<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Fortigate and FFTP in Broadband</title>
    <link>https://business.forums.bt.com/t5/Broadband/Fortigate-and-FFTP/m-p/89472#M16702</link>
    <description>&lt;P&gt;Not a question but more a tale of moving from ADSL/Copper to FFTP and VOIP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's early day's but so far it's all good.&lt;/P&gt;&lt;P&gt;I have removed all of the copper cable (lots), &amp;nbsp;the phone exchange (panasonic), and the old phones, so there is a lot less clutter - but I need do some touch up painting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we started from here: multiple land lines, &amp;nbsp;ADSL broadband, &amp;nbsp;a Business Hub in Bridge Mode, and a Fortigate wan interface connected using PPPOE. &amp;nbsp;A very reliable setup delivering close to 70Mbit/sec.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have ended up with 150MBit FFTP and Cloud Voice, running through the same Fortigate firewall with no Business smart hub. &amp;nbsp;It delivers around 140Mbit/sec down and 30 Mbit/sec up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The OpenNTU is small but needs a power socket close by.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="opreach_ntu.jpg" style="width: 400px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1752i77799B98F33F9BC3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="opreach_ntu.jpg" alt="opreach_ntu.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As we had so many holes drilled for the old copper, I asked for a fibre to run through an existing hole in a window frame to the outside box that terminated the fibre run from a telegraph pole. &amp;nbsp;The three cables are power, ethernet (to fortigate), and fibre to the outside box.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The BT Business Smart Hub requires power, and the supplied cable (Eth) is short so you need two power points for the NTU and Hub.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To keep things simple we installed using the BT Business Smart Hub, and this was very easy except for the Cloud Voice Express. &amp;nbsp;As a Business installation OpenReach engineers do not to have phone installation listed on their work instruction - but they do for Digital Voice &amp;nbsp;in home installations. &amp;nbsp; And our phone would not work, it had no line, and would not provision. &amp;nbsp;Eventually BT advised a factory reset of the Base Unit and that triggered the provisioning, but we were without a business phone for three days over a weekend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the Yellink phone was working, I removed the BT Business Smart Hub and ran a 30m flat ethernet cable (in trunking) from the NTU to my Fortigate. &amp;nbsp;I kept the existing rule base for my internal network, just changing the WAN interface, and adding a new interface for the Yeylink Base unit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing the PPPOE from ADSL with multiple static IP's to FFTP PPPOE took a few tries, and I learned to save the configuration before trying to connect. &amp;nbsp;All my static routes and VIP's (Static IP range) &amp;nbsp;were going (moved to cloud) and I was going to have a dynamic IP. &amp;nbsp; &amp;nbsp;And the WAN1 interface looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Addressing Mode: PPPOE&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obtained IP/Mask: &amp;nbsp; Leave the Renew button alone until you have saved the changes&lt;/P&gt;&lt;P&gt;Username: &amp;nbsp;&lt;A href="mailto:btbusinesshub@business.btckick" target="_blank"&gt;btbusinesshub@business.btckick.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Password: &amp;nbsp; &amp;lt;Blank&amp;gt;&lt;/P&gt;&lt;P&gt;UnnumberedIP: 0.0.0.0&lt;/P&gt;&lt;P&gt;Initial Disc Timeout: 1&lt;/P&gt;&lt;P&gt;Initial PADT Timeout: 1&lt;/P&gt;&lt;P&gt;Retrieve def gateway: enable&lt;/P&gt;&lt;P&gt;Distance: 10&lt;/P&gt;&lt;P&gt;Override Internal DNS: enable&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fortigate.jpg" style="width: 800px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1755i7EB14ADDBF10B954/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fortigate.jpg" alt="Fortigate.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have no static routes enabled, they are set up on connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Yealink Hub is shown below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yealink_base.jpg" style="width: 400px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1753i1062AE41D63AE884/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yealink_base.jpg" alt="yealink_base.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the Handset has a separate charging dock.