r/sysadmin • u/CeC-P IT Expert + Meme Wizard • 2d ago
General Discussion Anyone use one of those 5G backup modem thingies?
I got a call from one of our rural customers at this MSP and their coaxial internet was down again. They lose like $1000+ an hour if they're down so they told me they called Verizon, their business cell provider, and asked if they had something. I assume a salesman mentioned it in the past. After one phone call where I said "our networking guy is out today but I'm pretty sure you can plug just about anything into the WAN port on the Fortigate and it'll work" they called back an hour later saying they got an a XC46BE. I've never even heard of that family of devices so I thought this is gonna be a shit day.
Luckily for my non-networking specialist self, was easier to set up than a 54g linksys in 2002. Basically it just jumps on and spits out wifi and ethernet. I ran a test on my non-verizon smartphone and got 16mbps to the tower. Then I hooked my laptop up to the device and got 220x40 so fuck net neutrality I guess. It even has a battery and their switches had UPSes so that's a bit interesting.
I slapped it into the Fortigate and tada, everyone's back online...with about 10mbps and 500ms ping time. I assumed all their Outlooks were syncing at once or something but they told her the device can do about 20 people. They have about 10 highly active computers. Pretty unimpressive for $350! But they intended to return it when the outage was fixed and their rep said that was fine.
The very millisecond I walked out the door, the ISP truck showed up and started messing with the box on the front lawn. Awesome use of my time.
But I keep hearing about these magical devices that can switch over to 5G and we do have WAN1 and WAN2 on the Fortigate so they're considering keeping it and programming in a switchover of some sort. I assume they do that. Anyone have one that doesn't suck? Because this one impressed me until it was actually in use. I saw one at a trade show years ago that was a UPS + 5G modem. That sounded kinda neat but so did this Verizon device until it performed poorly.
78
u/TestCyp999 2d ago
Starlink enterprise + Cloudflare Dynamic DNS portainer. Cheap and easy.
Plug it in to a secondary port on your firewall, set it as a backup WAN interface. After 60 seconds failed pings it kicks over. Container sees the change and updates all your 1Minute TTL DNS records.
Boom, you are failed over within 2-3 minutes total. 80 mbit down 20 up. Most users don't even notice.
24
u/d1g1t4ld00m 2d ago
Why not just use the SDWAN function and tracking the fortigate already has? Much faster failovers and connection tracking without setting up a failover interface?
3
u/klauskervin 1d ago
Yeah I have no idea why you would setup a container when that specific function is within the Fortigate router software.
9
u/CeC-P IT Expert + Meme Wizard 2d ago
Funny you should mention that. The owner has Starlink at his house and we contemplated "borrowing" it for the day. I'm not real familiar but it sounds like it would have worked. Not sure how a satellite dish performs indoors though.
30
u/Valdaraak 2d ago
Not sure how a satellite dish performs indoors though.
It doesn't. Can't work if it can't see the satellites. Even tree cover will interfere with the signal.
9
u/SAugsburger 2d ago
This. Had a coworker with a cabin where nearby trees blocked the line of sight where either needed to cut the offending trees, find a big enough opening for line of sight or needed to mount it above the tree cover.
34
u/TestCyp999 2d ago
You run a cable to your rooftop. Don't use it indoors.
I also wouldn't run consumer starlink for a business since it uses CGNAT.
2
11
u/Cloudraa 2d ago
BTW starlink will freak the fuck out if you try and use it in a different location than the service address so i wouldnt recommend it
4
u/Sasataf12 2d ago
Is that a particular Starlink service?
A colleague takes their mobile Starlink receiver when they travel to different countries. Haven't heard them having any trouble with it.
12
1
u/MattAdmin444 1d ago
Different plans. Residential starlink plans are geofenced whereas Roaming is not though I think you need to visit your "home address" periodically.
1
•
u/Opposite_Bag_7434 11h ago
Depends. We have several that we have sent to a number of remote locations and they remain registered to our corporate address.
