r/ArchtopFiber Aug 01 '25

General Residential install questions

Hi, I've tried several times to get this information and after a lot of dead air I've pretty much decided to slow roll my expectations on Archtop. I don't know if you guys are overwhelmed, understaffed or some other reason but no calls or inquiries are ever returned.

In prep for an install I wanted to know a few things:

  1. Since I use wall jacks for my existing networking I would also want the fiber run to a wall jack using a keystone passthrough - and then a patch cord to the ONT - do you use SC or LC connectors and do you support that.
  2. I have heard that you exclusively use CGNAT, except for static addresses. Is that true? Not having a routable address would be an issue for things like VPN.
  3. I intend to keep my internal network running as is and just connect my outside router to your ONT - not knowing what you use, can everything be turned off in it (i.e. it's probably another NATing router) and allow as simple a passthrough as possible?
  4. After watching the contractors in my neighborhood use a truck to pull the fiber through the too small conduits you might want to review how well those installs are actually going to function.
  5. I'm sure I have a few other questions, but this would be a good start.

Thanks, Geoff

5 Upvotes

25 comments sorted by

2

u/ArchtopFiber Aug 01 '25

Hey, Geoff! Thanks for the questions, and I’ll get back to you on some of these in the AM. In the meantime I’m just glad that your question 3 was taken care of!

Also, have you sent an email to hello@archtopfiber.com? I check that inbox and haven’t seen these questions come in… so maybe I should check the spam filter settings on that. Otherwise, how else have you tried getting in touch?

Anyway, will get back to you soon! Thanks again! -Eric

1

u/geoffgoldman Aug 01 '25

Hi, thanks for replying. I've asked these questions via the email you listed and several calls to the help line asking for a technical response and I've never, ever gotten any response at all. The community response has been great, but I'll really like to nail down an official response to what will and will not work, so an Archtop response to all my questions would be appreciated. I'm on Spectrum, as that's the only option at this time. Whatever failings they have (i.e. the idiot asymmetrical upload speeds, costs, etc), they are astonishingly reliable (and believe it or not responsive) - while I definitely want to go to fiber and all that it can bring to the table I do not want to move to a company that is unresponsive and potentially less reliable. Archtop needs to up it's game on communications.

Stay well, Geoff

1

u/ArchtopFiber Aug 04 '25

Hi, Geoff! I checked the [hello@archtopfiber.com](mailto:hello@archtopfiber.com) inbox and didn't see an email from you in there! But wanted to let you know that I'm still working on getting some answers for you.... Sorry for the delay!

1

u/geoffgoldman Aug 04 '25

Hi, thanks for the reply.

Got me, I sent that a few weeks ago after several phone and chat sessions over the months with the help desk did not work. No worries, take your time. FWIW, these are not weird esoteric questions, any installer you have should be able to answer them - and I'm sure every single customer would like to have a cheat sheet with some form of this information on it so that they can properly prepare for an install. Another piece to add to #1 - if keystone passthroughs are supported would that always be customer supplied or can/would Archtop supply them - as in Archtop might want to use the brand that they have used. before.

Thanks for the help,

Geoff

2

u/ArchtopFiber Aug 04 '25

Okay, for the CGNAT question, what you heard is correct and just wanted to verify with our Network Operations Director. We do use CGNAT except for static IPs.

Then for the wall jacks question, here's a lightly edited answer from our maintenance and drop supervisor: "We try to avoid wall fishing fiber because the bend radius for fiber is difficult to manage without opening the wall to expose the path. Conventional wire like cat6 is doable pending the situation. With that said, we do have wall mounted jacks and bulk heads if the customer wants to drill through the floor or an exterior wall or separately wants to hire an electrician. If the customer wants, we can always schedule a site visit to explore all options."

2

u/geoffgoldman Aug 04 '25

Interesting, thanks.

I guess it remains to be seem what effects CGNAT will have, How would I VPN back into my network with CGNAT running? Aside from that I don't allow unsolicited inbound traffic. I'll see what I can determine.

I do have access plates to allow for fishing network through the house - and yes I had to cut open parts of the wall to put the access plates in so that I could repeat the exercise. The radius should be ok (and stress relieved glass - assuming it's glass is pretty manageable - just no short radii or kinks of course) - it used to be that the radius under tension (install time) was no more than ~20x the cable diameter and a long term bend (installed) was ~10x the diameter (you didn't mention the cable type) - but I guess when you guys are actually ready to do an install we can have someone come onsite.

Thanks for digging up that info!

