What is the default username and password for Actiontec Modems and Routers?
Most Actiontec Modems and Routers DO NOT have a default login. The exceptions are the Actiontec Modems and Routers made and branded for a specific Internet Service Providers (ISP). Some ISP's require a default user name and password. These Modems and Routers have a sticker on the bottom of the device with the default User name and Password printed on them.
How can I make a server on my local network, available to Internet users?
Unlike local server traffic, users attempting to access your server from the Internet must pass through the Actiontec Router or Modem SPI Firewall and NAT. To pass through, the port used by the server, must be opened in the Firewall. This process is known as Port Forwarding. For example, a FTP server would typically use port 21, so you would want to forward port 21 through the router's firewall to local address or HOST name of the FTP server. (Ports are identified by a numeric value from 0 - 65535. But the port numbers for the most common servers are in the range from 0 to 1023, so they are referred to as Well Known ports. Since IANA manages this range of ports, their web site, "iana.org" provides an accurate list of the services and their assigned port numbers.)
Are the Actiontec Modems and Routers upgrade-able?
Yes, they can be upgraded by flashing the Routers or Modems firmware. If the Actiontec Modem or Router that you have, is branded for a particular ISP, the proper firmware update will ONLY be available from that ISP. Actiontec can provide only the Retail or NCS (Non-Customer Specific) version of the firmware for the Router or Modem. The NCS firmware can not be substituted for all ISPs, but can be configured to be compatible with most. The firmware update for Actiontec Routers and Modem is available for download on the Actiontec Support site.
How many simultaneous connections does a Actiontec Router or Modem allow?
It varies from 190 to 254, depending on the product and the firmware. The GT704WGs that have the Verizon firmware loaded, have a limit of 190. The R7000M-2A is limited to 252, and all of the remaining Actiontec Routers and modems have a limit of 254. However, it is good to keep in mind that each computer added to the network will reduce the bandwidth available to the existing network computers. It is recommended to limit the number of connections to 45, but this number can vary depending on the activities of the network computers. For example, downloading MP3s, ISOs, or other large files, require much more bandwidth than checking email or simple Web browsing. If the network is Hosting Web, FTP or Gaming severs the limit for the number of network connections may be much lower.
I need to secure my wireless network. What types of Wireless Security are there? What kind should I use?
There are several types of security for wireless networking.
Wireless MAC Address Filtering - allows the router to control access to the wireless network by allowing only certain MAC addresses to connect to the wireless network. This is an older type of security and can be circumvented. The MAC address was intended to be a unique permanent identification number assigned to every network adapter, but now the BIOS on some computers allow the MAC address to be assigned by the user, and there are free programs that allow the user to change the MAC address at will. These changes undermine the integrity of using a MAC address for identification. While some users still prefer to use this type of security, in reality it should only be used in conjunction with some other type of wireless security, and not as the sole method for securing a wireless network.
WEP (Wired Equivalent Privacy) - gives the wireless network security equivalent to that of a wired network. There are known hacks, but it is probably the type of security that is most commonly used, because nearly all wireless cards support it. If WEP is going to be used, be sure to use the highest bit level possible. Common values are 64-bit, 128-bit and 256-bit, the higher the number the stronger the encryption.
WEP+ 802.1x - is an improved form of WEP that uses a Radius Server for authentication. This Enterprise class Wireless Security Solution is not commonly used outside of large companies though, due to the expensive hardware requirements.
WPA (WiFi Protected Access) - has two levels; an Enterprise mode that uses 802.1x, and replaces WEP with WPA; and a PSK (pre-shared key) mode known as WPA Personal. The latter is considered the best option available at this time for many home users. WPA's strength is that it does not trust to encryption alone. It has been improved in many areas. WPA allows a for a much larger and therefore stronger key. It also implements TKIP (temporal key integrity protocol) which dynamically changes keys as the system is used. WPA makes breaking into a wireless LAN far more difficult.
The best choice for security is WPA Personal (WPA PSK), it uses a password or passphrase called a PSK (Pre-Shared Key) string that is created by the customer. The key needs to be from 8 to 63 characters long, with 20 characters being considered by most to be the minimum length required for a reasonably secure network. The key must be strong because this is where many hackers will attack. They often use a dictionary attack so those 20 characters CAN NOT be in the form of a real word (like dog or umbrella), they should be random, letters or numbers, capitol letters and even punctuation is allowable.