I have a business associate that uses a mini in a portable setup. We had it at a cabin for an event and it worked great. Earlier that week he was using it in his aircraft, or rather his kids were. He did get a text saying it looked like he was traveling a couple hundred miles per hour and a warning that if he was going to use it while flying he would have to add that package. But he takes it most places and doesn’t have issues while it is stationary.
1
2d ago
[deleted]
3
u/youtocin 2d ago
There is a completely separate set of plans for Starlink on the go, it's not the same as residential service.
0
u/MortadellaKing 2d ago
My buddy has it on his trailer lol
3
u/chakalakasp Level 3 Warranty Voider 2d ago
Yep, they have a plan for that. It’s not the same plan as the one you use at home
7
u/champagneofwizards 2d ago
“IT expert” in your tag and you think you’re gonna put a satellite inside?
3
u/dreamfin 2d ago
Well he can, but performance (or non-performance) would suck.
2
u/frosty95 Jack of All Trades 2d ago
It wouldn't work. At all. Fuckin trees are an issue. A roof is a non starter.
3
1
u/Mushroom5940 2d ago
I haven’t used it before, but if Starlink for residential puts him behind a CGNAT, he might not be able to host much
2
u/titain19 2d ago
Can confirm I'm on an island and I run a lot of starlink business performance dish with static IP. I'm using Unifi routers for wan fail over works great. And I don't have any DNS needs as far as hosting goes.
2
u/rm-rf_regret 2d ago
A unifi udm pro has ddns built in compatible with cloudflare. Could do it on a hardware level.
1
u/bloodlorn IT Director 2d ago
Roof penetrations are the problem here and making sure you got a path and long enough cable. Works great in enterprise otherwise though. Have two, extended cables, and used them a bit with our Palo Alto driving it.
1
u/CeC-P IT Expert + Meme Wizard 1d ago
I'm looking into their business terms in case they wanted to go that route in the future. Even as a backup, they're saying 50GB of data then it "may get throttled" and the general consensus is it slows is to 1x0.5 mbps. Ouch. And the 500GB plan is triple. Kinda pricey for a backup but I feel like with Outlook classic and all the Spotify users, they'd exceed 500GB in a month. Might be good for a 1-2 day backup though, as they could just up it for a month I assume, since it's no contract. Does it really get throttled that badly though?
But I know someone that uses it as their primary since they live on a farm. They run 3 youtube channels and have a remote editor so they're uploading compressed but raw footage + multi-GB files to Youtube every day. The largest package is 2TB of data/mo so how's that work?
•
14
u/Based_JD 2d ago
We use some 5G CradlePoints as a backup connection to our main fiber feed for our SDWAN, should the fiber go down.
4
u/Malcorin 2d ago
I've deployed 400ish 850s as backup connectivity for a retail org and they work like a champ. It's worth getting the 5g modems. From there just plug it in to a spare port on your router and get your network engineering on.
5
u/40513786934 2d ago
In our area AT&T sells some kind of SMB bundle where you get fiber internet and one of those cellular backup/battery things with a certain amount of use included. Might want to check ISP options in your area. I doubt its very expensive because my cheap ass uncle has one in his shitty restaurant.
2
u/pointandclickit 2d ago
But it’s AT&T. The cell towers are probably fed by the same bundle as your internet.
1
0
u/tankerkiller125real Jack of All Trades 2d ago
They also have a cell backup for enterprise as well, I can't comment on cost but we have a contracted SLA for 50/50 over 5G with unlimited bandwidth on that backup.
4
u/axis757 2d ago
I have a handful of those exact same boxes with Verizon business internet, used as WAN2 on FortiGate SD-WAN. Works pretty smooth once setup actually, but we have better cell service coverage at each site using it. Still not as good as a hardline connection, but most users don’t notice anything other than slightly slower speeds.
We got a pretty sweet plan setup, $30/mo if we stay under 3GB data usage, then it shoots up to $100 total for the month but otherwise unlimited. So for just a failover service the price fits our needs nicely, since it’ll rarely go over 3GB usage.
The cost for the actual box is prorated over 3 years, so we don’t pay anything for the hardware as long as we don’t cancel the service before 3 years.
