Page 1 of 1

CBA850 passthrough modem access

Posted: Wed Dec 11, 2019 1:07 am
by Agl539
I followed the excellent Cradlepoint CBA850LP6 Introduction | Installation Options thread and have my CBA850-LP6 modem configured and working correctly with my pfSense router. I'm able to connect and control the admin interface without problem.

Before I finalize the router configuration and mount it on the roof near my aerials, I wanted to verify that in IP-passthrough mode it its possible to get a ping response from the modem or obtain SNMP settings via the passthrough interface as I've been unable to make this work so far. The fact the admin interface works leads me to think this is a configuration error on my part.

If I monitor pings to the CBA850 192.168.13.1 address, I see them reach the modem, but no responses. I do see packets for the admin interface to/from the modem flow correctly. I wondered if my problem was due to security settings, but I've been unable to configure the firewall in such a way as to enable responses. I wondered if anyone had this working?

I can see pings from my pfSense box to a google DNS server traverse correctly to validate a gateway is up.

I realize I could repurpose the primary LAN connection (Port 0) to support a standard, i.e non-passthrough connection, but that would require a second cable run and seems superfluous if only I could get the SNMP or ping responses to traverse the Port 1 connection.

thanks in advance for any help,

Edit: Running firmware v7.0.50 (Mon Mar 25 16:19:08 UTC 2019)

Re: CBA850 passthrough modem access

Posted: Wed Dec 11, 2019 8:54 am
by hazarjast
Not a configuration error on your part. This appears to be a wonky design choice by CradlePoint:

https://customer.cradlepoint.com/s/arti ... rough-mode

No clue on SNMP as I do not see a KBA for that.

Re: CBA850 passthrough modem access

Posted: Wed Dec 11, 2019 10:56 am
by Agl539
Thank you for signing up and sharing that information, I had spent an evening on it and just couldn't work it out. I was wondering if it was some asymmetrical routing where traffic would go in port1, and be returned on port0 but no, I didn't see them anywhere. I tried putting some NAT type stuff in place to force matters, but no luck either. Its reassuring to know its not a solvable problem.

Re: CBA850 passthrough modem access

Posted: Wed Dec 25, 2019 5:29 am
by BillA
Agl539 wrote: Wed Dec 11, 2019 1:07 am I followed the excellent Cradlepoint CBA850LP6 Introduction | Installation Options thread and have my CBA850-LP6 modem configured and working correctly with my pfSense router. I'm able to connect and control the admin interface without problem.

If I monitor pings to the CBA850 192.168.13.1 address, I see them reach the modem, but no responses. I do see packets for the admin interface to/from the modem flow correctly. I wondered if my problem was due to security settings, but I've been unable to configure the firewall in such a way as to enable responses. I wondered if anyone had this working?
While not too familiar with Cradlepoint routers, what comes to mind for testing purposes, is to disable the firewall completely in both Cradlepoint and the router, then possibly enable DMZ on Cradlepoint to pass all packets through without filtering (reboot everything after the setting changes). Play around with it, and see if it makes any difference. Course don't forget to re-enable the firewall and check the results.

Re: CBA850 passthrough modem access

Posted: Wed Dec 25, 2019 8:46 am
by Agl539
Thanks Bill, I tried that but this does appear to be a limitation of passthrough as linked to by hazarjest above. Its not critical but would have been nice to have had ping and SNMP output but the internal interfaces aren't available when in passthrough mode.

Re: CBA850 passthrough modem access

Posted: Wed Dec 25, 2019 7:09 pm
by BillA
Agl539 wrote: Wed Dec 25, 2019 8:46 am Thanks Bill, I tried that but this does appear to be a limitation of passthrough as linked to by hazarjest above. Its not critical but would have been nice to have had ping and SNMP output but the internal interfaces aren't available when in passthrough mode.
Well I guess it was worth a shot, maybe complaining or suggesting it to Cradlepoint, might fix it on a future firmware update (or not :/)