{"id":3338,"date":"2024-12-20T17:38:12","date_gmt":"2024-12-20T21:38:12","guid":{"rendered":"https:\/\/arielantigua.com\/weblog\/?p=3338"},"modified":"2026-01-28T09:02:09","modified_gmt":"2026-01-28T13:02:09","slug":"peplink-as-home-gateway-firewall","status":"publish","type":"post","link":"https:\/\/arielantigua.com\/weblog\/2024\/12\/peplink-as-home-gateway-firewall\/","title":{"rendered":"Peplink as home gateway\/firewall!"},"content":{"rendered":"<p>Peplink as home gateway\/firewall!<\/p>\n<p>I\u2019m a big fan of routers and firewalls, love the idea of running pfSense back in the days, before m0n0wall\/pfSense, I used to run a custom FreeBSD firewall!!<\/p>\n<p>Do you remember m0n0wall ??<br \/>\nYes, the father of pfSense and some may say that m0n0wall is the father of opnSense!<\/p>\n<p>Since a year ago, I decided in a branded router\/firewall for the home, just because one feature. Yes, only one feature made me buy this <strong>Peplink Balance 20X<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<p><!--more--><\/p>\n<p><strong>SpeedFusion<\/strong><\/p>\n<p><em>Peplink\u2019s patented SpeedFusion technology powers enterprise VPNs that tap into the bandwidth of multiple low-cost cable, DSL, 3G\/4G\/LTE, and other links connected anywhere on your corporate or institutional WAN. Whether you\u2019re transferring a few documents or driving real-time POS data, video feeds, and VoIP conversations, SpeedFusion pumps all your data down a single bonded data-pipe that\u2019s budget-friendly, ultra-fast, and easily configurable to suit any networking environment.<\/em><\/p>\n<p>This is the description that comes from the official website of Peplink [ <a href=\"https:\/\/www.peplink.com\/technology\/speedfusion-bonding-technology\/\">https:\/\/www.peplink.com\/technology\/speedfusion-bonding-technology\/<\/a> ]<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1380\" height=\"525\" class=\"wp-image-3339\" src=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically.png\" alt=\"A diagram of a network Description automatically generated\" srcset=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically.png 1380w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically-300x114.png 300w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically-1024x390.png 1024w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically-768x292.png 768w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically-1200x457.png 1200w\" sizes=\"auto, (max-width: 1380px) 100vw, 1380px\" \/><\/p>\n<p>There are free alternatives to SpeedFusion, but none of them works so seamlessly that sometimes I just forget about the SpeedFusion thing.<\/p>\n<p>In my case, I have two Internet connections, one with <strong>CLARO (300\/75)<\/strong> and a second one with <strong>OrbitCable (10\/5<\/strong>). Why the second Internet connections? Well, is cheap and in case CLARO has issues, I can be online and read emails or even do a Teams Call.<br \/>\nA year ago I was running OpnSense with Dual Wan and was Ok, got my hand on an old <strong>Balance 20<\/strong> (a previous model of the 20X and slower), play a little bit with SpeedFusion, at that moment I was convinced that this solutions is better for multiple internet connection with the bonding options, the failover is transparent because the IP of the VM hosting the other side of the SpeedFusion tunnel is the one being used for stablishing connections.<\/p>\n<p>It looks like this (almost&#8230;):<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"716\" height=\"520\" class=\"wp-image-3340\" src=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically-1.png\" alt=\"A diagram of a network Description automatically generated\" srcset=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically-1.png 716w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-diagram-of-a-network-description-automatically-1-300x218.png 300w\" sizes=\"auto, (max-width: 716px) 100vw, 716px\" \/><\/p>\n<p>My drawing skills are dead.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"853\" height=\"343\" class=\"wp-image-3341\" src=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-screen-description-aut.png\" alt=\"A screenshot of a computer screen Description automatically generated\" srcset=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-screen-description-aut.png 853w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-screen-description-aut-300x121.png 300w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-screen-description-aut-768x309.png 768w\" sizes=\"auto, (max-width: 853px) 100vw, 853px\" \/><\/p>\n<p>Traceroute from a machine with policy rules the sent traffic via SpeedFusion tunnel. A few machines are using this policy and going out to the internet using the bonded tunnel.