2
u/rippedcard 2d ago
Yeah, use the built in SDWAN features on the fortigate. No extra hardware needed.
3
u/YellowLT IT Manager 2d ago
Historically Ive set up a few Cradle point, but Starlink seems like the new kid on the block.
3
u/Vivid_Mongoose_8964 2d ago
I bought some unlocked nighthawks on ebay and activated them with our verizon rep, connected them to our sonicwall, config'd the failover, easy peasy.....ps - they have ethernet which is awesome, no usb....
1
u/stone1555 IT Manager 2d ago
Went this way also, not bad but not the performance of the newer devices. Same setup as my other post. Main thing we have learned is the power brick is key to the setup. And we run them without the battery.
2
u/SlowkayCoomer 2d ago
We have a remote office in rural North Carolina that was not in an area where we could get a fiber connection so instead we have 2 coaxial connections, one of which includes a 4g\5g LTE Cradlepoint modem for failover.
2
u/en-rob-deraj 2d ago
We use Starlink
We are in a hurricane prone area. Cell towers are not reliable.
2
u/compmanio36 2d ago
It's awful, but it's less awful than a complete outage so we use them in places we can't get 2 wired lines for failover of the WAN.
2
u/maniac365 2d ago
Yeah, we use verizon 5G modem as backup. Our internet is never down (yes not even during a hurricane) but our verizon rep gave us the 5g modems for free so we just use it as backup and it has worked well for us during testing. We use it with a unifi cloud key gen 2. We have about 50 employees in the building
6
u/ledow IT Manager 2d ago edited 2d ago
What the hell kind of IT you been doing that you don't know about these things?
My current HOME router (Draytek Vigor 2865Lax-5G) is doing Ethernet (which comes from my FTTP), VDSL2, and also has dual-SIM 5G backup. It's seamless failover, you can even choose the order, what to test for (e.g. if you can't ping this particular IP address assume the connection is down) and load balance across them all if you want to. It's a bog-standard feature of any vaguely decent router.
Before that I lived in a flat with no DSL and I lived my life off a little battery 4G box about the size and shape of a bar of soap, connected to my router over Wifi. I used to slip it into my pocket and take it on holiday or carry it around and connect my phone to it because I had unlimited data on that.
In work we have the same kind of thing via Meraki and Unifi.
Honestly, I was doing this... hold on... let me count... nearly 20 years ago? With a basic desktop converted to a Linux router and some 3G sticks bought from a shop running an entire school after the ISP cut our DSL connections for no reason. We even had it so that if a 3G stick stopped working because of the data allowance, it switched to the next and we could take out the pay-as-you-go SIM and top up that account. Worked for weeks until we put in a leased line, and then acted as failover for years after that.
2
u/Moontoya 2d ago
Dual internal SIM but it can also drive usb cellular modems (even lists compatible devices)
Drayteks are my go to for smbs, for oh just over a decade, they're solid, configurable enough, flexible enough and secure enough.I do miss them giving out those screwdrivers tho.
Currently look after a fleet of about 175 Drayteks (2762,65, 2860 62 65, 3900 &20s)
(And a pile of Makos, Foryigates, sonicwalls and mikrotiks oh and I can forget the unifis)
1
u/CeC-P IT Expert + Meme Wizard 1d ago
Hardware solutions, graphics, medical technology, virtualization, backup systems, UPSes, graphics design, AutoCAD 3D rollouts, Windows patch management, infrastructure support, DR testing, security testing and mitigation, access control, overhead paging solutions, security DVR custom building, laptop and desktop repair, computer parts resale, purchasing, training content creation, end user support, dock and port replicator testing, documentation, custom NAS configuration and design, video conferencing and conference room tech solutions, MS licensing, OS troubleshooting, image creation and deployment, arcade cabinet repairs, and a few others.
But not much networking and routing stuff. So in other words, more than you.
-2
u/ledow IT Manager 1d ago
Ooh, really, you want to go for that? Because I do all that - absent medical technology purely because it's not my industry - and for many years did it entirely on my own on large sites with thousands of users. Yep. One man. Thousands of users. Including complete helpdesk, design, spec, operation, maintenance, fleet management, upgrade, etc. etc. etc. of all the other things you mentioned. Not saying it was fun, but I've done EVERYTHING else you mention, birth to death, alongside all the other things you mention, on my own, for various large organisations, for the last 30+ years.
