Forum Discussion
Home internet service IPv6 traffic is all filtered even when using a Netgear LTE router. No port forwarding. Plz fix!
My background is in IT / networking and I started using Tmo Home Internet for the past 2 weeks. The router being shipped today to customers is missing very important features for power users - it actually broke my ability to remotely access my home via direct-connection using public IPv6 and IPv4 that I used on comcast.
Contacting support for help is pretty much useless, although I have raised a few tickets regarding the major issues affecting me since switching ISPs, namely:
- Unable to ping my IPv6 WAN address given by T-mobile (to remotely monitor my internet connection)
- Unable to remotely access my home via my VPN server which listens to connections on the WAN IPv6 address (again, T-mobile is filtering ALL my incoming traffic - comcast, att fiber, other major players in the market don’t do this filtering to endpoints except for spam port 25)
- Connecting to a VPN server hosted on the internet is unreliable and unstable.
- T-mobile does not offer IPv6 Prefix Delegation (comcast has it, att fiber does too)
I’ve spent the majority of my time trying to figure out ways to make this work. Most folks out there are blaming the Nokia router firmware which is really locked down by T-mobile, so being the IT engineer I pretend to be I purchased a Netgear LAX20 which is T-mobile and AT&T certified - I swapped SIMs for my Home internet service and tested both.
Even with a router that I fully control, with firewall disabled and allowing WAN icmp/ping responses T-mobile seems to continue to filter traffic (even pings!) incoming towards my service equipment… to make a fair comparison I got an AT&T SIM card and repeated the tests. On AT&T I can ping and access my device remotely when it is on the AT&T LTE network on the same Netgear LAX20.
Decided to post here to vent and share some findings, as this is somewhat frustrating that other LTE carriers that do not offer ‘home internet’ service do allow you to control and manage your network as you see fit while the new “home internet” service does not give you any control at all. Those users who wish to be able to remotely manage their smart home should perhaps stay away for now until T-mobile decides to do the right thing which is for “home internet” service subscribers to have different security network rules than cellphones on the network.
T-mobile please fix your business model for this new service, starting with adding the ability to request zero network filtering for home internet subscribers and the ability to get IPv6 prefix delegated.
- ReblogTransmission Trainee
intel wrote:
My background is in IT / networking and I started using Tmo Home Internet for the past 2 weeks. The router being shipped today to customers is missing very important features for power users - it actually broke my ability to remotely access my home via direct-connection using public IPv6 and IPv4 that I used on comcast.
Contacting support for help is pretty much useless, although I have raised a few tickets regarding the major issues affecting me since switching ISPs, namely:
- Unable to ping my IPv6 WAN address given by T-mobile (to remotely monitor my internet connection)
- Unable to remotely access my home via my VPN server which listens to connections on the WAN IPv6 address (again, T-mobile is filtering ALL my incoming traffic - comcast, att fiber, other major players in the market don’t do this filtering to endpoints except for spam port 25)
- Connecting to a VPN server hosted on the internet is unreliable and unstable.
- T-mobile does not offer IPv6 Prefix Delegation (comcast has it, att fiber does too)
I’ve spent the majority of my time trying to figure out ways to make this work. Most folks out there are blaming the Nokia router firmware which is really locked down by T-mobile, so being the IT engineer I pretend to be I purchased a Netgear LAX20 which is T-mobile and AT&T certified - I swapped SIMs for my Home internet service and tested both.
Even with a router that I fully control, with firewall disabled and allowing WAN icmp/ping responses T-mobile seems to continue to filter traffic (even pings!) incoming towards my service equipment… to make a fair comparison I got an AT&T SIM card and repeated the tests. On AT&T I can ping and access my device remotely when it is on the AT&T LTE network on the same Netgear LAX20.
Decided to post here to vent and share some findings, as this is somewhat frustrating that other LTE carriers that do not offer ‘home internet’ service do allow you to control and manage your network as you see fit while the new “home internet” service does not give you any control at all. Those users who wish to be able to remotely manage their smart home should perhaps stay away for now until T-mobile decides to do the right thing which is for “home internet” service subscribers to have different security network rules than cellphones on the network.
T-mobile please fix your business model for this new service, starting with adding the ability to request zero network filtering for home internet subscribers and the ability to get IPv6 prefix delegated.Would be really great if you post this over in the Reddit r/tmobileisp forum. Lots of people there working on the same issue, appears to be their use of CG-NAT. Agree?
- intelRoaming Rookie
Reblog wrote:
intel wrote:
x
Would be really great if you post this over in the Reddit r/tmobileisp forum. Lots of people there working on the same issue, appears to be their use of CG-NAT. Agree?
Agree. I’m active there - posted here as I don’t think T-mobile suits care about reddit and I may get someone at actually T-mobile to help raise the awareness of these issues.Here are some of my discussions in r/tmobileisp in:re T-mobile home internet.
