Our first PPPOE Set Up in Uganda: Luxenetworks

Views: 94

Our first PPPOE Set Up in Uganda: Luxenetworks

How We Set Up PPPoE for a Client: A Luxenetworks Walkthrough

At Luxenetworks, we get a lot of calls that start the same way: "My internet was working fine, then the ISP switched us to a new connection type, and now nothing works." More often than not, the culprit is PPPoE (Point-to-Point Protocol over Ethernet). Last week, we handled exactly this kind of job at a 50-unit apartment complex whose ISP had just migrated the property onto a PPPoE-based connection. Here's how we approached it, the equipment we used, and the steps we took, in case it helps you understand what a proper PPPoE setup actually involves at scale.

First, What Is PPPoE and Why Does It Matter?

PPPoE is a networking protocol that many ISPs, especially DSL and fibre providers, use to authenticate and manage customer connections. Instead of your router just grabbing an IP address automatically (like with DHCP), PPPoE requires your router to "dial in" using a username and password supplied by the ISP, much like old-school dial-up internet, just running over Ethernet instead of a phone line.

The upside for ISPs is better control over billing, session management, and security. The downside for customers is that if it's not configured correctly, the connection simply won't come up: no internet, no clear error message, just a blinking light and a frustrated household.

The Property and the Situation

This job was for a 50-unit apartment complex. The building had just been switched over to a new connection by their ISP, and the property manager reached out after residents across multiple units started reporting the same issue: Wi-Fi showing as connected, but no actual internet access. With that many units relying on one shared connection point, even a small misconfiguration at the network core cascades into a building-wide outage, so we prioritized the visit.

They called us with three symptoms:

  • The core router showed a physical link to the ISP's line but no internet access
  • The ISP-provided PPPoE username and password weren't being accepted
  • Wi-Fi devices connecting through the access points on different floors could see the local network but had no external connectivity

This is a textbook PPPoE misconfiguration, so we scheduled a visit.

The Equipment We Used

For a property of this size, we relied on a compact but capable equipment stack:

  • MikroTik RB951: our core router, chosen for its RouterOS flexibility, reliable PPPoE handling, and the ability to manage NAT and firewall rules for the whole building from a single point
  • Managed switch: sitting between the RB951 and the rest of the building, distributing wired connections out to each access point
  • Tenda F6 wireless routers (x2): repurposed as dedicated Wi-Fi access points to extend coverage across the property, rather than acting as independent routers
  • ISP-provided line: the incoming connection requiring PPPoE authentication
  • Cat5e/Cat6 patch cabling: connecting the ISP termination point, RB951, switch, and each Tenda F6 in the chain

This combination gave us a single, centrally managed PPPoE session at the RB951, with the switch and Tenda F6s doing what they do best: distributing that connection cleanly across a larger property without introducing conflicting routers or duplicate DHCP servers.

Step 1: Confirming the Physical Layer First

Before touching any settings, we always rule out physical and cabling issues. With this setup, the chain ran: ISP line in, then the RB951 WAN port, then the managed switch, then the Tenda F6 access points on different floors, then resident devices. We checked that:

  • The ISP's incoming line was active and delivering a stable signal
  • The cable running from the ISP termination point to the RB951's WAN port was properly seated and undamaged
  • The RB951's WAN port link light was active
  • The cable from the RB951's LAN port into the managed switch was solid, and the switch itself was passing traffic (link lights active on every relevant port)
  • The cabling running from the switch out to each Tenda F6 access point was intact

It's tempting to jump straight into software configuration, but a good chunk of "PPPoE won't connect" calls turn out to be a loose cable, a faulty switch port, or a bad patch lead, and in a multi-floor property, tracing that down first saves a lot of guesswork later. In this case, the physical layer was clean end to end, so we moved on.

Step 2: Gathering the Correct PPPoE Credentials

This is where most self-installs go wrong. PPPoE credentials are not the same as your Wi-Fi password, and they're often formatted in ways that trip people up: extra characters, case sensitivity, or a required domain suffix (like username@isp.net instead of just username).

We contacted the ISP's provisioning line to confirm the exact credentials issued to the account, and verified there was no realm/domain suffix required for this particular provider. Small detail, but it's a common point of failure.

