KevinEpicom's profile

Contributor

 • 

1 Message

Monday, November 30th, 2015 11:14 PM

Bypass or disable NAT table on NVG595?

I've searched and experimented to the extent of my ability, but I cannot find a way to effectivly bypass or disable the NVG595's NAT table entirely. Our office is constantly running into the problem of its NAT table capping out at around 2,000 entries, so it is having to flush some of the old ones. We have a nice pfSense firewall resting behind it that is capable of supporting many more sessions, but we can't use them because this gateway that AT&T gave us insists on getting involved.

 

My goal is to allow the pfSense router to freely use the /29 block of IP addresses we were given. I have it somewhat working correctly with IP aliases, but that doesn't stop the NVG595 from recording a NAT session for every single connection my router makes. I haven't yet tried the cascaded router option, but I've read elsewhere that in doing so, the NAT table will still record sessions. Has anyone else tried this?

 

If what I'm looking for is not possible, is there any other gateway device AT&T offers for use in a medium-sized business?

Professor

 • 

3.9K Messages

8 years ago

@Darknessrise or @lem3, eather of of you fell like playing O.J. and taking a stab at this?   thanks.

Professor

 • 

2.4K Messages

8 years ago

@Tigereyze209

@KevinEpicom

 

This seems to be a case where you might need to use the cascaded router function in your settings I believe(I might be wrong). I don't have much experience with static IPs on U-verse business to really point you in the correct direction. Maybe you might know more about the setting than I do. It's something to look into.

 

There's IP passthrough, but I don't believe it will do what you're looking to do. I don't think it's a real option when you have an static IP block.

 

There is a modem only device for business called the Arris NM55. However, I have never heard of anyone getting one. I'm not sure if AT&T ever released it.

Professor

 • 

3.9K Messages

8 years ago

You know, it suddenly dawns on me, if you are a business customer for ATT, you are also entittled to tech support thru your designated account representative, who's job it is, to handle issues exactly like this one.

AND why you pay extra for business class account services.

Good luck!

Contributor

 • 

1 Message

6 years ago

I do not understand the business logic of ATT with respect to business fiber with sole use of NVG595. You can almost get infinite bandwidth (up to 1G symmetric) with fiber but limited by small NAT sessions (2560 sessions, feels like small meter). By my measurement, the device itself uses anywhere from 300-700 sessions. So when you reach 1800 NAT sessions, your router/gateway crushes. It is quite easy to use large number of sessions if you open up several tabs in a browser and access the router/gateway through Wifi. We found the NAT limitation soon after we had installed the fiber. ATT tech suggested me to call Tech360 (ATT fee-based IT services). The advice I got was that you cannot fix the NAT sessions limitation by static IP or IP passthrough. I got a sense of being run around.

All the band width you get is wasted! So ATT business fiber advertisement is NOT entirely truthful. ATT uses large bandwidth to get you in. But your usage is limited by small NAT sessions. I do not see a large number of small businesses will adopt the business fiber as a gateway to internet unless ATT changes its practices.

For reference, my home Uverse DSL gateway has a NAT sessions limit 8172. In term of functionality, my home internet performs better with an old old technology and small band width (25M by 5M).

Contributor

 • 

2 Messages

6 years ago

I think I'm having a similar problem, thanks for posting! It's been driving me crazy, I have gigabit / uverse and I want to host my own webserver. My server and client are wired, Speedtest.net is fine. But "port forwarding" on my ARRIS BGW210-700 (software 1.3.12) is really flaky and slow, at least when accessed internally.

 

E.g. in http://192.168.1.254 router console I set Firewall => NAT/Gaming to map HTTPS TCP/UDP: 443 to my "webserver" machine port 443. The problem is "curl -v https://public-ip/" is really slow every other time I try it. There is a long hang before it makes the connection, and often it fails completely. "curl -v https://webserver" directly is always fast. Since I'm also wired into my home network I expect it to be equivalent.

 

I finally discovered that if I "Reset all sessions" in the NAT Table under Diagnostics the next "curl -v https://public-ip/" is consistently fast. Does anybody know why? This router doesn't do something crazy like allow only a single connection at a time, does it?! It shows only 88 total sessions in use out of 8192 available, so I don't think I'm running out of sessions.

 

Thanks,

Jamshid

Tutor

 • 

4 Messages

6 years ago

At&t business fiber service has no service level agreement. If you want better service you can order advanced switched Ethernet service with a service level agreement. You will no longer have NAT problems.

Contributor

 • 

2 Messages

5 years ago

Its more like AT&T business "fibber" service, has no service! Do not sell a solution as a Business Solution if it can't truly function for a business. Provide business class equipment or allow business to use their own. Spectrum broadband doesn't have an SLA either but the server does actually work. I spent 150 hours working with 12 different AT&T technicians (remotely and onsite) with zero resolution. They switch out the equipment a couple times. The firewall would be disabled but yet still blocking traffic. The equipment is buggy and very poor design. The NAT sessions might be one of the limitations but inability to truly disable the firewall is a major problem and causes most of the issues I found (could also cause the NAT issue). They sell the service saying "Greater for hosted websites and eCommerce" but I think I'd have more luck with my 56k Modem than my 1Gig AT&T Fiber! Oh and did I mention completely insecure Gateways as well! If you are considering AT&T fiber for your business run away as fast as you can! Go with Spectrum broadband or Fiber.  Go with Level3. Shoot, go with Verizon 4G over AT&T fibber. You will live a longer and happier life, trust me!

Not finding what you're looking for?
New to AT&T Community?
New to the AT&T Community? Start by visiting the Community How-To.
New to the AT&T Community?
Visit the Community How-To.