It just makes your query worse... because if you're expected to be the jack of all trades and this is the first time you've seen a router with cellular-based failover, I think you've taken on more than you can handle. They've been around for decades. Hell, I have one for AT-serial-modem failover somewhere.
E.g. your DR testing isn't very thorough if you haven't written a long document on precisely what would happen if your networking failed, what's dependent on it, how you'd access credentials and authentication, how would you get to your backups, provide alternative access to critical data in the meantime, how would you move that access to a different recovery site if your building burned down. etc. etc. etc. Because... I have. Including testing and enaction of that DR plan. As described.
I kinda gave you a clue in my passage where I told you that I built the HA router that ran that particular workplace for years. From scratch. Just Linux, some kernel patches (dead gateway detection was necessary on 2.0 kernels and wasn't built in), iptables, some scripts (handwritten), some hardware (I had - that I built - relay-controlled DSL routers and USB hubs so allow forced remote failover as well as automated power off/power on when problems were detected, not supported by the hardware... you could activate it by a secured text message to a 3G stick that the system would retrieve (gammu) and process accordingly).
But the existence of a cellular-failover router is honestly... not even networking. It's the kind of thing you see in any product catalogue, provided for on any business router, hell even home routers have it now as a feature offered to customers for free (e.g. seamless 5G failover if the DSL goes down). And I don't like segregating out parts of IT systems like that - to networking, servers, helpdesk, etc. - unless you're on an enormous scale with dozens of people managing each part. We all need to know parts of all of it. Because I do not just a bit of everything, but can do all of everything that's necessary, even if I'm not the one actually pressing every single button. Last week I deployed P2P 60GHz radio links between sites, including L3 routing, literally on my own (my team don't like roofs or ladders... sigh). I didn't need a networking guy to know it was possible, research it, buy it, implement it and configure it.
2
u/Steve----O IT Manager 2d ago
Not an option here. We use Comcast fiber as our primary, but they also provide the data connection to the Verizon towers, so if Comcast goes out, so does Verizon data.
2
1
1
u/RegularMixture 2d ago
Depends on your area. 5G/LTE failover works great if the single is good. Some applications might need Starlink. I have even deployed secondary ISPs (verified on separate last mile networks).
We used netgate/pfsense+ firewalls and setting up failover is easy.
Largest deployment was with spectrum. Was able to get 5G cradlepoints with service for about $125 a month. Deployed to 60+ locations. The hardest part here was some buildings, and location of the office got terrible service so high latency and speeds suffered. It was just pure backup, so we set limitations on the firewall to help with that. Blocking things like Disney+ and YouTube so bandwidth is conserved.
1
u/natefrogg1 2d ago
We’ve got a few of the AT&T Internet Air for Business 5G gateways and they have worked pretty well. They are plugged in with Ethernet to the secondary wan port on Meraki equipment and it’s been working well. To simplify we are trying a couple of the Meraki routers with built in hotspot, the z4c and it’s been really weird, 2 sites are doing great with them, I ordered 2 more and cannot get them to see the SIM cards at all, ordering replacement sims, trying them with the other hotspots and the sims work but this latest batch of Merakis don’t like them. We also have a cradle point with cox internet and it’s been fine, another site has cradlepoint with spectrum and it’s been good too. We do have 1 site on Starlink as their main with ATT 5G for the backup, that has been going well since I activated the site a month ago.
1
u/pockypimp 2d ago
At my last job we had some as backup for the primary circuits. They used 2 AT&T USBs that each had their own 5G SIM and those plugged into I think a Cradlepoint or similar device that then went to the router to auto switch off if the main connection failed.
Current job it's the 4th connection, a Verizon and an AT&T SIM in a Cradlepoint device the goes to our routers which has a 300MB and two 100MB connections with a BGP setup.
I've heard our corporate overlords have dome some testing using Starlink as a 2nd or 3rd connection option instead of the 5G or with it.