Step 3: Configuring PPPoE on the RB951

An important decision in a multi-device, multi-floor setup like this is choosing exactly one device to handle the PPPoE dial-up. You never want two devices both trying to authenticate the same session, especially on a property serving 50 units. We chose the RB951 as the PPPoE client, since it's the device sitting closest to the ISP line and has the routing horsepower to handle NAT and firewall duties for the entire building.

With confirmed credentials in hand, we logged into the RB951 via WinBox and:

  1. Created a new PPPoE client interface bound to the WAN-facing Ethernet port (ether1), rather than leaving it on a plain DHCP client
  2. Entered the username and password exactly as provided by the ISP, double-checking for trailing spaces, a surprisingly common issue when credentials are copy-pasted from an email
  3. Set the MTU to 1492, the standard value for PPPoE, since it accounts for the protocol's overhead compared to a normal 1500-byte Ethernet frame
  4. Set "Add Default Route" and "Use Peer DNS" so the RB951 would automatically pick up routing and DNS information from the ISP once connected
  5. Configured NAT masquerading on the PPPoE interface so devices on the LAN side could share the single public IP
  6. Enabled the connection and confirmed the PPPoE interface came up with a "running" status and a valid public IP address

Step 4: Setting the Switch and Tenda F6s to Their Proper Roles

With the RB951 handling PPPoE and routing, everything downstream just needed to pass traffic correctly across the building:

  • The managed switch was configured to carry traffic cleanly from the RB951's LAN port out to every Tenda F6 access point and any wired connections on the property
  • Each Tenda F6 was set to Access Point mode rather than its default router mode, with DHCP disabled on both units. This is a critical step, because if a Tenda F6 is left in router mode, it will try to hand out its own IP addresses and NAT traffic, creating a double-NAT situation that causes exactly the kind of "connected but no internet" symptom residents were seeing
  • Both F6s were connected to the switch via their LAN ports (not WAN), configured with static management IPs on the same subnet as the RB951, and set to the same Wi-Fi SSID and password so residents could roam between coverage areas seamlessly as they moved around the property

Step 5: Verifying the Connection End to End

With the PPPoE session up on the RB951 and the F6s reconfigured as access points, we ran through our standard checks:

  • Confirmed the RB951's PPPoE interface held a stable public IP with no repeated drops
  • Pinged an external IP from the RB951 to confirm outbound connectivity
  • Resolved a domain name to confirm DNS was working correctly (thanks to "Use Peer DNS" pulling the ISP's DNS servers automatically)
  • Tested speeds on a wired device through the switch and on Wi-Fi through each Tenda F6
  • Walked the property between coverage areas with a phone to confirm seamless roaming on the shared SSID, with internet access holding throughout
  • Spot-checked connectivity with a few residents on different floors to confirm the fix had resolved the outage building-wide, not just near the core router

Everything came back clean.

Step 6: Locking In Reliability

Getting PPPoE to connect once isn't the whole job. We wanted to make sure it stayed connected. So we also:

  • Enabled the RB951's built-in PPPoE keep-alive behaviour so a brief ISP-side blip wouldn't require a manual reboot or an on-site visit
  • Double-checked that DHCP was fully disabled on both Tenda F6s, so there was no risk of them silently re-enabling and causing IP conflicts across the building
  • Checked firmware/RouterOS versions on the RB951 and the F6s and applied available updates, since outdated firmware is a common cause of intermittent PPPoE drops and Wi-Fi instability
  • Documented the full topology and working configuration (RB951 PPPoE settings, switch layout, and F6 access point settings) securely for the property manager, in case a device ever needs to be replaced or the network expanded to cover more of the building

Common PPPoE Pitfalls We See Again and Again

If you're attempting a PPPoE setup yourself, especially with more than one networking device on site, here are the mistakes we run into most often:

  • Letting more than one device try to handle PPPoE. If your main router and a secondary access point (like a Tenda F6) both attempt to dial the PPPoE session, or both run DHCP and NAT, you end up with conflicts and double-NAT issues that are painful to diagnose.
  • Leaving access points in router mode. The Tenda F6 is a capable router in its own right, but when it's meant to just extend Wi-Fi, it needs to be switched into access point mode with DHCP turned off. Otherwise it'll hand out its own conflicting IP addresses.
  • Mistyped or copy-pasted credentials with hidden characters. Always type PPPoE credentials manually if pasting isn't working reliably.
  • Ignoring MTU settings. An incorrect MTU on the PPPoE interface can cause some websites to load while others time out, a confusing, hard-to-diagnose symptom.
  • No keep-alive configured on the dialing device. Without it, the connection drops and needs manual intervention, often at the worst possible time.
  • Assuming the switch and cabling are fine without checking link lights first. Physical issues on a switch port masquerade as configuration issues constantly.

Wrapping Up

For this 50-unit property, the whole process, from diagnosis to a fully stable, building-wide connection, took under a few hours once we were on site. PPPoE isn't inherently complicated, but it does require getting several small details right: correct credentials, correct connection type, sensible MTU, and a reliable reconnect policy. At scale, it also means making sure every downstream device (switch, access points) is configured to complement the core router rather than compete with it.

If you're dealing with a similar situation, a new ISP connection that just won't come online, whether it's a single home or a full apartment complex, it's often faster and less frustrating to have someone experienced take a look rather than guessing through router menus. That's exactly the kind of job our team at Luxenetworks handles regularly, and we're always happy to help get your connection stable and secure.

Related Insights

Jun 04, 2026

The launch of the National IP Peering Exchange (NIPX)

DIGITAL SOVEREIGNTY  ·  APRIL 2026 Uganda’s Internet Is Finally Coming Home The launch of the National IP Peering Exchange (NIPX) marks a turning point for Uganda’s digital economy — and a major win for every local ISP operating in the country. ●  NITA-U & Ministry of ICT    ●  Launched April 17, 2026    ●  Kampala, Uganda   ↓ Latency Local traffic speeds dramatically improved 1st Open IXP Uganda’s first neutral Internet Exchange Point FX Savings Reduced hard-currency spending on overseas routing     BACKGROUND The Traffic Boomerang Problem For years, a strange and costly thing happened every time a Ugandan accessed a government service or local website. Their data would leave Uganda, travel to servers in Europe, the United States, or South Africa — and then travel all the way back. This “boomerang” routing added latency, drove up costs for ISPs paying for international bandwidth, and left Uganda’s digital infrastructure dependent on foreign networks. The National IP Peering Exchange (NIPX) is designed to fix this. It is a neutral hub — not controlled by any single company or government entity — where ISPs, content delivery networks, cloud platforms, and government networks can exchange traffic directly, within Uganda’s borders. How Traffic Moved — and How It Moves Now Scenario Origin Route Hub Result Before NIPX Ugandan user → Overseas server High cost, high latency With NIPX Ugandan user → NIPX local hub Fast, affordable, local     “If a person in Uganda needs access to data from institutions such as URA, that data should not have to be routed through Kenya before it can be accessed. With NIPX, access happens directly within Uganda.” — Godfrey Sserwamukoko, Chairperson, Internet Service Providers Association of Uganda (ISPAU)   FOR LOCAL ISPs Six Game-Changing Advantages While NIPX benefits all digital stakeholders, the advantages for Uganda’s local Internet Service Providers are especially profound. 