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yealink-handset.jpg" style="width: 400px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1754iEA5F276477341A3F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yealink-handset.jpg" alt="yealink-handset.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Yealink base &amp;nbsp;is connected via ethernet cable to a separate interface on my firewall. &amp;nbsp;The rule base follows the BT guide "BT Cloud Voice - Firewalls and LAN". &amp;nbsp;On Page 4 there is a table of SIP and RTP rules to be implemented, on Page 5 &amp;nbsp;(DNS and NTP) and on Page 7 there some rules for the Yealink Base station. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also followed the Fortinet note on "Disabling SIP ALG on a Fortigate&amp;nbsp;firewall".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the Yealink Base tries to dial home to an address that is not listed, but you will find that in the logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And finally here is the BT Business Hub disconnected and in its box.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BusinessHub.jpg" style="width: 800px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1756i5C152935317455D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="BusinessHub.jpg" alt="BusinessHub.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly I enabled Fortigate DDNS to keep track of the IP address changes with minimal effort.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jul 2023 11:06:01 GMT</pubDate>
    <dc:creator>kmca</dc:creator>
    <dc:date>2023-07-24T11:06:01Z</dc:date>
    <item>
      <title>Fortigate and FFTP</title>
      <link>https://business.forums.bt.com/t5/Broadband/Fortigate-and-FFTP/m-p/89472#M16702</link>
      <description>&lt;P&gt;Not a question but more a tale of moving from ADSL/Copper to FFTP and VOIP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's early day's but so far it's all good.&lt;/P&gt;&lt;P&gt;I have removed all of the copper cable (lots), &amp;nbsp;the phone exchange (panasonic), and the old phones, so there is a lot less clutter - but I need do some touch up painting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we started from here: multiple land lines, &amp;nbsp;ADSL broadband, &amp;nbsp;a Business Hub in Bridge Mode, and a Fortigate wan interface connected using PPPOE. &amp;nbsp;A very reliable setup delivering close to 70Mbit/sec.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have ended up with 150MBit FFTP and Cloud Voice, running through the same Fortigate firewall with no Business smart hub. &amp;nbsp;It delivers around 140Mbit/sec down and 30 Mbit/sec up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The OpenNTU is small but needs a power socket close by.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="opreach_ntu.jpg" style="width: 400px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1752i77799B98F33F9BC3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="opreach_ntu.jpg" alt="opreach_ntu.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As we had so many holes drilled for the old copper, I asked for a fibre to run through an existing hole in a window frame to the outside box that terminated the fibre run from a telegraph pole. &amp;nbsp;The three cables are power, ethernet (to fortigate), and fibre to the outside box.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The BT Business Smart Hub requires power, and the supplied cable (Eth) is short so you need two power points for the NTU and Hub.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To keep things simple we installed using the BT Business Smart Hub, and this was very easy except for the Cloud Voice Express. &amp;nbsp;As a Business installation OpenReach engineers do not to have phone installation listed on their work instruction - but they do for Digital Voice &amp;nbsp;in home installations. &amp;nbsp; And our phone would not work, it had no line, and would not provision. &amp;nbsp;Eventually BT advised a factory reset of the Base Unit and that triggered the provisioning, but we were without a business phone for three days over a weekend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the Yellink phone was working, I removed the BT Business Smart Hub and ran a 30m flat ethernet cable (in trunking) from the NTU to my Fortigate. &amp;nbsp;I kept the existing rule base for my internal network, just changing the WAN interface, and adding a new interface for the Yeylink Base unit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing the PPPOE from ADSL with multiple static IP's to FFTP PPPOE took a few tries, and I learned to save the configuration before trying to connect. &amp;nbsp;All my static routes and VIP's (Static IP range) &amp;nbsp;were going (moved to cloud) and I was going to have a dynamic IP. &amp;nbsp; &amp;nbsp;And the WAN1 interface looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Addressing Mode: PPPOE&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obtained IP/Mask: &amp;nbsp; Leave the Renew button alone until you have saved the changes&lt;/P&gt;&lt;P&gt;Username: &amp;nbsp;&lt;A href="mailto:btbusinesshub@business.btckick" target="_blank"&gt;btbusinesshub@business.btckick.