The best choice for compatibility would be WEP, it is probably the type of security that is most commonly used, because nearly all wireless cards support it.
Before WPA is enabled or a PSK string is set on the router, be certain that all of the wireless cards that are going to be used support WPA. If a network adapter does not support WPA, check the support pages for that product. Many adapters may have an updated driver or firmware that may provide or improve WPA compatibility.
I now have Cable Internet service using a Cable modem provided by my new ISP. Can I use my wireless Actiontec DSL Modem, simply as a Wireless Router?
No, it is not possible to use any DSL modem as a router, whether it is wireless or not. The reason is that the WAN connection on the DSL modem is a RJ-11 phone line port. To function as a router the DSL modem would need to have a RJ-45 Ethernet port for its WAN or Internet connection and they do not. DSL modems do have a RJ-45 LAN Ethernet port for connecting to a PC, and if the port was connected to a Cable modem, the modem would behave as a hub or switch rather than a router.
I was told to change the MTU setting of the Actiontec, so it will work with my Xbox. How do I change the MTU?
There are several problems with this.
1. The MTU setting is not the cause. The default MTU setting for Actiontec routers and modems is 1492 for PPPoE and PPPoA connections, and 1500 for DHCP as well as Static connections. Many of the older Actiontec routers and modems do not allow the MTU setting to be changed. However, some of the newer firmware versions do allow this. If the firmware does allow the MTU setting to be changed, the option will be on the WAN IP Address page of the Advanced Setup in the device User Interface. Typically it is a text box near the bottom of the page. Simply enter the setting you want and click Apply to save the change.
2. The actual problem is that the ports used by the Xbox are not open for incoming traffic. There are two ways this can be changed.
A. Enable UPnP (Universal Plug and Play). Many of our routers and modems are delivered with UPnP disabled for security reasons. But UPnP can easily be enabled. To enable it, browse to the UPnP page in the Advanced Setup. Select the Enabled option and click Apply.
B. The other way to open the ports needed by the Xbox, is to use Port Forwarding. The Xbox uses ports 88 UDP and 3074 both UDP and TCP. Actiontec routers and modems use two different interfaces for port forwarding. (There will be one or the other, but not both. The utility for port forwarding will be in the Advanced Setup section unless there is a Security section and a Advanced Setup section, in which case it will be in the Security section.) One method is called Port Forwarding and requires entering the port needed and the IP address of the Xbox. This step is repeated until all ports are entered. Then the user clicks Next, then Save and Restart in the lower left, followed by clicking the Save and Restart button. The other method is Application Level Gateway. This is sometimes referred to as ALG or just Applications, either way it is still the tool for port forwarding in that firmware version. To forward the ports using this tool, you must create a rule. There are many pre-configured rules, but there isn't one for the Xbox. To create a rule the User must select the HOST Name of the Xbox from the drop-down and then select the Category 'User'. Then below the Available Rules box, click the button labeled 'New'. Now enter a name for the rule (example: XBOX), and then select the protocol UDP and enter the number 88 in each of the three boxes and click Apply. Then select the protocol TCP/UDP and enter the number 3074 in all three boxes and click Apply. Now that all of the required ports are listed across the bottom of the page, click Back. Double check that the correct HOST Name is showing in the drop-down and that the bullet is by the category User. Select the new rule (XBOX) in the Available Rules window and click ADD, to apply the rule for the Xbox. To save the newly created rule click Apply at the bottom of the page.
3. Make certain that the Firewall setting is OFF or BASIC. Any other setting will in most cases block ports that the Xbox needs to work correctly.
I need to open ports on the Actiontec, should I use Port Forwarding or DMZ Hosting? Why?
Port Forwarding and DMZ Hosting are two ways to accomplish the same thing, opening ports. Where Port Forwarding is selective and specific, DMZ Hosting is indiscriminate and wide open. If you need to open one port or a small range of ports, or even a combination of both, Port Forwarding is the best choice. If the list of ports that need to be opened is long and complicated, it may be tempting to use DMZ Hosting, but it should still be avoided unless the security of the machine in question is not critical. The only time that DMZ Hosting is appropriate, is when it can be used without compromising the security of the network.