1. Lower Bandwidth Costs ISPs currently pay premium rates for international transit bandwidth. By keeping local traffic local, they eliminate a major line item from their operational costs — savings that can be passed directly to consumers or reinvested in network expansion. 2. Faster Speeds for Customers Shorter data routes mean dramatically lower latency. ISPs can offer genuinely faster, more responsive connections to end users without adding infrastructure. Local traffic that previously bounced through international servers can now resolve in milliseconds. 3. A Level Playing Field NIPX is a neutral, collectively governed platform. No single operator controls access, giving smaller ISPs the same peering opportunities as the largest players. This open governance model is fundamental to the platform’s design. 4. Network Resilience When international subsea cables are cut or disrupted — as happens periodically across East Africa — ISPs relying solely on overseas routing lose service entirely. NIPX ensures domestic services remain accessible regardless of what happens to international links. 5. Local Cloud Hosting Opportunity As local traffic stays local, demand for Uganda-based data centers and cloud hosting grows organically. ISPs who invest in local server infrastructure can capture entirely new revenue streams as companies seek to host content closer to Ugandan users. 6. Foreign Exchange Savings International bandwidth is purchased in hard currency. By reducing dependence on overseas routing, ISPs retain more of their earnings in Uganda shillings, improving financial stability and reducing exposure to exchange rate fluctuations. STRATEGIC CONTEXT Part of a Larger National Vision NIPX does not exist in isolation. It is a strategic deliverable under Uganda’s Digital Transformation Programme 2023–2028 and the broader Digital Uganda Vision, which aims to transform the country into a competitive regional ICT hub. ●       Digital Uganda Vision 2040 launched — Framework established to build a knowledge-based economy anchored in digital infrastructure and innovation. ●       Digital Transformation Programme 2023–2028 — IP peering identified as a key deliverable. NITA-U mandated to develop national peering infrastructure. ●       NIPX announced, April 14, 2026 — NITA-U and Ministry of ICT unveil plans at Uganda Media Centre. Stakeholders briefed on the neutral governance model. ●       Official launch, April 17, 2026 — NIPX goes live at Speke Resort Munyonyo. ISPs, content providers, and government networks invited to connect immediately.   “The NIPX is more than just a technical upgrade; it is a strategic move to position Uganda as a competitive ICT hub in East Africa. The infrastructure is expected to attract investment, support innovation, and boost the development of local digital content.” — Kabbyanga Godfrey Baluku, Minister of State for National Guidance   ACTION What ISPs Should Do Now NITA-U has called on all eligible networks to connect to NIPX and begin peering immediately. The platform’s neutral governance model means participation is open and no single competitor gains an unfair advantage by joining early — quite the opposite. The sooner an ISP connects, the sooner it begins realising cost savings and performance gains that can be passed on to customers. For ISPs who have been watching Uganda’s internet infrastructure mature from the sidelines, NIPX is the clearest signal yet that the country’s digital backbone is being built from the inside out. The question is no longer whether to join — it is how quickly. Uganda’s internet is reclaiming its sovereignty The NIPX is a historic infrastructure milestone. For local ISPs, it is also a commercial opportunity, a competitive advantage, and a chance to be part of the country’s digital future. Connect now at NITA-U.  

