2026-08-06 10:20:43 +08:00
|
|
|
|
# gw — EdgeRouter X primary LAN gateway
|
|
|
|
|
|
|
|
|
|
|
|
## Role and access
|
|
|
|
|
|
|
|
|
|
|
|
| Item | Value |
|
|
|
|
|
|
|---|---|
|
|
|
|
|
|
| Role | Primary router for the `192.168.66.0/24` and `192.168.55.0/24` LANs |
|
|
|
|
|
|
| IPv4 | `192.168.66.254` |
|
|
|
|
|
|
| Verified hostname | `gw` |
|
|
|
|
|
|
| SSH | `ssh -4 zhiqiang@192.168.66.254` |
|
|
|
|
|
|
| Platform | Ubiquiti EdgeRouter X 5-Port, EdgeOS `v3.0.1` (Build `5862409`) |
|
|
|
|
|
|
| Kernel | `4.14.54-UBNT` |
|
|
|
|
|
|
| Time zone | `Asia/Shanghai` |
|
|
|
|
|
|
|
|
|
|
|
|
Use `zhiqiang` as the default account for all routine gateway operations. Its
|
|
|
|
|
|
key-only SSH login and passwordless `sudo` were verified on 2026-08-04; use
|
|
|
|
|
|
`BatchMode=yes` for unattended read-only checks. `ubnt` remains an existing
|
|
|
|
|
|
administrative account, but is not the routine operations entry point.
|
|
|
|
|
|
|
|
|
|
|
|
Do not store account passwords, PPPoE credentials, SSH keys, configuration
|
|
|
|
|
|
password hashes, or UISP/UNMS connection strings in this repository. Both
|
|
|
|
|
|
administrative accounts have EdgeOS configuration and sudo privileges. Verify a
|
|
|
|
|
|
new SSH host key out of band before accepting it.
|
|
|
|
|
|
|
|
|
|
|
|
## Network topology
|
|
|
|
|
|
|
|
|
|
|
|
| Interface | Address / role |
|
|
|
|
|
|
|---|---|
|
|
|
|
|
|
| `eth0` | `192.168.66.254/24`; LAN 66 |
|
|
|
|
|
|
| `switch0` (`eth1`–`eth3`) | `192.168.55.254/24`; LAN 55 |
|
|
|
|
|
|
| `eth4` | WAN physical port; PPPoE uplink |
|
|
|
|
|
|
| `pppoe0` | WAN default route; MTU `1492`; IPv6 prefix delegation `/60` |
|
|
|
|
|
|
|
|
|
|
|
|
IPv6 prefix delegation assigns SLAAC-capable `/64` networks to both LANs.
|
|
|
|
|
|
`eth4` applies the WAN IPv4 and IPv6 firewall policies.
|
|
|
|
|
|
|
2026-08-22 10:44:20 +08:00
|
|
|
|
**SE5420 single-uplink topology (verified 2026-08-22):** the TP-Link `TL-SE5420`
|
|
|
|
|
|
core switch is deployed — management `192.168.66.253` (TP-Link OUI `f8:c9:03`,
|
|
|
|
|
|
web UI on :80/:443). The LAN55 uplink into `switch0` is a **single member
|
|
|
|
|
|
port**: `eth1` link up, `eth2`/`eth3` down. All LAN55 wired devices (hass
|
|
|
|
|
|
`.11`, Aqara M3 `.248`, SmartThings `.48`, UAP-AC-Lite `.5`) are reached via
|
|
|
|
|
|
`switch0` behind that one uplink, so same-segment wired↔wired unicast is
|
|
|
|
|
|
switched locally on the SE5420 and never reaches the ER-X. The switch FDB is
|
|
|
|
|
|
hardware-offloaded and not readable from the ER-X (`brctl showmacs switch0` →
|
|
|
|
|
|
"Operation not supported"; `show mac-address-table` / `show ethernet-switch`
|
|
|
|
|
|
are not available on this EdgeOS build) — port link state (`show interfaces
|
|
|
|
|
|
ethernet`) plus ARP are the reliable topology checks.
|
|
|
|
|
|
|
2026-08-06 10:20:43 +08:00
|
|
|
|
Detailed effective configuration, including firewall binding and WAN exposure,
|
|
|
|
|
|
is recorded in [the EdgeRouter X configuration record](../docs/edgerouter-x-configuration.md).
|
|
|
|
|
|
|
|
|
|
|
|
## Services and policy
|
|
|
|
|
|
|
|
|
|
|
|
- DHCP serves both LANs with 24-hour leases. Client DNS is `192.168.66.36`.
