Skip to main content

Goedmorgen allemaal,

 

Firstly,  apologies for posting in English. If it is not ok let me know and I will use Google translator.

 

I have KPN fiber and up until now I have been using Fritzbox with no issues. I have to be away from home for a few months and I switch back to KPN Box 12 and SuperWifi 2 (wired) so my girlfriend could get KPN support in case of any malfunction.

KPN Box 12

Hardware Version            3.0

Software Version              SGEJ1000060E

SuperWifi 2

ModelWE620242

Firmware3.00.31

 

I found out that Guest network switch to Home network when connecting to the SuperWifi 2. This is an important security issue. This is a known issue that it get fixed on the new firmware V12.C.23.XX.XX.

There are also devices connected to the Superwifi 2 via Wifi that shows like connected over ethernet on the GUI map.

There is no way to force the update and I have read about it, but I am not sure if I will get it soon because first connection was with only the Box12 but one day after I installed the Superwifi 2.

I would really appreciate it if KPN could send the update for me asap, so I can leave everything configured for my girlfriend who really needed it for working and has not networking knowledge. Very very please KPN send the update to me aub!!

Also found that once you change the DNS provider, you no longer have access to the Box 12 web GUI. I assume this is because the DNS “server” on the Box 12 only provide DNS configuration via DHCP to the devices, but it does not function as a DNS server for the LAN which then forward the traffic.

The workaround for this is just manually change the DNS settings in your PC/Device to 192.168.2.254 to access the GUI and then switch the configuration back to “automatically” to use again the DNS provide that you have configured on your Box 12.

 

After all above described, I would like to share my thoughts. We all know that ISP routers are very basic with a very small room to configuration, but I think KPN should step up specially about security on the routers (like the issue with guest wifi on the Superwifi 2) specially now that a lot of people works from home.

It would be very nice also to have the option to bridge one ethernet port on the Box 12 and Superwifi 2 to the guest LAN so you can connect your work laptop to ethernet for better performance but block the access to your home LAN. And please add the option to back up the settings, it is just very simple and basic…

And last, I think is very good that KPN adopted free choice of routers with other brands like AVM or at least some of the models. I understand that you have the option to pay extra to get AVM equipment and support. But for the people who buy and own any supported AVM router, I think the support should be free of charge.

I want to mention that during the installation of the KPN router I had to replace it because I could not log in (after trying many methods of resetting) and the guy from the customer service was just excellent and extremely polite, so hartelijk bedankt for that.

 

Regards.

Hi again,

Has the dns settings change something to do with getting the update. Can I keep my dns settings or should I change them to defaults until the update arrive?

Thanks.


It would be very nice also to have the option to bridge one ethernet port on the Box 12 and Superwifi 2 to the guest LAN so you can connect your work laptop to ethernet for better performance but block the access to your home LAN. And please add the option to back up the settings, it is just very simple and basic…

With the new firmware the guest network is available on a separate vlan (1977) in order to make sure wifi clients connected to de guest wifi through a "super"WiFi (1/2) or Experia WiFi will be using the guast network instead of the normal LAN network. This means you can connect a PC with a networkcable to that vlan as well.

 

And last, I think is very good that KPN adopted free choice of routers with other brands like AVM or at least some of the models.

There is a free choice of routers. I for example use an EdgeRouter 4.

If you have TV from KPN as well there are some additional requirements for the router used.

In that case please check the topic below (in Dutch).

 

If you have no TV from KPN you can choose whatever router you prefer as long as it is suitable for the type of Internet connection (VDSL or fiber).


Hi,

Thanks for the response.

Unfortunately I still do not have the new firmware….I am looking forward to it but I dont think it will come soon. Still very worry about the guest network security bug….

The only solution its to get the new firmware but I did not get an answer from KPN so…

 

Regards,


Hi,

Thanks for the response.

Unfortunately I still do not have the new firmware….I am looking forward to it but I dont think it will come soon. Still very worry about the guest network security bug….

The only solution its to get the new firmware but I did not get an answer from KPN so…

 

Regards,

Updates are mostly done during night times. So to actually know if it already happened it is necessary to sometimes check if the web interface of the modem is already changed by attempting to login.


Hi @BruisTablet thanks for your response.

I just arrive home and check it. Indeed the firmware has been updated. Thanks KPN!!

Unfortunately the SW2 is still on the old version (I believe). I think so because the gui portal is still the old one, I can make changes on it and WPA2/WPA3 is not available.

I will try to factory reset the box and then the SW2 and see if I can force the firmware update and configure the network.

Regarding the answer from @wjb about the guest network over ethernet, I do not see any config about it on the box gui so I assume this is something that needs to be done on the device side right??

An other question, is the WPA2/WPA3 option using “PMF”?? I have a printer that do not support PMF and I do not want to step down the whole network to WPA2 beacuse of the printer so I think the best practice would be to set up an extra 2.4 wifi ssid right??

 

Regards,


Regarding the answer from @wjb about the guest network over ethernet, I do not see any config about it on the box gui so I assume this is something that needs to be done on the device side right??

It seems this vlan is hard-coded by KPN for the guest-network. If you want wired clients to connect to the guest network you need to make sure they connect to vlan 1977.


Hi, thanks again for your response.

 

Printer does not connect to the network when wifi is set to WPA2/WPA3 so it seem confirmed that it uses PMF. It has been connected to the extra wifi with WPA2 and works correctly.

 

Regarding the firmware of the SW2 is confirmed that is in the firmware version prior to KPN software but I have been unable to force the update. I had to call KPN because sometimes devices do not connect, light is amber or red and when it works still have the problem with the guest network.

They factory reset both the box and the SW2 but update is not installing and the issues still present. They told me I should receive the update but could be in one day, one week or one month so……

 

I have red on the forum one person with the same problem and one of the moderators send him an update and the problem was solved. I dont remember who because I have been unable to find the post again. So if someone could help I would really appreciate.

 

Regards, 


When the SW2 are still on the old firmware connectivity on the SW2 can only be working as a separated mesh environment where at least one SW2 needs to have connection via ethernet.

 

The last time i tried this after receiving new firmware on the v12 i could force the SW2 towards the new software by connecting it directly to the v12 on ethernet and factory reset the SW2 by long pressing the hardware reset button. Then after restarting it should seek contact and perform the update based on the fact the v12 is already is on the new firmware.  Basically what you are mimicking is the installation and presentation of a new to be installed SW2 device. Because thats basically the only scenario that kpn puts into the field. A standalone v12 unit that can have sw2 installed introduced as new devices.

Its good to hear WPA2/WPA3 is making use of PMF and that you can make a switch to WPA2 for one of the other extra ssid. However be aware that the extrawifi is actually communication oriented operating in the same bridging interface as the main ssid name is operating in.

If you succeed to get it on the new firmware it will be easy to spot as the SW2 are still individually accessible on their own web interface:

 


Hi @BruisTablet thanks for your response.

I tried your method and I was able to force the installation of the new fw. I think my previous mistake has been to factory reset the SW2 not connected to the box and then connect it. I did it with the SW2 connected to the 12 box  and everything went ok.

 

I still have problems on the gui that is not displaying correctly which devices are connected and how.

This was better when the box was in the new firmware and the SW2 in the old but I hope it will get solved in future updates.

The problem of getting the wrong ip address when connecting from the box 12 to the SW2 seems to be solved.

 

Thanks a lot to everyone for the help.

 

Regards,


I would not bother to much about the topology overview in the device. It seems they are working on that part.