I connected my fiber internet directly to my pfsense router via SFP!

preview_player
Показать описание
I completely bypassed my ISP provided ONT and Wifi Router. I was able to install a SFP+ card in my PfSense box and plug the ISP provided SFP GPON Module "Nokia SFP ONT" with success.

I got 1.5 gig internet! Video Below:

FOLLOW UP:

Router Specs:
Supermicro X9SCL

Intel Xeon E3-1220 V2
4GB Memory
40GB Intel SSD

The SFP module provided by Telus is a G-010S-A P/N 3FE46541AADA

A few things to note:
My ISP (Telus) requires you to use the Actiontec wifi router if you have IPTV. I have heard people getting it to work without it, but unreliably. I don't have IPTV, but I think you could create a bridge inside pfsense between one of the RJ45 ethernet jacks and the SFP module resulting in the ability to get a public WAN ip on the Telus actiontec router. I might test this theory at my parents house... if they let me.

If you have fiber phone, my understanding is you need the white Nokia ONT as it has the POTS ports on the back.

I successfully got this to work with a Chelsio T420 dual 10gbe SFP +. Based on my testing, not all cards are compatible.
Рекомендации по теме
Комментарии
Автор

10:16 "700 Mbs not great" he says. I'm over here with 35 Mbs :(

R-L-D
Автор

Once a connection was made that put a smile on my face lol

PSYCHOPATHiO
Автор

I love finding new channels to watch. Subbed. Excited for upcoming content.

davidg
Автор

Fun facts!


The SFP that Telus provided you is actually an ONT in itself. Specifically, it's a Nokia O-010S-P, hence you don't need the white ONT as well; although you will need it if you have POTS lines through Telus. Of course you could run a SIP-based PBX, or use an ATA adaptor (such as the Polycom Obi-200 for Google Voice).


I recognize the white ONT as a Nokia ONT G-240G-A. I actually ran a proof-of-concept with a Nokia 7360 ISAM OLT and one or two of those ONTs. We also tested several of the G-040P-Q ONTs (a similar model with PoE but no POTS lines), and a few other models they had (such as a single-port, a rackmount 8-port, a 4-port with PoE, 2 POTS and RF TV, and another one like that but also with Wi-Fi). They even talked about the SFP ONT, which I believe was not GA yet, so we didn't get to test that out. I hoenstly wasn't impressed with Nokia's management software, mostly with the web-based UI. I had requested several improvements, which they did put in the next release, but it was still pretty awful. The Java client was extremely clunky, and took (literally, I counted) 24 clicks to change a VLAN on a port. They had only recently (at the time) started getting into the enterprise market, so most of their products and software were geared towards service providers.


I have since headed up a proof-of-concept with a Tellabs OLT, and we ultimately chose them over Nokia, due to its many powerful features (dynamic VLANs, automatic NAC assignment, complete intergration with Aruba ClearPass, physical hardware & capabilities, and an _extremely_ user-friendly interface, just to name a few of the reasons).


Now, you won't be able to just buy an ONT (including the SFP) off eBay, and you can't use a different brand either - Nokia GPON will only work with Nokia ONTs; Motorola and Tellabs are the same as well. Furthermore, the FSAN/serial number is tied to your service, in much the same way that the HFC MAC address of one's cable modem is used to provision their cable internet. They can buy a cable modem from BestBuy (as I have done), but it's not going to work until their ISP registers and provisions it on their system.


Similarly, an ONT is assigned a TDM channel by the GPON system, from 1 through either 32 or 64 (or technically up to 128, but 32 and 64 being the common number of fiber splits). In a service provider environment, automatic discovery/ranging and provisioning is not likely to be enabled, since they would have full control over and ownership of the CPE. The provider will likely either manually accept an automatic ONT discovery request, or require the ONT be entered into their system manually. In our enterprise environment, I've opted to use auto-discovery, and have configured it in a way such that any ONT being plugged into any building with PON will be automatically assigned that building's specific NAC profile (which includes the available VLANs), and the VLAN and ACL assigned to the port will depend on the authentication, be it user-based or MAC-based.


Of course, that's not to say this isn't extremely awesome! I totally wish I had the option to do it myself! Unfortunately, FiOS doesn't quite come out this far in my state, and while my town did put in its own fiber internet, it opted to deliver it via Wi-Fi to the home...so that was a big no from me, haha!