|
|
|
|
|
|
Pools are `.38`–`.243` on both networks; selected infrastructure and client
|
|
|
|
|
|
addresses have static mappings. The UniFi controller is advertised as
|
|
|
|
|
|
`192.168.66.46`.
|
|
|
|
|
|
- DNS forwarding listens on `eth0` and `switch0` with a cache size of 512.
|
|
|
|
|
|
- WAN NAT masquerades all IPv4 traffic leaving `pppoe0`.
|
|
|
|
|
|
- `WAN_IN` and `WAN_LOCAL` default to drop, permitting established/related
|
|
|
|
|
|
sessions and rejecting invalid state. Equivalent IPv6 policies permit
|
|
|
|
|
|
necessary ICMPv6 and DHCPv6 traffic.
|
|
|
|
|
|
- `LAN_IN` defines a default drop plus explicit `55 → 66` and `66 → 55`
|
|
|
|
|
|
allows, but it is **not currently applied to an interface**. The active
|
|
|
|
|
|
inter-VLAN posture is therefore ordinary routed access: LAN55 and LAN66 can
|
|
|
|
|
|
communicate bidirectionally unless a different active policy intervenes.
|
|
|
|
|
|
`LAN_OUT` is likewise defined but inactive; WAN policies are active on
|
|
|
|
|
|
`pppoe0`.
|
|
|
|
|
|
- Management services: SSH on TCP 22; EdgeOS GUI on HTTP 80 and HTTPS 443.
|
|
|
|
|
|
|
|
|
|
|
|
## Safe inspection
|
|
|
|
|
|
|
|
|
|
|
|
Use the EdgeOS operational CLI for routine inspection. `show configuration
|
|
|
|
|
|
commands` can expose credentials and remote-management tokens, so either avoid
|
|
|
|
|
|
copying it or filter sensitive lines before recording output.
|
|
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
|
ssh -4 -o BatchMode=yes zhiqiang@192.168.66.254
|
|
|
|
|
|
show version
|
|
|
|
|
|
show interfaces
|
|
|
|
|
|
show ip route
|
|
|
|
|
|
show system uptime
|
|
|
|
|
|
show firewall
|
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
The [official EdgeOS User Guide](https://dl.ubnt.com/guides/edgemax/EdgeOS_UG.pdf)
|
|
|
|
|
|
explains that a firewall policy is a ruleset and must be applied to the
|
|
|
|
|
|
relevant interface/direction to take effect. Use the operational `show
|
|
|
|
|
|
firewall` output—not merely the configured rule definitions—to determine the
|
|
|
|
|
|
effective policy.
|
|
|
|
|
|
|
2026-08-14 16:26:23 +08:00
|
|
|
|
## PPPoE redial
|
|
|
|
|
|
|
|
|
|
|
|
To force the `pppoe0` session to reconnect (e.g. to obtain a fresh WAN IP), use
|
|
|
|
|
|
the operational `disconnect` / `connect` commands — **not** `renew dhcp
|
|
|
|
|
|
interface`, which applies only to DHCP interfaces:
|
|
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
|
ssh -4 zhiqiang@192.168.66.254
|
|
|
|
|
|
/opt/vyatta/bin/vyatta-op-cmd-wrapper disconnect interface pppoe0
|
|
|
|
|
|
/opt/vyatta/bin/vyatta-op-cmd-wrapper connect interface pppoe0
|
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
`disconnect` tears down the PPP session; `connect` re-dials immediately. A
|
|
|
|
|
|
short pause between them (a few seconds, or minutes for cautious ISPs) lets the
|
|
|
|
|
|
old session finish teardown before redialing. This briefly drops the whole WAN
|
|
|
|
|
|
uplink and may change the public IPv4 and delegated IPv6 `/60`; in-flight
|
|
|
|
|
|
sessions and port-forwarded services are interrupted until the new session is
|
|
|
|
|
|
up.
|
|
|
|
|
|
|
|
|
|
|
|
The `zhiqiang` account logs into `vbash`, not the EdgeOS CLI, so operational
|
|
|
|
|
|
commands must be invoked through `/opt/vyatta/bin/vyatta-op-cmd-wrapper` and
|
|
|
|
|
|
depend on its passwordless `sudo`. The `ubnt` account lands directly in the
|
|
|
|
|
|
operational CLI, where the same commands are entered without the wrapper.
|
2026-08-22 10:44:20 +08:00
|
|
|
|
`show`/`configure` are interactive-only aliases (from
|
|
|
|
|
|
`/etc/bash_completion.d/vyatta-{op,cfg}`, loaded via `~/.bashrc`), so a
|
|
|
|
|
|
non-interactive `ssh ubnt@… 'show …'` also fails — from a script use the op
|
|
|
|
|
|
wrapper above, or `_vyatta_op_run` after sourcing `vyatta-op` with
|
|
|
|
|
|
`vyatta_op_templates=/opt/vyatta/share/vyatta-op/templates`.
