The fibre surprise

The new place in cottage country came with a surprise. Bracebridge, Ontario is Muskoka lake country — the kind of place where you assume the internet arrives by DSL, by cellular modem, or by prayer, and I had mentally budgeted for misery. Instead, the place has 2.5-gigabit symmetric fibre. Fibre with an -re, because that’s how Canada spells it, which I’ve decided is the right way. Full multi-gig upload, in the woods, surrounded by loons. I went through bafflement and suspicion and landed on ecstatic in the span of one speed test.

What the upload was for

Because I had plans for that upload. The cottage was going to be a full node on the same private network as everything else we run — the Florida house, the servers, my laptop wherever it happens to be. That’s the deal I’ve built the whole setup around: every machine can reach every other machine directly, over Tailscale, no matter which country it’s sitting in. The cottage has a small computer that runs its smart home, and it’s slated to carry more — an exit node, and eventually a full clone of the home server, which means terabytes of replication flowing north. A symmetric multi-gig line makes all of that trivial. On paper.

The Bell fiber box was quietly wrecking that plan.

The bufferbloat detour

What actually sent me into the network’s guts was bufferbloat — the thing where a connection is blisteringly fast on a speed test and then someone uploads a video and every other device’s latency goes to the moon. Under load I measured round-trip times spiking to 2.8 seconds. I chased it the textbook way, putting a CAKE traffic shaper on the router, and the shaper dutifully fixed the number — 2.8 seconds down to 284 milliseconds — while also throttling my 2.4-gigabit upload to 75 megabits, which is like curing a headache with a guillotine. I reverted it. The real culprit turned out to be Wi-Fi saturation, not the fiber line at all. But by then I was deep enough in the plumbing to find the sin that actually mattered.

Bell’s unit is one of those all-in-one boxes: modem, router, Wi-Fi, one glossy shell. I run my own UniFi router behind it, which means two routers stacked, each doing its own network address translation — double NAT. Most people never notice double NAT, because for ordinary outbound life it’s harmless. Netflix works. Speed tests are full rate. Nothing looks wrong.

Tailscale notices. The way two machines on a private mesh connect directly is by hole-punching — both sides open a path through their routers at once and meet in the middle. One layer of NAT, fine. Two layers, and the punching gets unreliable: connections to the cottage couldn’t consistently make it through, and when hole-punching fails, Tailscale does the graceful thing and falls back to its relay servers — DERP, in their vocabulary. Your traffic still arrives, encrypted, but it’s taking a detour through a relay instead of flowing machine-to-machine, with the latency and throughput ceiling that implies. Fine for checking a thermostat. Not fine for pushing a server’s worth of data north on a schedule. Inbound port-forwards, meanwhile, just break — there’s no forwarding through a box you don’t control.

The maddening part was the inconsistency. Some days the connection punched through direct and fast, and I have the note to prove it. Some days it relayed. A link that’s direct by luck is worse than one that’s reliably slow, because you can’t build on it — every future plan for that site inherited an asterisk.

No bridge mode

Any grown-up router has a bridge mode — a setting that tells the ISP’s box to step aside, pass the connection through untouched, and let your own equipment run the show. It’s the polite, supported, five-minute fix for double NAT, and it’s what I fully expected to click on the day I found it. Bell’s firmware has no such setting. Not hidden, not unsupported — absent. I checked thoroughly, and the emotional register here went the opposite direction from the fibre discovery: a line this good, terminated in a box this stubborn, felt less like a limitation and more like an insult. So the only way to kill the double NAT was to retire the Bell box entirely, and the replacement is absurd when you say it out loud: a WAS-110, a fiber modem the size of a stick of gum that slots into the SFP+ port on my own router. You configure it to introduce itself to Bell’s network using the same identity as the box it’s replacing, move the fiber over, and your router does the PPPoE login to Bell directly. This is the part every forum thread treats as the dark art — the impersonation, the login handshake, the “you’ll need three weekends and a soldering iron” part. My guide for it was KTZ Systems’ walkthrough of the same stick on AT&T fiber — a different ISP on a different continent’s worth of network policy, but the technique is the technique, and having someone narrate it end-to-end mattered more than the details matching.

The cutover

It worked on the first try. The stick registered on Bell’s network within seconds of the fiber going in. I want that on the record, because nothing else in the next four hours went that well.

What ate the time was two of the most boring problems in networking. First: traffic to Bell has to carry a specific VLAN tag, and either the stick or the router can apply it — but exactly one of them, and I had configured the pair so that neither did. My login requests were leaving the router and evaporating. From the outside this looked identical to a deep fiber-layer failure, so I spent forty-five minutes diagnosing the part that was working perfectly. One checkbox fixed it.

Second: the PPPoE credentials themselves. Bell knows your username and password. Bell’s box logs in with them every day. But Bell has no interest in you having them, because the only reason to want them is to do exactly what I was doing. I went into the cutover with a username inferred from patterns and a password I had reason to believe was current, and Bell’s network disagreed, politely and repeatedly, while I burned cutover cycles permuting guesses like someone trying an old locker combination on a new locker. Actually extracting the real credentials meant going through Bell — a headache of exactly the flavor you’d expect for a request the phone tree has no button for. That should have been step zero, done from the couch, days before the fiber ever moved. Instead it became the wall I hit mid-cutover, because asking felt like a formality and guessing felt like momentum.

Neither of those took the house offline. I did that myself. Every failed attempt, I moved the fiber back to the Bell box so the household had internet, then back to the stick for the next try — maybe five swaps in an hour. Bell’s street-side equipment has protections against exactly that kind of flapping, and somewhere around swap four it stopped trusting either device. The household spent about an hour with no internet, during which I learned my router’s admin login depends on a cloud service it could no longer reach. I finished the diagnosis over a neighbor’s Wi-Fi, which is a humbling place to run a network migration from.

Attempt four: correct tag, real credentials, first handshake. The router now holds a genuine public address, the double NAT is gone, and connections to the cottage go direct — no relay, no asterisk. The site went from “reachable, mostly, with caveats” to a full citizen of the network, which is what the replication plan was waiting on.

The stick runs hot

One lesson arrived after the victory lap: the stick runs hot. Bare in the router’s port it was hitting 83 °C — technically within spec, spiritually on fire. A little spot fan brought it to 68, and a proper rack exhaust fan is the real fix, ordered approximately the moment I saw the first temperature reading. This matters more than comfort: the stick sits unattended for months while we’re in Florida, and my remote access to the cottage rides the very link the stick provides. A heat death isn’t a degraded service, it’s the drawbridge burning down — no internet at the site and no way in to fix it. So the stick now reports its own temperature and alerts me before it cooks. If you do this bypass, budget for airflow on day one. The gum stick is a tiny computer doing hard optical work in a metal slot with no ventilation, and nobody mentions that part in the forums.

The lesson I keep relearning, in a new costume each time: I prepare hard for the part that looks hard, and it repays the preparation by just working. The failures come from the facts I skip confirming because they feel beneath the occasion — a tag direction, a password. And the only real damage came from refusing to sit still for fifteen minutes. The fiber network forgives a careful cutover. It does not forgive fidgeting.