Meetinghouse Firewall Upgrade Available to FMs/STSs

Discussions about Internet service providers (ISPs), the Meetinghouse Firewall, wired and wireless networking, usage, management, and support of Meetinghouse Internet
Post Reply
rolandc
Member
Posts: 257
Joined: Tue May 15, 2012 8:20 pm

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#41

Post by rolandc »

russellhltn wrote:I have one building with DSL and 3 overlapping wards. I think it's 3Mbit. And the usage graphs do flat top at 3000kb/s. DHCP reports 80-90 users. I've not heard any complaints from that building.
I know of two buildings that have 10Mbit download but .4 - .5 upload and they bottlekneck at 60 - 70 users.

Download is not the main problem, its the low upload speeds that causes the problems.

The FMs still need to be warned to be ready for this problem.
Roland
aclawson
Senior Member
Posts: 760
Joined: Fri Jan 19, 2007 6:28 pm

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#42

Post by aclawson »

CleggGP wrote:This being said, STSs must remember to contact the Global Service Center to create a Special Purpose Zone if an "official" FHC exists in the meetinghouse. It may take a 2-3 days for the SP Zone to be created (due to GSC staffing levels), so take that into account when planning the firewall upgrade.
I called to have a couple of questions answered about the process and they completed the creation of the SPZ within just a few seconds. Don't make the call until AFTER you have moved the FHC to port 2 or your FHC will be offline until you do.
russellhltn
Community Administrator
Posts: 34487
Joined: Sat Jan 20, 2007 2:53 pm
Location: U.S.

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#43

Post by russellhltn »

rolandc wrote:I know of two buildings that have 10Mbit download but .4 - .5 upload and they bottlekneck at 60 - 70 users.
Interesting. Our DSL doesn't go that low. More like .768. But even then I wonder what's going on since that still seems sufficient unless someone is uploading photos, etc.
Have you searched the Help Center? Try doing a Google search and adding "site:churchofjesuschrist.org/help" to the search criteria.

So we can better help you, please edit your Profile to include your general location.
aclawson
Senior Member
Posts: 760
Joined: Fri Jan 19, 2007 6:28 pm

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#44

Post by aclawson »

60 users requesting web page refreshes, email server queries, sending emails, background status updates - .5 / 60 = a little over .008/sec which really isn't all that much. Saturation is to be expected. These firewalls can easily prioritize specific clients with QoS - it is baffling that they have not been programmed to do so.
russellhltn
Community Administrator
Posts: 34487
Joined: Sat Jan 20, 2007 2:53 pm
Location: U.S.

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#45

Post by russellhltn »

aclawson wrote:These firewalls can easily prioritize specific clients with QoS - it is baffling that they have not been programmed to do so.
Prioritizing clients would be a mess since it would require some method of identifying the client.

Most QoS I've heard of is based on traffic type or perhaps where it's going to/from. For example, prioritize lds.org and 10.x.x.x traffic.

I'd like to find a way to monitor the traffic so I can learn what's going on.
Have you searched the Help Center? Try doing a Google search and adding "site:churchofjesuschrist.org/help" to the search criteria.

So we can better help you, please edit your Profile to include your general location.
aclawson
Senior Member
Posts: 760
Joined: Fri Jan 19, 2007 6:28 pm

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#46

Post by aclawson »

russellhltn wrote:Most QoS I've heard of is based on traffic type or perhaps where it's going to/from. For example, prioritize lds.org and 10.x.x.x traffic.
Exactly. Since we know which clients are official devices (webcaster, clerk machines) then prioritize traffic going to/from those devices.
russellhltn wrote:I'd like to find a way to monitor the traffic so I can learn what's going on.
Packet sniffer between the clients and the firewall on the meetinghouse side.
User avatar
Mikerowaved
Community Moderators
Posts: 4741
Joined: Sun Dec 23, 2007 12:56 am
Location: Layton, UT

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#47

Post by Mikerowaved »

russellhltn wrote:Prioritizing clients would be a mess since it would require some method of identifying the client.
Even something as simple as giving priority to wired over wireless clients would help in many meetinghouses.
So we can better help you, please edit your Profile to include your general location.
CleggGP
Church Employee
Church Employee
Posts: 118
Joined: Mon Jul 28, 2014 1:55 pm

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#48

Post by CleggGP »

Now 22% of MH firewalls worldwide (USA 34%) are upgraded to the new Meetinghouse Firewall configuration, and over 400 stakes/districts have upgraded all of their MH firewalls. As noted on this forum message is being sent to STSs tell them about the upgrade, and provide information about how to upgrade their firewalls using Technology Manager.
harddrive
Senior Member
Posts: 501
Joined: Thu Jan 03, 2008 7:52 pm

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#49

Post by harddrive »

aclawson wrote:
russellhltn wrote:Most QoS I've heard of is based on traffic type or perhaps where it's going to/from. For example, prioritize lds.org and 10.x.x.x traffic.
Exactly. Since we know which clients are official devices (webcaster, clerk machines) then prioritize traffic going to/from those devices.
russellhltn wrote:I'd like to find a way to monitor the traffic so I can learn what's going on.
Packet sniffer between the clients and the firewall on the meetinghouse side.
When you use Wireshark for your packet captures. You will discover that when MLS connects to the SLC it will use an Internet IP address and not a 10.x.x.x address. So QOS will not help unless you get the correct Internet IP address and then it will only work on the last mile because the Internet does not support QOS tagging.
russellhltn
Community Administrator
Posts: 34487
Joined: Sat Jan 20, 2007 2:53 pm
Location: U.S.

Re: Meetinghouse Firewall Upgrade Available to FMs/STSs

#50

Post by russellhltn »

harddrive wrote:So QOS will not help unless you get the correct Internet IP address and then it will only work on the last mile because the Internet does not support QOS tagging.
Good point. You can prioritize requests going out, but I don't know if there's any way to manage what comes back in from our end.
Have you searched the Help Center? Try doing a Google search and adding "site:churchofjesuschrist.org/help" to the search criteria.

So we can better help you, please edit your Profile to include your general location.
Post Reply

Return to “Meetinghouse Internet”