Skip to main content
Jasys
Explorer
March 29, 2017
Question

Fortiwifi 60E and SKY Fibre Broadband

  • March 29, 2017
  • 1 reply
  • 10926 views

Hi, Hoping someone can offer some help.

The Company I work for has partnered with Fortinet and provided certain engineers with Fortiwifi 60E units, I need to put this on my Network at home (they supplied these for us to use and play with)

 

I am with SKY FTTC, and as you may be aware, they are a nightmare as they lock down thier SKY Modem/Routers, they use MER (Mac Encapsulated Routing) which can be extracted using wireshark, which I have done to get the username and password.

 

So on my Fortigate, I use "WAN1" with PPOE, using the extracted username and password.

I removed the SKY Router, and plugged in a BT Openreach VDSL Modem, then connected that to WAN1

DSL light goes solid on the Modem, So I know that parts working, The WAN1 on the Gate, will not get an IP Address... just says Failed.

 

I even tried using subst-mac-dst on the WAN1 interface on the CLI, to "spoof" the SKY routers MAC, still nothing, has anyone any ideas please?

 

Thanks

    1 reply

    ede_pfau
    SuperUser
    SuperUser
    March 29, 2017

    Shouldn't be the spoofed MAC on the modem's WAN port? It's not relevant inside.

    Jasys
    JasysAuthor
    Explorer
    March 30, 2017

    ede_pfau wrote:

    Shouldn't be the spoofed MAC on the modem's WAN port? It's not relevant inside.

     Its not on the inside (My inside is using 10.10.20.1) , its facing the Modem, so essentially the WAN facing SKYs network.

     

    This morning I even tried, to put the SKY Router back, changed it too modem only mode, and pushed all traffic to a DMZ address of 192.168.0.2, and configured my Fortigate WAN1 to this address. Still nothing.

     

    Really fustrated (I am 100% sure this is not an issue with the Fortigate) I really need to get this working.

    ede_pfau
    SuperUser
    SuperUser
    March 30, 2017

    nope, you got me wrong. 'internal' in that sense is everywhere else in contrast to 'public' which the ISP sees. So, if the ISP authenticates via MAC then the "ISP facing" interface has to have the authorized MAC. And not some interface behind that, including the FGT.

    In contrast to IP addresses MAC addresses cannot be "forwarded" or such.