|
2026-08-14 16:26:23 +08:00
|
|
|
|
|
2026-08-06 10:20:43 +08:00
|
|
|
|
## Maintenance notes
|
|
|
|
|
|
|
|
|
|
|
|
- EdgeOS writes persistent changes through its configuration tree: enter
|
|
|
|
|
|
`configure`, make the intended change, then run `commit` and `save`.
|
|
|
|
|
|
- The current SSH service reported a non-post-quantum key-exchange warning.
|
|
|
|
|
|
Treat any cryptography or SSH-policy maintenance as a planned, lockout-safe
|
|
|
|
|
|
change following the repository SSH safety procedure.
|
|
|
|
|
|
- This device is distinct from `gfw.windy.lan` (`192.168.66.1`), the OpenWrt
|
|
|
|
|
|
OpenClash gateway. Do not apply OpenWrt procedures to this router.
|
|
|
|
|
|
|
|
|
|
|
|
## Verification record
|
|
|
|
|
|
|
|
|
|
|
|
Configuration and reachability were checked by read-only SSH on 2026-08-04.
|
|
|
|
|
|
No network policy changes were made during that inspection. The `zhiqiang`
|
|
|
|
|
|
account password was subsequently rotated using the EdgeOS configuration tree
|
|
|
|
|
|
and verified by a separate SSH login; the password is intentionally not
|
|
|
|
|
|
recorded here.
|
|
|
|
|
|
|
|
|
|
|
|
Inter-VLAN access was rechecked by read-only SSH on 2026-08-05. A probe sourced
|
|
|
|
|
|
from `192.168.55.254` reached the UniFi controller at `192.168.66.46` with
|
|
|
|
|
|
3/3 ICMP replies. This supports the AP Inform path to
|
|
|
|
|
|
`192.168.66.46:9080`; the controller listener and an online LAN55 AP provide
|
|
|
|
|
|
the corresponding application-level evidence. No firewall changes were made.
|
2026-08-21 08:57:53 +08:00
|
|
|
|
|
|
|
|
|
|
IPv6 was re-verified by read-only SSH on 2026-08-20 during the UniFi AP/AC
|
|
|
|
|
|
check: the IPv6 routing table shows connected `/64`s on `eth0` (LAN66) and
|
|
|
|
|
|
`switch0` (LAN55) plus `::/0` via `pppoe0`; both UniFi APs obtained SLAAC
|
|
|
|
|
|
addresses from the router's RAs. No configuration changes were made.
|
2026-08-22 08:18:23 +08:00
|
|
|
|
|
2026-08-23 11:06:35 +08:00
|
|
|
|
**DHCP 保留 `matter` 失效(2026-08-21 发现,2026-08-23 复核仍未生效,W1N-207):**
|
|
|
|
|
|
静态映射 `matter` → .45 / MAC `34:98:7a:27:10:bc`,但该灯泡一直以**动态租约**拿
|
|
|
|
|
|
`.148`(hostname `matter`;2026-08-23 09:02 时租约当日 04:40 已续租)。保留 .45 从未
|
|
|
|
|
|
被租出。2026-08-23 复核补充:另一盏工作灯泡的 MAC 已变为 `fc:e8:c0:25:a1:f0`
|
|
|
|
|
|
(动态 `.146`,hostname `espressif`),原「把 MAC 改为 `34:98:7a:27:7f:08`」的修正
|
|
|
|
|
|
建议已过时(该灯泡已离网)。处置:删除该保留,或按现用 MAC(`.148` 的
|
|
|
|
|
|
`34:98:7a:27:10:bc` / `.146` 的 `fc:e8:c0:25:a1:f0`)重建,**未执行**。
|
2026-08-22 10:44:20 +08:00
|
|
|
|
|
|
|
|
|
|
**SE5420 部署 + switch0 单上联(2026-08-22 只读核实):** `switch0` 成员口
|
|
|
|
|
|
`eth1` link up、`eth2`/`eth3` down(单上联);SE5420 管理面 `192.168.66.253`
|
|
|
|
|
|
在线(TP-Link OUI `f8:c9:03`,:80/:443);ARP 显示 LAN55 主机(hass `.11`、
|
|
|
|
|
|
M3 `.248`、SmartThings `.48`、UAP-AC-Lite `.5`)全部经 switch0 可达。含义:
|
|
|
|
|
|
`switch0` 不再是 LAN55 的全量抓包点(同段有线单播在 SE5420 本地交换),详见
|
|
|
|
|
|
[runbooks/matter-packet-capture.md](../runbooks/matter-packet-capture.md)。
|