May 22, 2026

The Ruijie 6262(G) Gambit: Taking a Risk on Budget Enterprise Wi Fi

Is the Ruijie RG RAP6262(G) Overrated? Here’s Why Some Network Admins Think So The Ruijie RG RAP6262(G) has built a strong reputation as an affordable outdoor Wi Fi 6 access point. On paper, it looks almost too good to ignore. You get Wi Fi 6, mesh support, cloud management, IP68 weather protection, and marketing claims that position it close to enterprise brands at a much lower price. That combination naturally attracts attention from small businesses, installers, and even experienced network admins looking to save money without sacrificing too much performance. But once the excitement fades and these devices are deployed in real environments, opinions become more divided. Some users still love it for the value it offers, while others feel the product is heavily overhyped. So why do some people call the Ruijie RG RAP6262(G) overrated? The Problem Usually Starts With Expectations A big reason for the criticism is that many buyers compare it to premium enterprise access points from brands like Cisco, Aruba, Ruckus, or Ubiquiti. That comparison creates very high expectations. The Ruijie device is often promoted online as a “budget enterprise alternative,” which sounds great until people start using it in demanding environments with lots of clients, VLAN complexity, guest access requirements, roaming expectations, and long term reliability needs. For simple deployments, the AP can work surprisingly well. For larger or more advanced networks, some users discover the experience is not as polished as they hoped. Firmware Updates Have Frustrated Some Users One of the biggest complaints involves firmware consistency. Several users have reported situations where a firmware update actually made performance worse instead of better. In some cases, signal strength appeared weaker after updates. Others experienced instability, random disconnects, or unusual behavior that was not present before upgrading. That creates hesitation among admins who depend on predictable behavior from networking equipment. With more established enterprise vendors, firmware updates are usually heavily tested because businesses expect stability first. When updates introduce inconsistent performance, trust drops quickly. The Hardware Feels Better Than the Software Interestingly, many people do not criticize the hardware itself. The general opinion is that the physical device is solid for the price. Outdoor durability is decent, Wi Fi coverage can be respectable, and setup is relatively easy. The bigger concern tends to be the software ecosystem surrounding the AP. Some users describe the cloud platform as functional but not fully mature. Others mention delayed configuration syncing, guest network bugs, or settings that do not always behave consistently across devices. For home users or small businesses, these issues may not matter much. For professional deployments, however, software reliability matters just as much as radio performance. That is where brands with more mature ecosystems usually maintain an advantage. Some Enterprise Features Feel Limited Another reason people become disappointed is feature depth. The marketing suggests enterprise style flexibility, but certain advanced capabilities are either limited or handled differently than admins expect. Captive portal functionality is one example often mentioned. Some users assume it is built directly into the AP experience, only to later realize there are restrictions or additional requirements involved. This does not necessarily make the product bad. It simply means the device may not fully match the expectations created by the marketing. Support Can Be a Concern Outside Asia Ruijie has a stronger presence in Asian markets, where adoption and support networks are much larger. Outside those regions, some buyers worry about long term firmware support, documentation quality, replacement logistics, and how quickly they could get help during an outage. That uncertainty matters more in professional environments where downtime affects real business operations. A cheaper AP becomes less attractive if troubleshooting takes significantly longer because support resources are limited. Real World Performance Does Not Always Match the Marketing Like many networking products, the specifications sound impressive. Wi Fi 61775 Mbps throughputMesh networkingIP68 weather resistanceSupport for up to 100 users Those numbers look excellent in product listings. The issue is that real deployments are rarely ideal. Heavy client loads, interference, roaming traffic, and advanced VLAN setups can expose limitations that do not appear in lab testing or marketing material. Many admins feel the device performs well for light to medium usage, but not always at the level implied by the hype surrounding it. Why Some People Still Love It Despite the criticism, plenty of users are genuinely happy with the Ruijie RG RAP6262(G). For small businesses, cafes, outdoor spaces, schools, or home installations, the value proposition can still make sense. The device is cheaper than many enterprise competitors. Setup is relatively beginner friendly. Outdoor coverage is decent for the price, and cloud management is approachable for users who do not want complicated controller systems. In the right environment, it can absolutely do the job. So, Is It Actually Overrated? The answer depends on how it is being used. If someone expects premium enterprise reliability at a bargain price, disappointment is more likely. If someone wants affordable outdoor Wi Fi with decent performance and simple management, the AP can be a strong value option. The “overrated” label mostly comes from the gap between marketing hype and real world expectations. The hardware itself is not necessarily bad. In many cases, it is actually quite competitive for the price. The frustration usually appears when people expect it to perform like high end enterprise gear in demanding deployments. That is a difficult standard for any budget networking product to meet.