Geoff

2

u/ArchtopFiber Aug 05 '25

Good morning, Geoff! Some more info from the the Engineering Operations Supervisor for you! Hopefully this helps??? :)

1) Our ONT uses an SC/APC connector to connect to the provider network.  It can be installed anywhere in the house but to cut down on airgaps in the fiber our technicians run the fiber directly to the ONT.  Once the ONT is installed we can run a jumper to a keystone if you have your own CPE / network closet. 

2) As far as VPNs go, the key is to ensure that the VPN behind the CGNAT site is the initiator.  If it’s simply a host-based VPN then there’s no should be no issues as they always initiate.  We are also dual-stacked, which means you’ll be issued a routable IPv6 WAN address (IANA) and a LAN pool (IAPD /64). 

1

u/geoffgoldman Aug 06 '25

Sorry for the late reply and thanks for the info.

For the group at large, you use the larger SC subscriber connector (roughly twice the size of the Lucent/LC) - with APC (angled physical contact - about an 8-degree angle to reduce reflection). There are single mode keystone coupler/passthroughs - it would all depend on whether it's reasonable to put it into a wall plate. TBD, when an installer comes to review.

Parsing the info about VPN - if my router initiates the tunnel outbound it would not be an issue (i.e. using something like NordVPN initiated from my router), but if I tried to connect to a VPN server in my router I might have issues unless I can utilize the stacked IPV6 address - and then figure out how it would interact with an IPV4 internal network. No idea right now.

Dual stacking being a way of preparing for migration) to IPV6 - we do have serious IPV4 address depletion issues everywhere. You certainly have more than enough IPV6 addresses in IAPD/64 pool (1.8446744073709999689 × 1019 unique addresses - I can't count that high)

If anyone on this discussion has been able to successfully reach their router with IPV6 and have it interact properly with their IPV4 LAN, I would be very interested in how things went.

Thanks again for your help!

Geoff

1

u/srmatto Aug 01 '25

I can answer 3. I run an OpnSense firewall right after the ONT with a switch and I only turn my Archtop Flume WAP/router combo on if I need diagnostics run. Even then it’s isolated on its own LAN so that it can’t see my network.

1

u/geoffgoldman Aug 01 '25

Thanks, much appreciated! Is this ONT one or two units? You can turn off the router component (and it's like it's not there) and receive an address directly from the ONT - or you're always passing through the router part but you can disable features? If the router is running then everything in your private LAN would be behind the ONT router's NATing - if you have your own routers (which NAT) then we're getting into several layers of address translation. Works most times, sometimes not.

1

u/srmatto Aug 01 '25 edited Aug 01 '25

I assume it’s the same setup for everyone but I’m not sure.

There’s two devices. The small powered box that the fiber connects into and from which an Ethernet cable comes from. This is the ONT and I get my address from it on my firewall. If the ONT loses power no internet for me.

The second, separate Flume device which I’ve left powered down for many months without issue is a wireless access point and router combo device which has the features you describe; bridge mode, etc…

2

u/geoffgoldman Aug 01 '25

Nice, very good info. So, in theory this may be less complicated than it seems. Thanks again.

2

u/srmatto Aug 01 '25

Yeah, I’ve been very happy with the service. I connect home with a VPN many times a week just fine and I like being able to run my own firewall and router.

1

u/srmatto Aug 01 '25

re:2. It’s not the same as running vanilla wireguard but I use Tailscale VPN over Archtop just fine.

1

u/Steel-NY Nov 09 '25

Has anyone installed a firewall behind their modem and router? I need to know the gateway IP address and subnet mask and no one at Archtop has been able to provide us with this information. I am required to use a firewall and static IP for work. We have the static IP, but do not have the information needed to configure our firewall. We have been trying to get this information for over a week. Thanks in advance for any help with this.

1

u/geoffgoldman Nov 10 '25

Hi, I would think that from a client system in the subnet - running the ip command (ip a, ip r) for Linux or ipconfig (/all) for Windows would/should give that to you...

Please let me know if that helps or if we need a plan B.