Netgear LAX20 with ATT SIM card = IPv6 can be pinged and ports forwarded. T-mobile should fix their home internet and remove filtering on IPv6
https://www.reddit.com/r/tmobileisp/comments/l2iipa/netgear_lax20_with_att_sim_card_ipv6_can_be/
Unstable or "hung" SSH sessions when using the Nokia?
Xbox One NAT / UPnP results for the Nokia modem for those that asked.
I also posted this issue in DSLreports for those oldtimers like me that remember that site. https://www.dslreports.com/forum/r33010714-Connectivity-Incoming-traffic-filtering-by-Tmo-Home-internet-no-IPv6-DN
- djb14336Bandwidth Buddy
Agreed... still on the older white box, and it is doubly frustrating because we have access to the normal features (dmz, forwarding, firewall, etc) but none of the features work.
Can see their v6 details... set up my Asus to link up and try to run v6 instead of v4. No joy.... appears to work at first, but doesn't.
We are forced through a 464 tunnel. Any traces run show no nothing once you leave the LAN until you exit that tunnel on the other side.
Even setting up OVPN in the router gets knackered up.
No bridge mode on their devices... no v6 support on the LAN side... no proper way to manage port traversal…
Just so many ways they are missing the boat here.
Don't really need all of that to work right now (though it does suck not having remote access to a couple things)... but when I get around to doing multiplayer on the consoles again it WILL become an issue. May force me to switch back to a wired service again.
- JaykeTransmission Trainee
T-Mobile come on its been months now. Why do we still not have basic things like prefix delegation and inbound ipv6. This would let us use a real router with things like a guest network, and fix a lot of online gaming and vpn issues.
- djb14336Bandwidth Buddy
SGS wrote:
Great report. Does this issue prevent the ability to remotely access Wyze cameras, ring alarm system, Ooma phone and video doorbells. Thanks
yes. any unsolicited inbound connection will get blocked. basically, if an app or device requires a port to be opened/forwarded to work properly, it can knacker it up. peer to peer games/applications, remote desktops, inbound VPN’s… all manner of things are getting hosed because they are forcing us to use a 464XLAT approach instead of a more proper dual stack--or even full IPv6. - msd360Roaming Rookie
Jumping on this bandwagon too. As the OP, I made my living for over 40 years in IT and most lately HFC carrier ISP network monitoring. The Nokia gateway needs to act as an Ethernet bridge (just like cable modems do) so the public IP is handed to my router instead of the gateway and my router can handle VPN, port forwarding and other public facing services. Port forwarding at the Nokia gateway would be nice, but only after it can reliably provide WiFi and NAT services without overheating and thus affecting ability to connect to the 5G network with more than 1Mbps.
- SGSRoaming Rookie
Great report. Does this issue prevent the ability to remotely access Wyze cameras, ring alarm system, Ooma phone and video doorbells. Thanks
- darinfRoaming Rookie
Wow, That’s really bad.
I already signed up for TMO Home Internet, but the routers are backordered until March.
Now I am reading so many bad things about the service, I guess I should cancel the order. Too good to be true to think I could get 5G speeds for $50/month.
- uzunTransmission Trainee
I’ve had nothing but problems with T-Mobile and the new cylindrical router since I got it. It works on most websites but for gaming services its really hit or miss. Sometimes it works sometimes it does not. I think it’s due to lack of port forwarding. I keep T-Mobile because it is so fast in my area, 200-400mbps typical. But I just use it for uploads and downloads really. I have Verizon for any real internet use even though its limited to 50 Mbps.
T-Mobile does not work with most set top boxes or streaming internet devices, it does not work for most gaming sites via pc or console most of the time. It’s fast for uploads and downloads on sites that are compatible with it. I wish they would fix it to be a general purpose internet but I have no idea who to contact to get anything done.
I have spoken to the advanced tech support people and they say limitations of the network mean it won’t really work as general purpose home internet unless major changes are made to the T-Mobile network itself on their end, and that they have no plans to do it in the near future.
- mobileman82Transmission Trainee
Locutus wrote:
n8rbzu wrote:
This post I found seems related and comments have been disabled. (link below) I have had my gateway for three days now and just attempting the gateway settings and noticed port forwarding is missing. It looks like this has been an issue for some time and there are no plans to address it. So we were sold home internet, but got a wifi hotspot. I am sad that my only option now is to return the unit to T-Mobile and pay triple what T-Mobile was offering to get the same speeds with Cox. :-(
T-Mobile is an IPv6 network. Port forwarding is for ipv4 networks. So, its unlikely you will ever have port forwarding. For ipv6, right now T-Mobile blocks all unsolicited inbound traffic. This may be a global network configuration or it may be on the gateway. At any rate, there is no inbound traffic allowed at this time. If you need a work around, you can connect up your own router to the gateway and use a VPN service for about $5.00 a month.
What a dumpster fire. No Ipv6 or Ipv4. Might as well call this one way internet. This breaks multiple internet standards and expectations for an internet provider. Ipv4 is still crucial in 2021. Borking Ipv6 is not acceptable.
Related Content
- 25 days ago
- 4 years ago
- 11 months ago
- 6 years ago