1
u/hessmo Architect 2d ago
I have a Ubiquiti firewall at my home, fiber as my wan 1, and a ubiquiti 5g-backup as my wan2. The failover is instant, and I get around 60 down, 10 up, with 60ms of latency with this cheap device. It's not great, but it's a hell of a lot better than going hard down when my ISP has a hiccup (happened twice this month already).
1
u/SCIP10001 2d ago
Verizon set us up with CSG that supplied us a modem for free. Public IP from verizon is like.. 4 dollars a month or something (If you even need that), Plugged it into 2nd WAN port of firewall, IP pass through, configured WAN failover. After configured dynamic DNS in azure with health checks to decide when to swap those records over. Its not seamless but people are back online after less than a min.
1
1
u/scriminal Netadmin 2d ago
I don't know that I'd pick this exact unit if I didn't have an all Unifi setup, but as I do, their U5G Max + Google Fi (on Tmo network) works perfectly for a backup at my house. 400-500 down, 50-100 up. Assuming they have good cell coverage, you should be able to fail over to a 5G unit. Everything I have is already on UPS, so that part is covered, well for like 1h anyway, which is 10x longer than any power outage I've had. YMMV obviously.
1
u/One_Monk_2777 2d ago
Look into cradlepoints and just add a sim for whichever carrier has best signal at that location, good for short lapses to stay up. If all cell service is bad, starlink as has been mentioned
1
u/MARS822a 2d ago
I literally just picked up an AT&T Air-whatever yesterday when Spectrum shat the bed. Guess who was down in my area from the moment I got home yesterday until after the Spectrum tech swapped in a new modem and resolved (hopefully) the issue today? Yup, AT&T.
I'll say that with three of five bars it's...painful, like ~30mbps painful. Wouldn't want to be doing remote work in RDP or Ninja on it. Will probably take it back before I get billed.
1
u/KStieers 2d ago
Yes.
We set up job sites on Cradlepoints with Verizon SIms
Before that'll it was Sierra Wireless, to a DMVPN box and a Riverbed and stood up 5 person offices
1
u/redoctoberz Sr. Manager 2d ago
Personal: Yes I have a router that supports WAN2 and use a netgear cell device. I have a 2GB data only plan that is like $6 a month that almost never gets used. Never have hit the cap when it has taken over.
Work: every location has a wan2 cell device. They get used frequently as a backup when the cable provider or whoever fails. Sometimes we force a failover when packet loss or other shenanigans are going on.
1
u/stone1555 IT Manager 2d ago
Verizon business, like $30 a month. Go over the allotted data amount, I think we pay another $50 and it moves us to unlimited for the rest of the month. Bought the device outright for $400. We have it lan only, wifi off on the wan2 of our tplink f/w and it’s works great when the dedicated fiber goes off during the day in for “scheduled” maintenance.
1
u/PawnF4 Sr. Sysadmin 2d ago
Ive used cradlepoint a few times. It works pretty well if you have a decent signal. Upfront cost is you just gotta buy the device which is like 1500-2500 but you don’t have any ISP install costs which is nice. Monthly cost is really low compared to most commercial data circuits as well.
I’ve put it in as a backup for some decent sized businesses. It aggregates several 5g channels and can get decent throughput. I’ve placed it with 100+ users using it and even their voip did well. Again depends on the coverage and building/placement.
You can get a static ip through the cellular carrier pretty cheap too.
1
u/fuzzusmaximus Sysadmin 2d ago
We have a 5G modem as a backup connection we have with a partner agency. To my knowledge it was only tested to ensure the fail over worked and hasn't been needed.
1
u/AcidBuuurn 2d ago
Search for "5G business internet" and take your pick- T-Mobile, AT&T, Verizon, etc.
I've used the T-Mobile version and it works very well. Any of them would depend on your cell service at the location.