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Password: &amp;nbsp; &amp;lt;Blank&amp;gt;&lt;/P&gt;&lt;P&gt;UnnumberedIP: 0.0.0.0&lt;/P&gt;&lt;P&gt;Initial Disc Timeout: 1&lt;/P&gt;&lt;P&gt;Initial PADT Timeout: 1&lt;/P&gt;&lt;P&gt;Retrieve def gateway: enable&lt;/P&gt;&lt;P&gt;Distance: 10&lt;/P&gt;&lt;P&gt;Override Internal DNS: enable&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fortigate.jpg" style="width: 800px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1755i7EB14ADDBF10B954/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fortigate.jpg" alt="Fortigate.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have no static routes enabled, they are set up on connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Yealink Hub is shown below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yealink_base.jpg" style="width: 400px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1753i1062AE41D63AE884/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yealink_base.jpg" alt="yealink_base.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the Handset has a separate charging dock.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yealink-handset.jpg" style="width: 400px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1754iEA5F276477341A3F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yealink-handset.jpg" alt="yealink-handset.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Yealink base &amp;nbsp;is connected via ethernet cable to a separate interface on my firewall. &amp;nbsp;The rule base follows the BT guide "BT Cloud Voice - Firewalls and LAN". &amp;nbsp;On Page 4 there is a table of SIP and RTP rules to be implemented, on Page 5 &amp;nbsp;(DNS and NTP) and on Page 7 there some rules for the Yealink Base station. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also followed the Fortinet note on "Disabling SIP ALG on a Fortigate&amp;nbsp;firewall".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the Yealink Base tries to dial home to an address that is not listed, but you will find that in the logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And finally here is the BT Business Hub disconnected and in its box.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BusinessHub.jpg" style="width: 800px;"&gt;&lt;img src="https://business.forums.bt.com/t5/image/serverpage/image-id/1756i5C152935317455D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="BusinessHub.jpg" alt="BusinessHub.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly I enabled Fortigate DDNS to keep track of the IP address changes with minimal effort.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 11:06:01 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Broadband/Fortigate-and-FFTP/m-p/89472#M16702</guid>
      <dc:creator>kmca</dc:creator>
      <dc:date>2023-07-24T11:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate and FFTP</title>
      <link>https://business.forums.bt.com/t5/Broadband/Fortigate-and-FFTP/m-p/89643#M16772</link>
      <description>&lt;P&gt;Transitioning from ADSL to FTTP and VOIP involved removing copper cables, an old phone exchange, and switching to a Yealink Cloud Voice setup. The FTTP installation provided increased speeds, but initial Cloud Voice provisioning issues led to a factory reset.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 05:07:40 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Broadband/Fortigate-and-FFTP/m-p/89643#M16772</guid>
      <dc:creator>Rileystanley</dc:creator>
      <dc:date>2023-08-24T05:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Fortigate and FFTP</title>
      <link>https://business.forums.bt.com/t5/Broadband/Fortigate-and-FFTP/m-p/90202#M16913</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hey kmca, thanks for sharing your transition to FTTP and VOIP. Removing the old setup and adapting the Fortigate firewall seems quite a journey. Kudos on the smooth migration! &lt;A href="https://mycenturahealth.site/" target="_self"&gt;mycenturahealth&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 09 Nov 2023 17:30:25 GMT</pubDate>
      <guid>https://business.forums.bt.com/t5/Broadband/Fortigate-and-FFTP/m-p/90202#M16913</guid>
      <dc:creator>alle78</dc:creator>
      <dc:date>2023-11-09T17:30:25Z</dc:date>
    </item>
  </channel>
</rss>

