Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PPPoE on WAN link for Centurylink gigabit service

    General pfSense Questions
    23
    51
    47.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      The C2000T has DSL and ethernet WAN ports it looks like.  OP can you port a picture of the back of the C2000T when the service is working?  If DSL, you'll need to use  a DSL modem of some sort.  If ethernet handoff you might be able to get it working with nothing but pfSense WAN.

      Also, you seem to have some uncertainty that you tagged VLAN 201 correctly.  What did Interfaces > (assign) look like when you tried it?

      From what I can tell if you tag vlan 201 to Centurylink's ONT it should work.  My couple minutes of searching yield:

      • People reporting PPPoE and/or DHCP working

      • People reporting you might need to clear the MAC address (ARP) table in the ONT with a reboot if you change routers.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • A
        almabes
        last edited by

        O@Derelict:

        The C2000T has DSL and ethernet WAN ports it looks like.  OP can you port a picture of the back of the C2000T when the service is working?  If DSL, you'll need to use  a DSL modem of some sort.  If ethernet handoff you might be able to get it working with nothing but pfSense WAN.

        Also, you seem to have some uncertainty that you tagged VLAN 201 correctly.  What did Interfaces > (assign) look like when you tried it?

        From what I can tell if you tag vlan 201 to Centurylink's ONT it should work.  My couple minutes of searching yield:

        • People reporting PPPoE and/or DHCP working

        • People reporting you might need to clear the MAC address (ARP) table in the ONT with a reboot if you change routers.

        Just re-read the OP, and he states that the its set for Ethernet, so I retract my previous "Bridge that puppy" statement.  I misunderstood how CenturyLink handed off to you.

        First you'll need to know which interface is WAN, in my case it's re1

        Then, from the Interfaces (assign) menu option you will add VLAN 201 and assign it to your WAN interface (re1 in my case)

        You then can reassign your WAN interface to re1 VLAN 201

        Last you should be able to configure your PPPoE credentials on the WAN interface.

        interfaces.png
        interfaces.png_thumb
        Vlan201.png
        Vlan201.png_thumb
        AssignVLAN201toWAN.png
        AssignVLAN201toWAN.png_thumb

        1 Reply Last reply Reply Quote 0
        • J
          johns1
          last edited by

          Thank you for the suggestions both almabes and Derelict. As soon as I am able I will configure as suggested and post images of the configuration with results.

          1 Reply Last reply Reply Quote 0
          • J
            johns1
            last edited by

            Sorry for the delay in posting back an update. I was called out of town for an unscheduled trip.

            almabes and Derelict, I am happy to report that I now have a connected link on the WAN. However, pfsense can't seem to connect to the outside world even thought the link is UP. The version window in the dashboard states "Unable to check for updates" and the Gateway Monitoring Daemon (apinger) is stopped and under the Gateways the WAN_PPPOE status is Unknown.

            So far I have tried rebooting the ONT but that did not change anything (link still goes up, but no passing traffic). I tried using the MTU value of 1492 as my google searching said that was a Centurylink requirement as well as not putting a MTU value in (default) and that doesn't change anything, I get the link UP but no passing of traffic.

            Any other ideas you can think of to try?

            Let me know if you want me to post some specific image of a configuration tab from pfsense.

            Thank you again for any help you can provide.

            1 Reply Last reply Reply Quote 0
            • A
              almabes
              last edited by

              Post a screenshot of Status–System Logs--PPP tab.

              Maybe that will point us in the right direction.

              Edit:
              Status--Interfaces might be helpful, too.

              1 Reply Last reply Reply Quote 0
              • J
                johns1
                last edited by

                Ok. Both are attached.

                Thank you again for your help.

                SystemLogsPPP.png
                SystemLogsPPP.png_thumb
                StatusInterfaces.png
                StatusInterfaces.png_thumb

                1 Reply Last reply Reply Quote 0
                • J
                  johns1
                  last edited by

                  I decided to give Centurylink support a call to see what if anything they could do to help me. I spent about an hour on the phone with the GPON support engineer. He did state that they do not require a MTU of 1492, that is a direct contradiction to what the settings on my C2000T modem show. So I think I will keep trying it both ways. We tried a number of other configuration changes, but no matter what could not seem to get the entire link process to complete. He stated he could see that my system had established a link and taken the full 1 gigabit of bandwidth available but that the PPPoE authentication was not completing. He noted that authentication attempts are logged to their RADIUS server and that from the entries he could see it looked like the pfSense server was starting a connection and then requesting to closing the connection itself.

                  I am going to continue trying to get this to work and will post updates if I make progress.