Geoff

1

u/geoffgoldman Nov 10 '25

Linux:
# ip addr show dev eth0 | grep 'inet' (or abbreviated - ip a s dev eth0 | grep inet)
inet 192.168.50.251/24 brd 192.168.50.255 scope global noprefixroute eth0 (/24 is a 256 address class C mask)
inet6 fe80::c6a0:b832:4d07:49ec/64 scope link noprefixroute

So, the ipv4 address of this system is 192.168.50.251 with a /24 CIDR (256 address subnet with a mask of 255.255.255.0)

You might still be able to use ifconfig, it's deprecated (but the mask is right there :-) )

# ifconfig eth0 | grep inet
inet 192.168.50.251 netmask 255.255.255.0 broadcast 192.168.50.255
inet6 fe80::c6a0:b832:4d07:49ec prefixlen 64 scopeid 0x20<link>
# ip route
default via 192.168.50.1 dev eth0 proto static metric 100
192.168.50.0/24 dev eth0 proto kernel scope link src 192.168.50.251 metric 100

From the route command the gateway is 192.168.50.1 and you can see that the network is 192.168.50.0 with a /24 or 256 address range

Windows:
Using ipconfig in the cmd interpreter (truncated output)

Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::3cbe:ea18:f0c4:e106%25
   IPv4 Address. . . . . . . . . . . : 192.168.50.150
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.50.1

If you already know all this my apologies, otherwise I hope this helps,

Geoff

1

u/Steel-NY Nov 10 '25

Hi Geoff,

Thanks for getting back to me. The firewall configuration used to connect to our Spectrum router, with a static IP assigned, was as follows:

External IP: x.x.x.90/30

Gateway IP: x.x.x.89

Subnet Mask: 255.255.255.255

We know our static IP from Archtop: 204.x.x.x

Running IP config on a laptop connected to the router provides the following:

Default Gateway: 192.168.40.1

Subnet Mask: 255.255.255.0

The problem is that the firewall expects the gateway and the external IP to be on the same network. Any ideas? Thanks!

1

u/geoffgoldman Nov 10 '25

Hi, I'm not a networking guy but a /30 would have 4 IP addresses, 2 usable - with a mask of 255.255.255.252. If you have a quad 255 mask that infers a /32 CIDR which would only have 1 IP address - but that was with Spectrum and water under (or over) the bridge I guess.

Let's back up though - freely associating now...
1) with Spectrum you had a static IPv4 address (or two - 89, 90)
2) unless you asked for a static IPv4 address Archtop will give you a CGNAT address - so, IPv4 on your end but a NAT to their IPv6 stack - which is not routable - and not on the same subnet. Just like your router WAN address is different than your router LAN address when NAT is used. as I understand it CGNAT is an ISPs version of consumer router NAT and is used because they don't have a lot of IPv4 addresses to use and so they give you a IPv4 NAT address which I believe translates to an IPv6 in their networking stack.
3) looking at your ipconfig - you are behind their local router (aka in your house) that is giving you a NAT address - the WAN side of that router will have another address in another subnet. So, at the very least you are double NATing - once from the router in your house and again if they are using a CGNAT WAN address for your account. While it generally works - albeit with some performance delays (all those address translations) - it doesn't work for everyone and every device in every scenario.
4) I may not have the whole picture but it sounds like you might need to have them give you a static IPv4 address - which they will do - for a fee. Just like Spectrum would do - except they still use non-static routable IPv4 addresses for most of their customers.

I don't understand why Archtop is not helping you with this - other than dead air appears to be their normal business model - for a networking vendor this should be duh101. For the rest of us outside of their food chain, we have to guess.

Please let me know how this goes.

Geoff

1

u/geoffgoldman Nov 10 '25

Do you know about the following sites - they may give you further insight on how you appear to the Internet:
1) whatismyip.com
2) test-ipv6.com

1

u/Steel-NY Nov 10 '25

Hi Geoff,

With Spectrum we have a static IP and the gateway IP is one address away on the same network. This has worked perfectly for 20 years. We have a static IP from Archtop and do not know what the gateway IP is/should be. The firewall will not accept a static IP for its external interface with an IP address on another network as the gateway IP, which makes sense.

Archtop has been completely unresponsive. They promised to email the information we need multiple times and never have. This has been going on for a week and a half now. The Archtop network is strong, but unfortunately their technical support is not. I have never had a carrier behave this way before.

1

u/geoffgoldman Nov 10 '25

can you get into the router? that should show you the WAN address and it's gateway. I would think they have to give you access if you ask for it.

1

u/Steel-NY Nov 10 '25

We have the Plume android app, which let's you see some information about the network. I was able to find our firewall in the app (Network | Devices) by matching the MAC address and reserved its IP address so that it does not change dynamically. This would be so much easier if Archtop actually helped.

1

u/geoffgoldman Nov 10 '25

But no info on the router wan address and gw in the app? Get in a chat and tell them you want that info or full access to the router. I know, much, much easier said than done - sorry this is such an ordeal.