Examples where DMZ Hosting might be appropriate:
1. Devices like game consoles or web-cams with a limited Operating System
2. A server designed for that type of an environment
(like a proxy server or a server with hardened security)
3. Possibly a gaming computer, but it is not recommended
(At the very least the computer may need frequent reloading of the OS)
The difference between Port Forwarding and DMZ Hosting is security. While any open port will slightly degrade security, it is possible to maintain a level of security on a network that utilizes Port Forwarding. It is not really possible to keep a network secure using DMZ Hosting, unless the network or some of it's critical components are designed for it.
Rule of Thumb:
Use Port Forwarding as the primary tool for configuring ports.
Use DMZ Hosting only when it is required.
Is my AT&T Network Password the same as my AT&T Email Password?
No, they are different. The Network Password is a system generated password used by your modem/router to authenticate and connect to the DSL network. Modems/routers provided by AT&T will automatically populate your Member ID and Network Password into the device. For modems/routers not supplied by AT&T, you will need to enter this information in to the device
What is the default IP address for accessing an Actiontec Modem or Router?
The default IP address for accessing most of the Actiontec Modem and Routers is "192.168.0.1". The exceptions are the Actiontec Modems and Routers made and branded for a specific Internet Service Provider (ISP). The Modems and Routers made for a specific ISP will have a sticker on the bottom of the device with the default IP address on it. However, the IP address can be changed by the user, so it is important to document and save the IP address when it is changed. It is suggested that the IP address should be written on a label that is then attached to the Modem or Router. If this new IP address is communicated to technical support early in any relevant conversation, it will save time and confusion.
Can the antenna on the Actiontec Wireless device be upgraded?
Yes, this device has an antenna that can be removed and replaced or upgraded. The connection method for this device, Reverse Polarity Sub-Miniture Adapter (RP-SMA), is readily available at most computer or electronics stores.
My VPN Client shows I am connected, so why am I still unable to access resources on the VPN network?
This will sometimes occur when there is a problem with the IP address used by the VPN Client computer. The remote VPN Client is either using an IP address that is in a range that conflicts with the VPN network or the VPN network requires that Clients use an IP address from within a specific range. If the IP address is in conflict, the solution is to change the range of IP addresses used by the Actiontec Router or Modem. But if the VPN network requires a specific range of IP addresses, then only an administrator can provide the information that is needed. After contacting the network Admin to determine the correct IP range, the directions in the following section can be used to configure the LAN IP Address of the Actiontec Router or Modem.
To change the range of addresses used by the computer network, the router's LAN IP address must be changed. To change the LAN IP address you must first access the User Interface of the Router or Modem at the current IP address. (Virtually all of the Actiontec Routers and Modem have a default IP address of 192.168.0.1. The exceptions are the Routers and Modem that Actiontec produces for use on Verizon's FiOS and DSL Service. Those devices have an IP address of 192.168.1.1.) After accessing the User Interface, select the 'Advanced Setup' option. In the Advanced Setup, select 'LAN IP Address'. On the LAN IP Address page, you need to do more than just change the IP address, you need to change the network. The simplest way to do this is to change the third octet. That is the third section of the IP address. By default the third section, or octet, is either a '0' (In the address 192.168.0.1) or a '1' (In the address 192.168.1.1). Not just any number value can be used; it must be a value that is between the number '2' and the number '254'. So something like 192.168.5.1 (The third octet is '5') or 192.168.77.1 (The third octet is '77') would work. It is not enough to just change the last octet or section. That would not change the network, only the IP address. This means that the network clients would still be assigned an IP address that conflicts with the VPN sever.
(Changing the LAN IP Address will cause the Router or Modem to assign new IP addresses that are compatible with the new LAN IP Address to all DHCP clients. Network Clients with Static IP addresses will need to be changed manually. Naturally, you will need to use the new IP address when accessing the User Interface of the device in the future.)
All of the Ethernet ports on my Modem or Router are in use; can I still add devices? How?
Yes, connecting an Ethernet hub or switch will extend the capabilities of the Actiontec Modem or Router. Just run a standard Ethernet cable from the UPLINK port of your new hub or switch to a LAN port on the Actiontec Modem or Router. Then connect the power supply to the hub or switch.
Will my Xbox work with the Actiontec Modem or Router?
Yes, Actiontec Modems and Routers are compatible with the Xbox. However, it may be necessary to forward the ports used by the Xbox, in the Actiontec Modem or Router. Without Port Forwarding, the Xbox Connection Test may report a "NAT" rating of "STRICT" or "MODERATE", rather than "OPEN".
Can I use the Actiontec Modem or Router to connect to my employers VPN so that I can work from home?
