F5F Stay Refreshed Power Users Networks Avoid deep packet inspection by using alternative methods to analyze network traffic.

Avoid deep packet inspection by using alternative methods to analyze network traffic.

Avoid deep packet inspection by using alternative methods to analyze network traffic.

L
LightCloud
Member
145
09-18-2016, 11:04 AM
#1
I’m facing a problem with my network that restricts me to only seven MAC addresses, each tied to a fixed IP. I attempted to expand the network using a budget Tplink router or Wi-Fi AP, but once the system identifies it as a router, it blocks internet access until it recognizes the change. Switching MAC addresses or hostnames didn’t help, suggesting packets are being checked for NAT. I bought a PC Engine APU2C2 to run pfSense and enable a VPN to hide traffic, aiming to reduce bandwidth usage (30-40Mbps on up to 100Mbps connections) and improve ping performance. Currently, I rely on PIA as my VPN provider.
L
LightCloud
09-18-2016, 11:04 AM #1

I’m facing a problem with my network that restricts me to only seven MAC addresses, each tied to a fixed IP. I attempted to expand the network using a budget Tplink router or Wi-Fi AP, but once the system identifies it as a router, it blocks internet access until it recognizes the change. Switching MAC addresses or hostnames didn’t help, suggesting packets are being checked for NAT. I bought a PC Engine APU2C2 to run pfSense and enable a VPN to hide traffic, aiming to reduce bandwidth usage (30-40Mbps on up to 100Mbps connections) and improve ping performance. Currently, I rely on PIA as my VPN provider.

G
GC_Lewk
Member
219
09-20-2016, 07:43 AM
#2
You're likely aiming for a more powerful pfSense device. VPNs tend to consume significant CPU resources, while this model appears to offer better performance. Consider options featuring AES-NI support for enhanced speed.
G
GC_Lewk
09-20-2016, 07:43 AM #2

You're likely aiming for a more powerful pfSense device. VPNs tend to consume significant CPU resources, while this model appears to offer better performance. Consider options featuring AES-NI support for enhanced speed.

J
JdGamingShow
Member
180
09-20-2016, 01:13 PM
#3
You can try adjusting certain settings to improve performance. It's possible the PIA Servers are limiting speed. Since you invested £170 in the PFSense box, you'd prefer it to last longer rather than replace it soon. After moving in July, you won't need the MAC Address restriction anymore, so the VPN tunnel won't be necessary. Edited February 24, 2018 by MaroonLance Added second paragraph
J
JdGamingShow
09-20-2016, 01:13 PM #3

You can try adjusting certain settings to improve performance. It's possible the PIA Servers are limiting speed. Since you invested £170 in the PFSense box, you'd prefer it to last longer rather than replace it soon. After moving in July, you won't need the MAC Address restriction anymore, so the VPN tunnel won't be necessary. Edited February 24, 2018 by MaroonLance Added second paragraph

H
HiImAnnabel
Member
238
09-22-2016, 01:58 AM
#4
You could simply ask the network administrator or your ISP to approve your router. Check if they are willing to do that first.
H
HiImAnnabel
09-22-2016, 01:58 AM #4

You could simply ask the network administrator or your ISP to approve your router. Check if they are willing to do that first.

P
PersieO
Posting Freak
786
09-22-2016, 07:11 AM
#5
Your ISP doesn't permit firewalls or routers? That seems odd. If the virtual machines are behind the host, it's challenging to detect them as separate hosts. Yes, it's simpler to request permission than facing restrictions for being clever. Still, I don't understand how DPI relates, since packet inspection just identifies the data stream, not the host itself.
P
PersieO
09-22-2016, 07:11 AM #5

Your ISP doesn't permit firewalls or routers? That seems odd. If the virtual machines are behind the host, it's challenging to detect them as separate hosts. Yes, it's simpler to request permission than facing restrictions for being clever. Still, I don't understand how DPI relates, since packet inspection just identifies the data stream, not the host itself.