoping someone can help me with port forwading on the B593 and a Lenovo ix4-300d NAS device that I would like to access remotely. Router is B593-601.

Its my first time doing this sort of thing but I have tried but it doesnt seem to be working, perhaps Im missing something.
I will upload pics of what the lenovo says to do and what I did shortly.

Lenovo settings

View attachment 380236

View attachment 380238

B593 settings

View attachment 380240


Im not sure what to put into "remote host" and "remote range"
Hoping someone can tell me where Im going wrong.
 
Hey guys
Hoping someone can help me with port-forwarding on the B593 and a Lenovo ix4-300d NAS device that I would like to access remotely. Router is B593-601.
Its my first time doing this sort of thing but I have tried but it doesnt seem to be working, perhaps Im missing something.
I will upload pics of what the lenovo says to do and what I did shortly.

I'm not sure what to put into "remote host" and "remote range"
Hoping someone can tell me where I'm going wrong.
Your image uploads are busted, unfortunately; but ... some general background :

In theory, you could use the port-forwarding page to forward a range of ports (like 80 through 443) on the B593's WAN IP address, to a corresponding range of ports (like 8080 through 8443) on a local host IP address. In practise, however, that UI page is dysfunctional : you can define a range of ports for the incoming WAN connection, but only one single port on the local host to which that traffic will be forwarded. So, using the same example, you could forward incoming packets on WAN ports 80 through 443, all to port 8080 on a LAN host IP (which is virtually guaranteed to do NOTHING useful at all).

So practically, this means you have to use the table on that UI page to define each port to be forwarded separately, ie one row entry in the forwarding table per port.

As for the "remote host", this is intended to limit the port-forwarding action only to WAN traffic that originates from a certain IP or URL. Generally you would just leave that entry blank.

This post shows a practical example related to viewing IP cameras remotely. Also check out a few posts above and below that one where the topic was discussed in a few different scenarios.
 
Last edited:
Your image uploads are busted, unfortunately; but ... some general background :

In theory, you could use the port-forwarding page to forward a range of ports (like 80 through 443) on the B593's WAN IP address, to a corresponding range of ports (like 8080 through 8443) on a local host IP address. In practise, however, that UI page is dysfunctional : you can define a range of ports for the incoming WAN connection, but only one single port on the local host to which that traffic will be forwarded. So, using the same example, you could forward incoming packets on WAN ports 80 through 443, all to port 8080 on a LAN host IP (which is virtually guaranteed to do NOTHING useful at all).

So practically, this means you have to use the table on that UI page to define each port to be forwarded separately, ie one row entry in the forwarding table per port.

As for the "remote host", this is intended to limit the port-forwarding action only to WAN traffic that originates from a certain IP or URL. Generally you would just leave that entry blank.

This post shows a practical example related to viewing IP cameras remotely. Also check out a few posts above and below that one where the topic was discussed in a few different scenarios.

Thanks jcheek
Will check out the link and if I'm don't come right will remind the pics.
 
I think I spotted my problem. I need to put in the same port in the remote port range. Will test on Monday when I'm. Back at the office.
 
Your image uploads are busted, unfortunately; but ... some general background :

In theory, you could use the port-forwarding page to forward a range of ports (like 80 through 443) on the B593's WAN IP address, to a corresponding range of ports (like 8080 through 8443) on a local host IP address. In practise, however, that UI page is dysfunctional : you can define a range of ports for the incoming WAN connection, but only one single port on the local host to which that traffic will be forwarded. So, using the same example, you could forward incoming packets on WAN ports 80 through 443, all to port 8080 on a LAN host IP (which is virtually guaranteed to do NOTHING useful at all).

So practically, this means you have to use the table on that UI page to define each port to be forwarded separately, ie one row entry in the forwarding table per port.

As for the "remote host", this is intended to limit the port-forwarding action only to WAN traffic that originates from a certain IP or URL. Generally you would just leave that entry blank.

This post shows a practical example related to viewing IP cameras remotely. Also check out a few posts above and below that one where the topic was discussed in a few different scenarios.

Still cant get it to work
Have tried the pics again

B593

20160808_083357_zps3kqwtfch.jpg


Lenovo

20160808_083420_zps06daxmlu.jpg


20160805_120117_zpsds1yadtu.jpg
 
Still cant get it to work
Have tried the pics again.
Pics now good.

Do you have a working scheme (DDNS) in place to resolve a custom hostname (like rodgaNAS.dyndns.org) into the current public IP of the B593's WAN connection ? Or are you looking up the current public IP and entering it manually in order to gain access from the internet ?

If you're sure your access request is ending up at the correct IP, perhaps try temporarily enabling DMZ mode on your B593 (Security / DMZ / Enable) and placing the Lenovo NAS in the DMZ, ie ALL traffic will be temporarily forwarded to 192.168.1.101. Then see if that works ?
 
Last edited:
Pics now good.

Do you have a working scheme (DDNS) in place to resolve a custom hostname (like rodgaNAS.dyndns.org) into the current public IP of the B593's WAN connection ? Or are you looking up the current public IP and entering it manually in order to gain access from the internet ?


If you're sure your access request is ending up at the correct IP, perhaps try temporarily enabling DMZ mode on your B593 (Security / DMZ / Enable) and placing the Lenovo NAS in the DMZ, ie ALL traffic will be temporarily forwarded to 192.168.1.101. Then see if that works ?

Still trying to figure this out

I dont have a custom hostname.
 
Top
Sign up to the MyBroadband newsletter
X