KatTheFoxtaur
Автор

This video is just gold on gold, I was randomly searching stuff about the "NOKIA XS-2426G-B" router and landed here with the first search hit.
Appreciate everything was done in 1 video and not in a 4 part video with a lot blabla to fill the series lol.
Also I love it when consumers win from draconian internet providers with their secret squeezing speeds sauce.
Why I was searching for the "NOKIA XS-2426G-B" you may ask, well I found an internet provider in EU that has consumer 2Gbps up/down for consumer prizes.
It is cool to see that we won't be stuck to 1Gbps for another decade, 2 Gbps is already here and talks about 3, 4, 5, 6, 7, 8, 9, 10 is just a photon away.

NN
Автор

This is a godsend, thank you so much. Fellow Canadian looking to build a PFSense box, did not want to have to deal with Bell's horseshit. Exactly what I needed! Well put together video

gvrry
Автор

I'm almost certain it wasn't a power issue with the SC-APC transceiver. Fiber transceivers in general are very low power. You likely ran afoul of HP limiting what SFP+ modules their products support. Your Dell duplex LC-type module is OEM-manufactured by Finisar, and they make HP's own transceivers too, so that's likely why the LC module worked.

Also, if you decide to do more experimenting, KNOW YOUR CABLES. Your carrier's fiber cable is a simplex SC-type, and the green color means it's APC (angled polish), which is fairly uncommon. That also requires SFPs specifically for APC connectors, so be kind to the one you have. The more common SC cables out there have blue connectors, which are UPC (uniform/flat polish). If you plug the wrong type into a transceiver that's expecting the other type, you will DESTROY the module and the fiber cable. So be careful.

Good call on getting the Chelsio card. Those are the gold standard for BSD (the OS that PFsense runs on), and they're transceiver agnostic. You won't find better for PFsense.

I would have liked to know what your throughput was before making all these changes though. Hard to tell how much improvement was gained.

t.williams
Автор

Different cards support different SFP module types.

TristynRusselo
Автор

Those intel cards will only work with specific spf's unless you add a specific boot argument to the kernel telling it "ignore unsupported sfp ids"

AnonyDave
Автор

IPTV setups in this context are multicast based. Additionally, the implementation is going to be covered under proprietary trade secrets by the Telco. As such, getting information about how to configure PFSense to properly relay the multicast traffic will be difficult.

thomasbonse
Автор

I just stumbled upon your channel, please keep making content like this, subbed !

syncgg
Автор

I use my ISPs ONT and a $150 Ubiquiti router and I get 950/550 (my plan is "gig/half gig"), so nothing wrong with my performance. But I too am a huge nerd and would love to move to SFP based termination, but I don't think it's really possible in New Zealand simply because it's intended for business customers and the plans cost so much more. I'm jealous!

jbrizz
Автор

Thanks for doing this. I am not a fan of the junky installs that (Telco) does with exposed wiring, multiple boxes required and and no chance of a single point battery backup. I have placed my installation on hold until I sort out some way to simplify things and eliminate exposed wiring.


Goal: Eliminate proprietary equipment inside house but still have TV. The Nokia ONT is okay, but the required modem is huge. Currently my cable modem setup resides in a structured wiring box and is UPS backed but the telco modem won't fit so it'll need an additional structured wiring box with another UPS.


This may be region specific but tech support tells me that SFP might work but if I want TV, I'll need to use the Nokia ONT+ the modem that they supply. The modem connects to the ONT via Cat5/6. There are 5 ethernet ports on the modem, one looks to be a WAN port connects to the ONT. 3 ports go to TV set top boxes using Cat 5/6 and the remaining port on the modem is for the LAN.

xwired
Автор

you should buy and install a rack on the basement :D

criptoportugal
Автор

Man, I’ve been run same setup, pfsense on pizza server and hp card 2x10gb and it worked like a charm. Cool 😎

opentechnology
Автор

They still have an ONT (2024 June install by Telus Fiber to home). Speeds are symmetrical ~950MB/s. The ONT > Telus modem > Telus router.
I do not have fiber to home in my area but when I finally do get it, hopefully can go from ONT directly to fiber SFP+ on my own router.

NetITGeeks
Автор

At 5:20 when you plugged the fiber connection in to the SFP you pulled on the release lever which activates a mechanism that pushes the ONT away from housing, so the HP card MAY have worked if you didn't do that, the SFP ONT may not have been seated correctly.

Jeradox
Автор

You should get one of those dry fiber optic cleaners. You'd be amazed how much one fingerprint can reduce your transmission speeds.

NortelGeek
Автор

I have an HP dual card sfp+ collecting dust in my closet. I have had the best luck with the Mellanox ConnectX 2 or 3 cards. I had a Chelsio card that either didn't work with my setup, or was dead on arrival. I'm dying to direct connect fiber to my router, since it has an sfp+ port on it to connect a transceiver. Thanks for the great video!

jeffmiller
Автор

Thanks you for doing this. I was so seeing about SFP fibre from ISP with PFsense for a while.

augurseer