May 26, 2026

Zero Trust Networking: Why “Never Trust, Always Verify” Matters

For years, Virtual Private Networks (VPNs) were the standard solution for secure remote access. They allowed employees to connect to company networks from outside the office and helped businesses support remote work securely. But the cybersecurity landscape has changed dramatically. Cloud computing, remote work, mobile devices, and increasingly sophisticated cyberattacks have exposed the limitations of traditional network security models. In response, organizations are rapidly adopting a modern approach known as Zero Trust Networking. Unlike traditional security methods that automatically trust users once they’re inside the network, Zero Trust assumes that no user, device, or connection should be trusted by default. Its philosophy is simple: Never trust. Always verify. What Is Zero Trust Networking? Zero Trust Networking is a cybersecurity model that continuously verifies every user, device, application, and request before granting access to company resources. Traditional networks operated like a castle: Strong defenses around the perimeter Open trust once inside This worked when employees mainly worked from office buildings using company-managed devices. But today: Employees work remotely Applications live in the cloud Personal devices access corporate systems Attackers target user identities instead of networks As a result, trusting users simply because they connected to the network is no longer safe. Zero Trust removes that assumption by verifying access continuously and limiting permissions to only what users truly need. What Is a VPN? A VPN, or Virtual Private Network, creates an encrypted connection between a user’s device and a company’s internal network. VPNs are designed to: Protect internet traffic Allow remote access Hide user activity from outside interception Secure communications over public networks When users connect through a VPN, they are often treated as if they are physically inside the company’s office network. This approach was highly effective for many years — but it also introduced a major problem: Once connected, users often gain broad access to internal systems. If attackers steal credentials or compromise a device, they can potentially move throughout the network with fewer restrictions. How Zero Trust Differs from VPNs Zero Trust and VPNs may appear similar because both deal with secure access, but they operate very differently. A VPN focuses on securing the connection. Zero Trust focuses on securing identity, access, and behavior continuously. Zero Trust vs Traditional VPN Feature Zero Trust Networking Traditional VPN Security Model “Never trust, always verify” Trust once connected Access Control Granular, role-based access Broad network access Authentication Continuous verification Usually verified only at login Network Exposure Minimal exposure Larger internal network exposure Remote Work Security Built for modern distributed teams Designed for older perimeter networks Lateral Movement Risk Greatly reduced Higher if compromised Device Verification Frequently enforced Often limited Cloud Compatibility Strong cloud-native integration Less optimized for cloud systems Threat Detection Real-time monitoring and response Basic session monitoring Scalability Flexible and modern Can bottleneck under heavy usage User Experience Direct access to specific resources Full network tunnel access Why Businesses Are Moving Toward Zero Trust Modern cyberattacks no longer focus only on breaking through firewalls. Instead, attackers target: Weak passwords Phishing emails Stolen credentials Unsecured devices Human error Once attackers gain access to a traditional VPN-connected environment, they may move laterally across systems. Zero Trust helps prevent this by: Restricting unnecessary access Continuously validating identities Monitoring behavior in real time Segmenting networks into smaller protected zones This significantly limits how far attackers can go if an account or device becomes compromised. Core Principles of Zero Trust 1. Verify Every User and Device Every access request must be authenticated and validated, regardless of where it originates. This may include: Multi-factor authentication (MFA) Device security checks Identity verification Behavioral analysis 2. Least Privilege Access Users receive access only to the systems and data they need to perform their tasks. This reduces exposure to sensitive resources. 3. Micro-Segmentation Networks are divided into smaller protected sections to prevent attackers from moving freely between systems. 4. Continuous Monitoring Zero Trust systems constantly analyze activity for suspicious behavior, including: Unusual login attempts Unexpected file transfers Abnormal access patterns Unauthorized privilege changes Benefits of Zero Trust Networking Stronger Security Zero Trust minimizes blind trust and reduces attack surfaces. Better Remote Work Support Employees can securely work from anywhere without exposing entire networks. Reduced Breach Impact If attackers gain access, their movement is heavily restricted. Improved Visibility Organizations gain deeper insight into users, devices, and application activity. Better Cloud Security Zero Trust aligns naturally with modern cloud environments and hybrid infrastructures. Challenges of Implementing Zero Trust Although Zero Trust offers major advantages, implementation can be challenging. Organizations may face: Complex infrastructure changes Legacy application compatibility issues Higher upfront investment User resistance to additional verification steps However, many businesses consider these trade-offs worthwhile given the growing threat landscape. Can Zero Trust Replace VPNs Completely? In some cases, yes. Many organizations are adopting Zero Trust Network Access (ZTNA) solutions that provide secure application-level access without exposing the full network. However, VPNs still remain useful for: Legacy systems Certain internal tools Temporary remote access needs Smaller organizations with simpler infrastructures Today, many businesses use a hybrid approach where VPNs coexist with Zero Trust strategies during transition periods. The Future of Cybersecurity Cybersecurity is moving away from perimeter-based security toward identity-based security. As businesses continue embracing: Remote work Cloud computing SaaS applications Mobile devices AI-powered systems Traditional trust-based models become increasingly risky. Zero Trust Networking represents a modern security mindset built for today’s digital environment — one where every access request must earn trust continuously. Final Thoughts VPNs helped shape secure remote work for decades, but modern threats require more adaptive security approaches. Zero Trust Networking offers a smarter framework by: Continuously verifying access Limiting unnecessary permissions Monitoring activity in real time Reducing attacker movement across systems In an era where cyberattacks are becoming more sophisticated every day, trusting nothing by default may be the strongest defense organizations can build.