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"926\" height=\"321\" class=\"wp-image-3342\" src=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-program-description-au.png\" alt=\"A screenshot of a computer program Description automatically generated\" srcset=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-program-description-au.png 926w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-program-description-au-300x104.png 300w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-screenshot-of-a-computer-program-description-au-768x266.png 768w\" sizes=\"auto, (max-width: 926px) 100vw, 926px\" \/><\/p>\n<p>Traceroute from a machine without route policy rule, going out via CLARO. This is the normal behavior for the entire network, if CLARO goes down, the traffic moves over to Orbit.<\/p>\n<p><strong> What are the advantages of this?<\/strong><\/p>\n<ul>\n<li>Using the SpeedFusion tunnel, the remote connections doesn\u2019t see my real WAN IP, so in case one of the WAN goes down, the connection doesn\u2019t reset.<\/li>\n<li>The classic Dual Wan\/Load Balance is available, using policies you can manage how the WANs are being used inside the tunnel.<\/li>\n<li>You can publish internal services using the SpeedFusion VM WAN IP Address and only need to open ports on that VM hosted in the remote Data Center.<\/li>\n<\/ul>\n<p><strong>Any disadvantages?<\/strong><\/p>\n<ul>\n<li>Yes, some sites detect my connections as bot\/crawlers, and I need to complete captchas to get into some sites (Cloudflare, eBay and others).<\/li>\n<li>Slow, the bandwidth available inside the VPN is 100Mbps, this is a hardware limitation of the <strong>Balance 20X<\/strong>.<\/li>\n<li>Price, for this model, I need to pay for the 2<sup>nd<\/sup> WAN, it only has one Ethernet WAN and need to create a <strong>Virtual WAN<\/strong> which cost $49\/y, the <strong>Balance 20<\/strong> have two Ethernet WANs, I wasn\u2019t aware of this until I got my hands on the 20X.<\/li>\n<\/ul>\n<p><strong>Special Use Case?<\/strong><\/p>\n<p>I\u2019ve been running an ASN enable network for almost 6 years. big part of this network is connecting different Linux VMs with BGP via GRE\/Wireguard tunnels to able to route to internet using a <em>\/24 of Public Routable IPv4 and a \/40 of IPv6 Addresses<\/em>.<\/p>\n<p>There is a <strong><em>Mikrotik RB3011<\/em><\/strong> connected directly to the Peplink, using this connection a GRE Tunnel is formed with another <strong><em>Mikrotik (CHR)<\/em><\/strong> running in the same virtual network as the SpeedFusion VM, the CHR is receiving a default route from a Debian VM with BGP Sessions to <strong><em>BuyVM<\/em><\/strong> routers, a lot of configurations in place. Before of this setting, there were two Wireguard Tunnels to different places to form the BGP Sessions, now I only need one, which is running on top of the two WANs.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1014\" height=\"258\" class=\"wp-image-3343\" src=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-black-screen-with-white-text-description-automa.png\" alt=\"A black screen with white text Description automatically generated\" srcset=\"https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-black-screen-with-white-text-description-automa.png 1014w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-black-screen-with-white-text-description-automa-300x76.png 300w, https:\/\/arielantigua.com\/weblog\/wp-content\/uploads\/2024\/12\/a-black-screen-with-white-text-description-automa-768x195.png 768w\" sizes=\"auto, (max-width: 1014px) 100vw, 1014px\" \/><\/p>\n<p>Is cleaner, I think&#8230; this a topic for an upcoming post!<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Peplink as home gateway\/firewall! I\u2019m a big fan of routers and firewalls, love the idea of running pfSense back in the days, before m0n0wall\/pfSense, I used to run a custom FreeBSD firewall!! Do you remember m0n0wall ?? Yes, the father of pfSense and some may say that m0n0wall is the father of opnSense! Since a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[123,7,34],"tags":[160,161],"class_list":["post-3338","post","type-post","status-publish","format-standard","hentry","category-bgp","category-general","category-networking","tag-peplink","tag-speedfusion"],"_links":{"self":[{"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/posts\/3338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/comments?post=3338"}],"version-history":[{"count":2,"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/posts\/3338\/revisions"}],"predecessor-version":[{"id":3402,"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/posts\/3338\/revisions\/3402"}],"wp:attachment":[{"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/media?parent=3338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/categories?post=3338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/arielantigua.com\/weblog\/wp-json\/wp\/v2\/tags?post=3338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}