- Home
- Category
- Information Communication Network
- It Networks
- Routers Network Gateways
- Residential Small Office Gateways
Showing 0 products
Frequently Asked Questions
What is double NAT and why does it matter?
Two devices in series both translating addresses - which breaks inbound connections and confuses applications that need to know their own address.
It happens whenever a customer router is added behind a provider-supplied gateway that is already routing. The inner network is translated twice before reaching the internet.
Outbound browsing still works, which is why it goes unnoticed. What breaks is anything needing an inbound path: remote access to a camera or server, port forwarding, some voice and video services, and gaming consoles reporting a restrictive connection type.
Diagnosis is confused by there being two devices, two address ranges and two sets of rules, and by port forwarding on one device being defeated by the other.
The fix is to have only one device route. Put the provider's box into bridge or modem mode so it passes the public address through to your router. Where the provider does not permit that, the alternative is to place your router in the provider's DMZ - less clean, but it restores inbound connectivity.
Should the provider's supplied gateway be replaced?
Often yes for anything beyond basic use, but check first whether it can be bridged and what the provider requires.
Supplied gateways are built to a price and sometimes to the provider's management requirements. Wireless performance is typically modest, configuration options are limited, and some are locked so that even basic settings cannot be changed.
Replacing with your own router gives better wireless, real firewall control, VPN capability and configuration you own. The requirement is that the provider's device can be bridged so it stops routing, or that the service can be terminated directly on your equipment - which needs the connection details and, on some services, specific protocol support.
Two cautions. Voice service bundled with the line often depends on the supplied device, and bridging it can disconnect the telephone. And support may be declined if the provider's equipment is not in use.
Establish both points before ordering a replacement.
How much does the integrated wireless matter?
It is usually the limiting component, and in anything larger than a small dwelling it should be treated as temporary.
A gateway's wireless is a single radio unit in a fixed position - usually wherever the provider's cable enters, which is frequently a hallway or a cupboard, and rarely where the users are. No amount of specification compensates for the wrong position.
For a small flat or a single office room it is fine. Across a house, an office suite or anything with solid walls, coverage falls off and the symptom is blamed on the internet connection rather than the radio.
The better arrangement is to disable the gateway's wireless and install access points where the users are, cabled back to the gateway. Even one well-placed access point usually outperforms a more expensive gateway left in a cupboard.
Where cabling is impossible, a mesh system is the compromise - simpler than cabling, but each wireless hop reduces available throughput substantially.
What security does a small-office gateway provide?
Stateful firewalling outbound, which is genuinely useful, plus whatever else the manufacturer includes - which varies enormously.
The baseline is that address translation and a stateful firewall block unsolicited inbound traffic by default. That alone prevents a great deal.
Above that, better gateways add guest network isolation so visitors cannot reach internal devices, some content or category filtering, and occasionally simple intrusion detection. Quality varies and the filtering is rarely comparable to a dedicated appliance.
The more significant issues are the device itself. Default credentials that were never changed, remote management left enabled on the internet-facing side, universal plug and play opening ports automatically at the request of any internal device, and firmware that stopped receiving updates years ago.
All four are worth checking on any gateway in service. Turn off remote management, change credentials, consider disabling automatic port opening, and know when the device's support ends.
How long is a gateway supported with firmware?
Typically a few years from release, and considerably less than most people keep the device - which is an increasing problem.
Gateways are internet-facing devices running an operating system with a browser interface, and vulnerabilities are found regularly. Once the manufacturer stops issuing updates, known vulnerabilities remain open permanently.
Provider-supplied devices are often better in this respect, since the provider pushes firmware centrally for as long as the device is in their estate. Retail devices depend on the manufacturer, and support periods are frequently unpublished.
Before buying, look for a stated support commitment - some manufacturers now publish an end-of-support date, and a few offer several years explicitly. That is a legitimate reason to prefer one product over a cheaper one.
For a small business, treat the gateway as having a defined life of a few years rather than running it until it fails. A router that stopped receiving updates is not working correctly merely because traffic still passes through it.
Can a small office use a gateway plus separate access points?
Yes, and it is usually the best-value arrangement for anything above a couple of rooms.
The gateway keeps doing what it does well - terminating the circuit, routing, translating addresses and firewalling - while its own wireless is disabled. Access points are installed where the people are, cabled back to the gateway's switch ports or to a small switch behind it.
The result is proper coverage, the ability to add capacity by adding access points, and separation of the two problems so that a wireless issue does not require touching the internet connection.
PoE simplifies it further, either from a PoE switch or from injectors for one or two units.
If the access points support multiple networks, a guest network can be carried separately and isolated from the office devices - which a gateway's own guest wireless does less thoroughly.
The main constraint is cabling. Where a cable can be run to a ceiling position in each area, this arrangement outperforms almost anything else at the price.
What port speeds should a small-office gateway have?
Fast enough for the circuit today and for the one after it - and increasingly that means more than a gigabit on the WAN side.
For years a gigabit WAN port was ample because no service exceeded it. That is no longer true, and a gateway with a gigabit WAN port caps a faster service at a gigabit regardless of what is delivered.
On the local side, gigabit remains adequate for most small offices, but multi-gigabit ports are worth having where files move between machines, where a NAS is in use, or where wireless access points capable of exceeding a gigabit are connected - a modern access point on a gigabit uplink is limited by the cable rather than the radio.
Also count the ports. Four is typical and four is quickly consumed by a printer, a NAS, an access point and a desk. A small switch behind the gateway is inexpensive; specifying a gateway on port count alone rarely is.