                  If any other members of the forum have advice feel free to provide input.

                  A special thank you to almabes for taking time to try and troubleshoot this with me.

                  1 Reply Last reply Reply Quote 0
                  • ?
                    Guest
                    last edited by

                    Maybe this will help you.
                    https://www.dslreports.com/forum/r29358085-VLAN-Tagging-on-Tomato-for-FTTH

                    I have read about people successful in get CL to remove VLAN tagging, then you won't need their router at all.

                    1 Reply Last reply Reply Quote 0
                    • G
                      goetter
                      last edited by

                      Have you made any progress?

                      I will soon be attempting the same thing with CenturyLink.

                      1 Reply Last reply Reply Quote 0
                      • L
                        l3lack
                        last edited by

                        I, too, would love to hear the progress for this issue. I would like to be able to get rid of CT2000, and have pfsense connect directly to CenturyLink.

                        1 Reply Last reply Reply Quote 0
                        • superweaselS
                          superweasel
                          last edited by

                          I received CenturyLink Gigabit Internet service two weeks ago and was able to immediately replace the C2000T with pfSense for use with the service. It was simple to setup.

                          Here are the steps:

                          • Create a VLAN with ID 201, Interfaces>Assign>VLANs

                          • Assign the VLAN to the WAN parent interface

                          • Create a PPP interface for the WAN, Interfaces>Assign>PPPs

                          • Make the following PPP settings:

                          Link type - PPPoE
                                      Link interface(s) - WAN interface with VLAN, e.g. igb1_vlan201
                                      Provide the Username and Password for the CenturyLink account
                                      Save

                          At this point, the WAN interface will connect to the CenturyLink service.

                          I have noticed that the C2000T is about 20 percent faster on download speed tests and on parity with upload speed tests when compared to pfSense running on a SG-4860. Not exactly sure why that would be the case. Still investigating.

                          Screenshots of the settings below.

                          ![Voila_Capture 2015-06-08_04-16-51_PM.png](/public/imported_attachments/1/Voila_Capture 2015-06-08_04-16-51_PM.png)
                          ![Voila_Capture 2015-06-08_04-16-51_PM.png_thumb](/public/imported_attachments/1/Voila_Capture 2015-06-08_04-16-51_PM.png_thumb)
                          ![Voila_Capture 2015-06-08_04-15-56_PM.png](/public/imported_attachments/1/Voila_Capture 2015-06-08_04-15-56_PM.png)
                          ![Voila_Capture 2015-06-08_04-15-56_PM.png_thumb](/public/imported_attachments/1/Voila_Capture 2015-06-08_04-15-56_PM.png_thumb)

                          pfSense rig: pfSense SG-4860/120GB SSD
                          WAN: CenturyLink Gigabit Fiber

                          1 Reply Last reply Reply Quote 1
                          • J
                            johns1
                            last edited by

                            superweasel, thank you for posting some detail. For some reason new post to thread notifications were not reaching me so I was not aware that new posts had been made.

                            I tried to follow your instructions and even went so far as to do a complete new install of 2.2.3 to make sure old configuration changes were not affecting me but I still can't get pfsense to work with Centurylink. By following your advice I have made more progress than before. I was unclear about what the WAN link should be set to on Interfaces (assign) so I put it to the PPPoE option created by following your instructions. pfsense then gets an IP address on the WAN link but clients on the LAN can't get to the internet. Screen shots are below, note in PPPtoWAN image that pfsense gets and IP address, can tell it is on the current release but the 1000baseT full duplex is missing. When I set the WAN back to em0 (default) I get the 1000baseT link full duplex but no IP address.

                            I am sure there is some minor setting I am missing, and I would appreciate any further advice you have.

                            Thank you in advance for any help you can provide.

                            WANtoPPP.png
                            WANtoPPP.png_thumb
                            WANbackinitial.png
                            WANbackinitial.png_thumb

                            1 Reply Last reply Reply Quote 0
                            • superweaselS
                              superweasel
                              last edited by

                              With an IP address from CenturyLink, the WAN side of the house is all set. IP address from CenturyLink is the critical piece. With PPPoE, pfSense does not report connection speed or duplex.

                              Make sure the PPPoE Gateway is set as the Default Gateway (System>Routing, see image below). You might also want to add the CenturyLink DNS servers to your DNS list (System>General>DNS servers, see image below).

                              As for the LAN side, most likely a firewall issue or route issue. Make sure you are not blocking routes to the WAN from LAN (see image below). Just to verify, take a look at Diagnostics>Routes to see if LAN can route to WAN.