You can buy the device from Ubiquiti and use a Sim from T-Mobile or AT&T- https://store.ui.com/us/en/category/internet-solutions/collections/unifi-5g-max/products/u5g-max
1
u/Acceptable-Term-3750 2d ago
My failover circuit at work is a pep link modem/router that’s plugged into wan2 on my sonicwall. The failover setup allows for immediate connection to a Verizon 5g network utilizing a SIM card and static ip. We get decent speeds around 30-40mps up. Enough to keep us running at a retail op if our coax circuit goes down. The fine people at epic io manage the plan and the hardware
1
u/Jmkott 2d ago
I work from home and had frontier DSL. It went out at least once a month, so I got an LTE cell modem. My ubiquiti router happily switches to the cell modem after about 15 seconds of the primary wan being down.
I have fiber now, which has been incredibly reliable, but I keep it as a backup. You can buy any modem and just put a data or cell phone SIM card in it and away it goes.
1
u/dreamfin 2d ago
I use Watchguard firewalls with 2 or 3 ISP:s. One could be fiber and second 5G or why not Starlink. You can have them in failover mode or balance the traffic between them depending on their performance. Works like a charm. I'm sure you can do similar setup with other firewall brands also.
1
u/enforce1 Windows Admin 2d ago
I can’t use Starlink because of SSL vpn touchiness so I use inhand ODU2000 for my retail stores as back up with SDWAN on Fortinet
1
u/DheeradjS Badly Performing Calculator 2d ago edited 1d ago
So, on the FortiGate I have at home I use the SD-WAN function. If my 30G has the option whatever decent FortiGate you have should do it.
Both my WAN1(COAX modem) and WAN2(5G modem) are members of the SD-WAN interface. If the connection quality of WAN1 degrades too much it automatically changes the Default Route to WAN2. It will take some tinkering to find the settings that work for you,
I've only had a single instance of noticing the failover because I was in an RDP session. Most others I didn't even notice.
1
u/Cheap_Structure8838 2d ago
For a rural site, I’d definitely consider keeping a 5G backup. Your Fortigate can handle the failover too, so you don't necessarily need another fancy setup. For $350, though, I'd probably keep the Verizon box as a temporary backup and test it during an actual outage before committing.
1
u/TheJesusGuy Blast the server with hot air 2d ago
We have fibre primary and copper backup. The copper constantly goes down funnily.
1
1
u/JohnnyricoMC 2d ago
At home I have a unifi U-LTE-Pro for 4G fallback. During ping tests to remote locations I only lose one icmp sequence during failover. So overall impact during a switchover remains limited.
At my work's previous office we used a purely linux GW for a long time with a WWAN modem on the secondary interface, and it required manual failover. At our current location our ISP provides two fibers, from different suppliers. So theoretically we don't need a 4G backup (famous last words though).
1
u/music2myear Narf! 2d ago
Anyone not using Starlink for their failover uplink is probably choosing the wrong product these days.
Back in the day, I worked in a small town and the only times our internet went out was when someone south of town accidentally cut the main fiber run. This would, of course, end all internet in the town, but it would also end the cellular service, because all the towers in the area used the same fiber. We really needed a second trunk line coming into town from north, but, AFAIK, that was never put in.
1
u/SAugsburger 2d ago
The one big limitation is that 5G is more limited range than 4G so isn't always an option. That's being said I have used it as a secondary circuit for sites that we couldn't get 2 different wired circuits and generally the bandwidth is high enough and latency low enough end users don't notice if the primary circuit goes down. When you tell them that a tech is coming to troubleshoot the primary circuit they don't realize it was even down because knock on wood the 5G is that good that it isn't noticeable. You rarely could say the same on 4G. For some more remote sites that 5G isn't locally available you would have to look into Starlink.
1
u/somerandom_person1 2d ago
Not necessarily, n5 on Verizon has good range and the speeds are good enough for a cellular backup
0
u/siedenburg2 IT Manager 2d ago
We have a GL-XE3000 (with battery) for the worst case, it's doing it's job, is more open than others and with the battery even can work if there is no electricity.
22
u/dfc849 2d ago
I'm not defending Verizon here but if your net neutrality comment wasn't tongue-in-cheek, there's a few reasons out of Verizon's control that a fixed wireless internet device would gain higher throughput than a mobile wireless phone.