Romain Jourdan
Romain Jourdan
Owner of this blog
Sep 5, 2016 5 min read

Hybrid WAN - my setup

This is the second article of a series covering Hybrid WAN for home office workers.

After presenting the benefits of the approach, I am now describing my environment and what I put in place to make it work.

A second connectivity

On top of public ADSL, I had to find another way of getting access to the Internet. Initially, I had in mind to order a new line and order a DSL access with a different service provider. I would have had a similar bandwidth (8M download, 1M upload) and it would have very likely been connected to the same telecom center hence in case of failure, I would have two lines down. Therefore, I decided to test other options.


A colleague of mine recommended Twoway I found it interesting: up to 22Mbps download, up to 6M upload.

What was a bit problematic was obviously the latency: 600-700ms. For sure, packets have to be transmitted up to the space and back again to Earth to the main station that forward finally traffic on Terrestrial links.

Since I worked for a WAN optimization company, I knew I would have solutions to mitigate this problem at least when accessing Headquarter resources.

Twoway satellite dishTwoway satellite dish

I took the starter pack (modem + Satellite dish) and also subscribed to a 25G data plan offer (40€ per month). Traffic during the night was unlimited (good for some replication jobs, BitTorrent…).

At this time, it was with Alsatis. They have handed over this business to NordNet in France and they don’t have such interesting plan anymore.

It helped a lot to get much more bandwidth. The high latency was an issue for a comfortable user experience for Web browsing but ok for watching videos (YouTube, NetFlix) or listening to on-line music. Having a bigger pipe helped Netflix to provide HD videos.

Question was how to steer the traffic intelligently so NetFlix goes on the Satellite uplink. I could have listed all IPs from Netflix but that would have been heavy to implement and maintain. Therefore, my first configuration was quite dumb: I routed based on source IP, the ones from AppleTV or my smartTV.

Similarly, I listed the few IP addresses of the SSL VPN gateway at HeadQuarter in SanFrancisco and created routes to have this traffic sent over Satellite.

I must admit that at the end of my contract, I was really fed up with the inconsistency of the service. Between 5pm and 9pm, it was almost unusable . Rest of the time, connection was ok and delivering the missing Mb/s I was looking for with this Hybrid WAN initiative.


Back in June 2016, 4G on my smartphone started to be incredibly fast when I was home.

4G performance with nPerf4G performance with nPerf

It was time to switch! I checked what 4G routers I could deploy at home to integrate wth my network. I chose the Huawei B315s-22 4G LTE/WiFi.

Huawei B315s-22Huawei B315s-22

I subscribed to a 40G data plan for 39€.

On my “Hybrid WAN” router (see here after), I replaced the satellite uplink and connected the Huawei router.

Experience is now far much better. Latency is low, bandwidth much higher. Problem is that I usually consume the 40G data plan before the end of the month. Once it is over, link is rate limited to 128kbps… But still, very good result. Let’s wait for unlimited data plan.

Some words about the 4G router

Huawei is one the major telecom vendors and has a great experience with mobile networks.

The 4G reception on this router is really good.

Design is nice but actually I don’t really care as the router stays in the basement :-D Oh, you probably wonder why one would do that to get 4G connection. This is because from the basement I have direct access to the garden and installed a 4G antenna with cables.

External 4G antennaExternal 4G antenna

Besides, my “datacenter” is down there. So it is easier for me to distribute the network.

Home LabHome Lab

I am missing some “basic” features like:

  • Reporting on the mobile coverage and quality (gain) so to optimize the positioning of the antenna
  • Ability to create static routes

Router firewall

The most important piece for this setup is the router that will be able to connect your LAN and load balance the traffic to two (or more) different connections.

In addition to routing capabilities, I wanted the router to be a stateful firewall as well so to protect the LAN from the Internet and create a DMZ for the services I want to expose.

Home network topologyHome network topology

I also wanted something cheap, opensource, green (low consumption) and with 1Gbps ports for the LAN. Being happy about Netgear products, I chose the WNR3500L-100PES.

Netgear WNR3500L-100PESNetgear WNR3500L-100PES

One will argue that there is only one WAN port on that router so why using this device for an hybrid WAN setup? This is true but the community is smart and provides good support.

I knew the DD-WRT project. They have referenced many routers so you will find what you need.

I installed DD-WRT on the gear and followed this tutorial

In the mean time, I found this one and although I have not tested it, it looks promising.

Great results however after few months, I started to miss some advanced features and a nicer GUI for this router-firewall.

More features meant a need for more power. I found this nice small box on Amazon for $150 . This great platform can host whatever OS you want and the goal was to find a good opensource solution.

Advanced router platformAdvanced router platform