Yes, the Actiontec Modems and Routers support connecting to VPN servers. By default, Actiontec Routers and Modems allow Client VPN traffic to pass-through. (the Actiontec will allow a connected PC to "pass-through" and connect to a remote VPN server).
NOTE: Unless otherwise specified, Actiontec Routers and Modems do not function as VPN endpoints. They cannot make a VPN connection directly to a VPN server, router or client. The reverse is also true, VPN routers, servers and clients cannot make a VPN connection directly to the Actiontec Router itself. (Some of the proprietary VPN applications require specific ports be opened in the Actiontec, for a successful connection. Not all VPNs use the same ports, so determine the ports used by your VPN software before attempting to forward the ports.)
Can I stop using my software Firewall or Security program on my computers, now that I have the Actiontec Modem or Router?
The answer depends on the security requirements of your Network and what the individual computers are used for.
Actiontec Modems and Routers have a Stateful Packet Inspection (SPI) Firewall built-in, and because of this many users wonder if it is safe to uninstall their PCs software Firewall, if it is a third party product, or disable it, if it is built into the Operating System. This is desirable because when customers purchase a Router, they are interested in networking their computers, and having a separate firewall on each PC can make networking quite complicated.
The short answer is Yes, the software Firewalls can be removed or disabled, but not without risk. Many operate with only the one Firewall on the router successfully for some time. The risk is if a virus or hacker gets past the routers Firewall, there is nothing to stop it from compromising the entire network. If this type of arrangement is going to be used, any sensitive information, POS machines, or PCs used for banking, should be off of the Network, or these individual computers should continue to have their own software Firewall to protect them if the network was compromised.
Should I turn the Actiontec Router or Modem Off each night, or should I leave it On, perpetually?
Actiontec Routers and Modems are designed to be left on continuously. The nature of the Internet makes an 'always on' connection very desirable, and in some cases a requirement. Turning the Actiontec Off when it is not being used, could arguably add to security. But any gains to Security by not being connected to the Internet 24/7, must be balanced against the loss of much convenience.
Whether it is a computer or a router, many users feel that turning electronic devices Off and On each day will wear them out prematurely, and others are convinced it will not.
Actiontec recommends leaving our routers and Modems on continuously, but they can be turned Off and On each day if you prefer.
Do the Actiontec Routers and Modems support File and Printer Sharing? Is there anything that needs to be done, to enable it?
Yes, the Actiontec Routers and Modems support File and Printer Sharing.
No, it does not require enabling. There are no settings on the Actiontec Routers and Modems with regard to Sharing, it is the router's default behavior. All of the settings for Sharing are on the computers (or printers, or NAS, etc...) themselves.
The Actiontec routers and modems do not have any additional features or settings for File and Printer Sharing (computers that can 'see each other' or a networked printer on the network). As stated earlier, the default behavior of the Actiontec allows this activity with no restrictions. Wireless devices have access to each other and to Wired devices, whether Ethernet or USB. The reverse is also true, Wired devices (like a PC) have full access to other Wired devices (like a printer or NAS), as well as Wireless devices (whether PC or printer).
Provided that the PCs in question have a functioning Internet connection through the Actiontec Router or Modem. Then...
If a device can not 'see' the network or access resources on the network, the cause will be on the devices themselves. If it is a printer, then it may be a network TCP/IP setting or missing protocol. If it is a server or workstation that cannot be accessed, then it will be TCP/IP settings, Firewall settings or mis-configured Sharing on the PC.
The bottom line is this, there are NO settings on the Actiontec Routers and Modems for Sharing.
Help for the configuring of File and Printer Sharing for MS Windows.
Is there a limit to the number of Wireless connections, that the Actiontec Wireless Router or Modem will allow?
There is no limit on the number of wireless connections, but there is a limit to the amount of traffic or bandwidth that can pass through the Actiontec. It is good to keep in mind that each computer added to the network will reduce the bandwidth available to the existing network computers. It is recommended to limit the number of connections to 45, but this number can vary depending on the activities of the network computers. For example, downloading MP3s, ISOs, or other large files, require much more bandwidth than checking email or simple Web browsing. If the network is Hosting Web, FTP or Gaming severs the limit for the number of network connections may be much lower.
What is Actiontec doing about the industry wide issue of the (WPS) Wi-Fi Protected Setup PIN brute force vulnerability?
