[FWA510/515] - It's possible to execute a PPPoE over VLAN using the LAN/WAN port?

Options
Maverick87
Maverick87 image  Master Member
Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
edited August 16 in Mobile Broadband

Hello,
I've an USG Flex 500H and would like to buy an FWA510/515 as connection backup.

I use the USG Flex 500H with WAN (on port P1) that do a PPPoE over VLAN; in this way my network use the single WAN point to exit on internet.

Now, with also the FWA, I can connect it on port P2 and use the firewall in dual-WAN configuration active, passive; in this way if I don't have internet on port P1, the port P2 take the WAN priority and my network use 5G as exit point on internet.

Now, my question is: can directly the FWA do the PPPoE over VLAN? In this way I can use only one port on the firewall, and leave that the dual-WAN configuration is done by the FWA directly.

Also, it's possible to maintain the downstream IP via Bridge/IP Passthrough for both PPPoE and 5G/WAN Backup usage?

So..
1. The FWA support the PPPoE over VLAN (using the LAN/WAN port)?
2. What is the best approach to use the dual-WAN active, passive configuration? Done it by FWA side or Flex 500H side? How I can configure the "WAN" interface into the firewall?

My usage can be:
- FWA with LAN/WAN used as primary WAN with PPPoE;
- FWA with WAN Backup as 5G;
- The LAN side of the FWA as internet entry-point for the firewall;
- Disable all the L2/L3 feature (Routing/NAT/Firewall/DNS/VLAN/DHCP etc etc) on the FWA;
- Leave the L2/L3 layer management to the firewall.

It's possible obtain this? How I need to configure the "WAN side" on the firewall?

Thank you

«1

All Replies

  • Zyxel_Tina
    Zyxel_Tina image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @Maverick87,

    1. PPPoE over VLAN on the FWA’s Ethernet WAN

    After checking, support for this feature depends on the FWA model. The FWA510 does not support VLAN configuration, while the FWA515 does.

    On the FWA515, navigate to Network Setting > Broadband > Add or Edit a New WAN Interface to configure the Ethernet WAN interface.

    image.png

    2. Dual-WAN on the Firewall (USG FLEX 500H)

    For your setup, with P1 connected to the fixed-line connection and P2 connected to the FWA515, you can configure dual-WAN failover directly on the firewall:

    • Configure the mobile router in Router mode and connect it to P2. The firewall interface will obtain an IP address via DHCP.
    • Configure the PPPoE connection directly on P1, including the VLAN tag if required by your ISP.
    • On the firewall, navigate to Network > Interface > Trunk and create a trunk. Add both WAN interfaces, set P1 as Active and P2 (the FWA connection) as Passive, and then designate it as the Default Trunk.

    This configuration provides a straightforward primary-and-backup WAN failover setup. For detailed information, please refer to this FAQ.

    Zyxel Tina

  • Maverick87
    Maverick87 image  Master Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
    edited August 18
    Options

    Hi @Zyxel_Tina,

    Thank you.

    Ok, I configure the VLAN on the FWA515, but how I can use the PPPoE? I see that the encapsulation is selected as IPoE, but I need the PPPoE over VLAN 835 to initialize an internet connection.

    If the FWA515 support the PPPoE over VLAN, I can use the ETHWAN to establish the internet connection over WAN, and then I can use the failover on 5G; all this can be managed directly on the FWA515 and in this way it can manage also the internet connection.

    In this way, I can configure a single port on the flex 500H because the connection management is directly into the FWA.

    Can I see under the dropdown menu "Encapsulation" what are the other choice?
    There is a demo website for some FWA?

    Thank you

  • Maverick87
    Maverick87 image  Master Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
    Options

    Hi @Zyxel_Tina,

    I asked to a user to share the ETHWAN configuration of the FWA515

    image.jpeg

    So:

    1. Seems there is a possibility to set the encapsulation as PPPoE
    2. It's possible then to insert username and password
    3. It's possible also to specify a VLAN

    My actual configuration is:
    ONT Fiber ETH —> USG FLEX 500H P1 (configured as PPPoE over VLAN 835)

    To avoid using another firewall port, I would now like to configure the new infrastructure as follows:

    1. ONT Fiber ETH --> FWA515 ETHWAN (PPPoE Passthrough)
    2. FWA515 LAN --> USG FLEX 500H P1 (still configured as an external interface but without DHCP)

    At this point, the firewall no longer performs failover/backup between ports P1 and P2; instead, is the FWA itself that acts as a backup, pass to the LAN port the fiber connection (if present), or the 5G cellular network if PPPoE fails for some reason.

    Could this work? How can I configure port P1 on the firewall to receive the IP from the uplink?

    Thank you

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    So you have one ISP that works by ethernet and PPPoE VLAN 835?

  • Maverick87
    Maverick87 image  Master Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
    Options

    Hi Peter,

    Yes, only one single ISP on PPPoE over VLAN

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 19
    Options

    I don't have PPPoE for testing (well not by a real ISP just a testing PPPoE by linux mint) but from what I can tell it can work but not in the way I would like.

    so FWA515 becomes your main router by PPPoE with likely your WAN IP but by connecting your FLEX 500H you no longer need PPPoE because FWA515 will give out a LAN IP by ethernet now at this point you will double NAT or if the FWA515 support static routes then your LAN IP/subnet on FLEX H can have routing rules with SNAT none and static routes them LAN IP/subnet  on FWA515 back to FLEX H IP. on fail of your ONT Fiber the FWA515 will use 5G and all your devices on FLEX H will go over to that.

    or

    You can have FLEX 500H on one port with PPPoE and another port for FWA515 and do the fail over on FLEX H which I think is best.

  • Maverick87
    Maverick87 image  Master Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
    Options

    I think that using the Passthrought functionality (for PPPoE and Cellular), is not necessary the double NAT; using passthrought the WAN/5G IP is directly passed to the output port (so is passed the public ip, not the 192.168.x.x ip), and in this way the port are directly exposed to external and is not necessary the double NAT.

    Or I'm wrong somethings?

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    I don't think that will work when you enable the Cellular IP Passthrough you no longer have the WAN option.

  • Maverick87
    Maverick87 image  Master Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Nebula Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate
    Options

    So you think that if I enable the PPPoE Passthrought, is not possible also enable togheter the Cellular IP Passthrought? Is not possible to enable both the passthrought?

  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited August 19
    Options

    Some things are unclear till someone does it unless people who have done just happen to of done it and reply.

    So I think I get what you want you want there to be one WAN port on the FLEX H that the FWA515 ack as a switch you get PPPoE by VLAN and Cellular IP Passthrought goes to the same port by ethernet…it would seem that would work…but then will it forward the tagged packets…

    ….what might work is a small VLAN switch so that you tag your PPPoE VLAN 835 by two ports and a third port has your FWA515 untagged and untagged out the port with the tag port to FLEX H…I think that will work.

Consumer Product Help Center