                              Last one, in researching the speed issue with pfSense and gigabit PPPoE connections, I opened a support ticket with pfSense. As of v2.2.3, pfSense will not attain gigabit speeds with PPPoE (https://redmine.pfsense.org/issues/4821).

                              ![Voila_Capture 2015-07-20_07-40-22_AM.png](/public/imported_attachments/1/Voila_Capture 2015-07-20_07-40-22_AM.png)
                              ![Voila_Capture 2015-07-20_07-40-22_AM.png_thumb](/public/imported_attachments/1/Voila_Capture 2015-07-20_07-40-22_AM.png_thumb)
                              ![Voila_Capture 2015-07-20_07-34-11_AM.png](/public/imported_attachments/1/Voila_Capture 2015-07-20_07-34-11_AM.png)
                              ![Voila_Capture 2015-07-20_07-34-11_AM.png_thumb](/public/imported_attachments/1/Voila_Capture 2015-07-20_07-34-11_AM.png_thumb)
                              ![Voila_Capture 2015-07-20_07-34-58_AM.png](/public/imported_attachments/1/Voila_Capture 2015-07-20_07-34-58_AM.png)
                              ![Voila_Capture 2015-07-20_07-34-58_AM.png_thumb](/public/imported_attachments/1/Voila_Capture 2015-07-20_07-34-58_AM.png_thumb)

                              pfSense rig: pfSense SG-4860/120GB SSD
                              WAN: CenturyLink Gigabit Fiber

                              1 Reply Last reply Reply Quote 0
                              • J
                                johns1
                                last edited by

                                superweasel, many thanks for your posts. I am now up and running on pfSense!. It turns out the inability for clients to access the WAN was because CenturyLink was moving the IP the assigned to me at the same time I was trying to browse the web from a client. With others asking "when is the internet going to be up again?" instead of taking time to make sure things were right I just assumed there was some setting I was missing.

                                As to your bug report, I would like to help prove an issue as my pfSense system is yielding about 1/3 to 1/2 the performance I get when using the technicolor modem. I will message you directly about that.

                                Thank you again for the detail you provided. I appreciate it.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  dburkland
                                  last edited by

                                  I am guessing the PPPoE requirement is region specific as I did not need to set this up here in the Twin Cities (Support also confirmed this as well).

                                  Cheers,

                                  Dan

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    dopey
                                    last edited by

                                    @superweasel:

                                    Last one, in researching the speed issue with pfSense and gigabit PPPoE connections, I opened a support ticket with pfSense. As of v2.2.3, pfSense will not attain gigabit speeds with PPPoE (https://redmine.pfsense.org/issues/4821).

                                    Thanks for tracking this down.  I've been wondering why I can't get gigabit over centurylink but was able to between hosts on the WAN and LAN interfaces.  Didn't think that PPPoE would have been the factor here.

                                    1 Reply Last reply Reply Quote 0
                                    • H
                                      Heavyb
                                      last edited by

                                      Can anyone confirm that the PPPoE performance issue has been addressed in v.2.3?

                                      Thanks!

                                      1 Reply Last reply Reply Quote 0
                                      • B
                                        Bagoette
                                        last edited by

                                        I have just upgraded to CenturyLink Fiber Gigabit as well, and after getting pfSense to connect to the PPPoE, I can only manage at most 300 Mbps Down and 350 Mbps Up.

                                        My CPU info is included in attachment.

                                        I have both Gigabit NIC's on the LAN and WAN.

                                        When I hook up the CenturyLink C2100T I can get 700+Mbps Up and Down. Can anyone pull high speeds with pfSense?

                                        ![Pfsense Version.PNG](/public/imported_attachments/1/Pfsense Version.PNG)
                                        ![Pfsense Version.PNG_thumb](/public/imported_attachments/1/Pfsense Version.PNG_thumb)

                                        1 Reply Last reply Reply Quote 0
                                        • S
                                          Spirundik
                                          last edited by

                                          I had the opposite problem.  I got ~900 up/down when my pfSense was connected directly to the ONT and establishing the PPPoE connection, but only get ~700 up/down when the C2100T is in place to provide routing for my /29 subnet.

                                          attached is my cpu info.

                                          pfsense.PNG
                                          pfsense.PNG_thumb

                                          1 Reply Last reply Reply Quote 0
                                          • T
                                            teeler123
                                            last edited by

                                            I have tried everything suggested in this thread - VLAN201 on WAN, PPPoE on VLAN201, and input username and password. It then says that it is "up" but no IP address is received and not internet.

                                            Any thoughts for further actions?

                                            Thanks,

                                            Tyler

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.