As of 1/31/2012 all future Actiontec products that have the (WPS) Wi-Fi Protected Setup feature in the firmware will also contain a WPS "lock-out" feature and/or any other Wi-Fi Alliance recommended improvements to the (WPS) Wi-Fi Protected Setup.
Are our DSL Modems and Routers compatible with Docsis 3.0?
No, they are not because this standard only applies to cable modems.
Is my Actiontec DSL Modem or Cable/DSL Router a Firewall?
Yes, the Actiontec DSL Modem and Cable/DSL Router acts as a Firewall. They provide security through "Stateful Packet Inspection" or SPI, which inspects incoming data packets to make sure they correspond to an outgoing request. Unsolicited packets (which could be harmful) are rejected. Through the use of specific Firewall settings, the firewall can be configured to block outgoing as well as incoming traffic.
What is the current firmware version for my Actiontec Device?
This document lists the current product firmware versions for Actiontec and the various Internet Service Providers or ISPs.
Current Firmware Versions
If a product is not listed in the document, then there has been no firmware update or upgrade released for that product.
How do I disable Client Isolation or AP (access point) Isolation?
Actiontec devices NOT have Client Isolation or AP (access point) Isolation enabled on our routers (therefore no disabling is required).
How to connect a Google Chromecast adapter.
Connect a Google Chromecast adapter to an Actiontec modem/router, these are the steps
1)Using the computer/phone/tablet etc., click on the wireless networks and select the google chromecast wireless device.
2)Locate the Google chromecast app on the device and run the app. Verify the code on the tv matches the code in the Chromecast app then click next. If desired you can change the name of your Chromecast app then click next.
3)Select the wireless network of the modem/router and input the security key. It will now tell you that the app is setting up chromecast and it is connecting to the wireless network. If it appears that it is not connecting, go back to your phones wireless network selection and reconnect the phone to your wireless network. The Chromecast app should now tell you the adapter is now ready to cast. You can verify your chromecast is connected to the network by tapping the arrow to the right.
4)Run the desired app to stream to the chromecast adapter(ie., Netflix, youtube, etc.).
5)If after these steps the Chromecast device doesn't connect or stream, user will need to contact Google for further support.
What are the VPI/VCI settings for AT&T DSL Service?
By default, the Actiontec router/gateways VPI/VCI values are set to 0/35. For BellSouth customers these values are required to be 8/35. To change these values, from the unit's interface, click the Advanced Setup tab, from the menu on the left, click Broadband Settings and/or DSL settings. Changed the 0 to 8 and click "Apply". Once the page refreshes, verify the color of the Internet LED on the front of your unit. If both the PPP Username/Password and VPI/VCI entered into the unit are correct, the Internet LED will be Green. If it is Red, you have not entered the correct PPP Username/Password under the Quick Setup tab. Re-enter these values, the PPP Username will typically be an email address (firstname.lastname@example.org) and the PPP Password will be a six digit alpha/numeric such as (xyz123). These values are only available from AT&T. If the Internet LED is off, please verify that you have input the correct VPI/VCI has it pertains to your AT&T network. Again, these values are only available from AT&T.
How can I know the correct VPI/VCI settings to use?
Your ISP should provide the VPI/VCI settings, but if they do not, here are some guide lines for trying to get your modem configured anyway.
ISP VPI/VCI Settings
CenturyLink/Qwest 0/32, Verizon 0/35, SBC 0/35, AT&T 0/35, SW Bell 0/35, Sprint 8/35, TDS 0/35, Bell South 8/35, CenturyTel 8/35, EarthLink 0/35, Embarq 8/35, and GSInet 8/35
ISP VPI/VCI Settings
NTL 0/38, Bulldog 0/38, UK Online 0/38, and Tiscali 0/38
If your ISP is not in this list but they are in the USA, then first try 0/35, and if the Internet light remains off, try 8/35. If your ISP is not in this list and they are in the UK, then you should try 0/38. Other than CenturyLink/Qwests 0/32, the settings of 0/35 and 8/35 are the most common used by ISPs in the USA, and 0/38 is used by virtually all of the ISPs in the UK. The ISP should have provided this information in the beginning, but some ISPs resist giving the VPI/VCI information if you have not purchased the modem that they provide. However if 0/35, 8/35 and 0/38 do not work, then there is really no alternative, to getting the information from your ISP. It is unfortunate, but sometimes it requires a great deal of insistence to obtain this information from the ISP.