diff --git a/docs/lan-overview.md b/docs/lan-overview.md index e9edf8c..035199b 100644 --- a/docs/lan-overview.md +++ b/docs/lan-overview.md @@ -41,8 +41,10 @@ from each section below. ``` > **SE5420 live (2026-08-22):** TP-Link `TL-SE5420` (purchased 2026-08-09) is -> online — management `192.168.66.253` reachable, web UI on :80/:443 (verified -> 2026-08-22); migration status per the deployment plan +> online — management `192.168.66.253` reachable, web UI on :80/:443; LAN55 +> 上联为 ER-X `switch0` **单口**(`eth1` up、`eth2`/`eth3` down,2026-08-22 +> 只读核实)→ `switch0` 不再是 LAN55 全量抓包点(同段有线单播在 SE5420 本地 +> 交换),全量点只能靠 SE5420 port mirroring。迁移状态见部署计划 > [lan-se5420-deployment-guide.md](lan-se5420-deployment-guide.md). Design/planning refs: > [lan-erx-se5420-network.md](lan-erx-se5420-network.md), > [lan-core-switch-upgrade-plan.md](lan-core-switch-upgrade-plan.md). diff --git a/hosts/gw.md b/hosts/gw.md index 9291523..1c67da5 100644 --- a/hosts/gw.md +++ b/hosts/gw.md @@ -34,6 +34,18 @@ new SSH host key out of band before accepting it. IPv6 prefix delegation assigns SLAAC-capable `/64` networks to both LANs. `eth4` applies the WAN IPv4 and IPv6 firewall policies. +**SE5420 single-uplink topology (verified 2026-08-22):** the TP-Link `TL-SE5420` +core switch is deployed — management `192.168.66.253` (TP-Link OUI `f8:c9:03`, +web UI on :80/:443). The LAN55 uplink into `switch0` is a **single member +port**: `eth1` link up, `eth2`/`eth3` down. All LAN55 wired devices (hass +`.11`, Aqara M3 `.248`, SmartThings `.48`, UAP-AC-Lite `.5`) are reached via +`switch0` behind that one uplink, so same-segment wired↔wired unicast is +switched locally on the SE5420 and never reaches the ER-X. The switch FDB is +hardware-offloaded and not readable from the ER-X (`brctl showmacs switch0` → +"Operation not supported"; `show mac-address-table` / `show ethernet-switch` +are not available on this EdgeOS build) — port link state (`show interfaces +ethernet`) plus ARP are the reliable topology checks. + Detailed effective configuration, including firewall binding and WAN exposure, is recorded in [the EdgeRouter X configuration record](../docs/edgerouter-x-configuration.md). @@ -100,6 +112,11 @@ The `zhiqiang` account logs into `vbash`, not the EdgeOS CLI, so operational commands must be invoked through `/opt/vyatta/bin/vyatta-op-cmd-wrapper` and depend on its passwordless `sudo`. The `ubnt` account lands directly in the operational CLI, where the same commands are entered without the wrapper. +`show`/`configure` are interactive-only aliases (from +`/etc/bash_completion.d/vyatta-{op,cfg}`, loaded via `~/.bashrc`), so a +non-interactive `ssh ubnt@… 'show …'` also fails — from a script use the op +wrapper above, or `_vyatta_op_run` after sourcing `vyatta-op` with +`vyatta_op_templates=/opt/vyatta/share/vyatta-op/templates`. ## Maintenance notes @@ -135,3 +152,10 @@ addresses from the router's RAs. No configuration changes were made. `34:98:7a:27:7f:08`(动态租约 .145,hostname `matter`)。保留 .45 从未被租出。 修正需在 `service dhcp-server shared-network-name LAN2 ... static-mapping matter` 里把 MAC 改为 `34:98:7a:27:7f:08`(或删除该保留),**未执行**。 + +**SE5420 部署 + switch0 单上联(2026-08-22 只读核实):** `switch0` 成员口 +`eth1` link up、`eth2`/`eth3` down(单上联);SE5420 管理面 `192.168.66.253` +在线(TP-Link OUI `f8:c9:03`,:80/:443);ARP 显示 LAN55 主机(hass `.11`、 +M3 `.248`、SmartThings `.48`、UAP-AC-Lite `.5`)全部经 switch0 可达。含义: +`switch0` 不再是 LAN55 的全量抓包点(同段有线单播在 SE5420 本地交换),详见 +[runbooks/matter-packet-capture.md](../runbooks/matter-packet-capture.md)。 diff --git a/runbooks/matter-packet-capture.md b/runbooks/matter-packet-capture.md index 801ba22..003ae28 100644 --- a/runbooks/matter-packet-capture.md +++ b/runbooks/matter-packet-capture.md @@ -36,9 +36,9 @@ capture on hass `end0`. Use the AP `br0` point for wireless-device or phone-driven flows (a wireless client's unicast to/from its AP is only visible there). -A third candidate point, `gw` `switch0`, is topology-dependent and is **not yet -a documented capture point** — see -[Conditional capture point: gw switch0](#conditional-capture-point-gw-switch0). +A third point, `gw` `switch0`, is **verified as a limited capture point** +(cross-subnet/gateway/mDNS flows only — not a full mirror of LAN55) — see +[Capture point: gw switch0](#capture-point-gw-switch0). ## Ownership @@ -248,33 +248,47 @@ ssh zhiqiangf@192.168.55.5 "tcpdump -ni br0 -s 0 -C 5 -W 12 -w /tmp/matter-\$(da For the hass point, prefix the same commands with `ssh hassio@hass.windy.lan "sudo -n -i tcpdump -ni end0 …"`. -## Conditional capture point: gw switch0 +## Capture point: gw switch0 -**Status: NOT yet a documented capture point.** Its coverage depends on the -live topology; verify before relying on it. +**Status: verified 2026-08-22 — limited capture point; NOT a full mirror of +LAN55.** - `gw` `switch0` (`eth1`–`eth3`, `192.168.55.254/24`) is LAN55's L2 aggregation - point only while devices plug directly into the ER-X. EdgeOS ships tcpdump, - and `tcpdump -ni switch0` follows Linux bridge semantics. -- **Live state (verified 2026-08-22): the SE5420 core switch is deployed** - (management `192.168.66.253` reachable; TP-Link "Web Switch" on :80/:443). - With the flat-VLAN55 single-uplink design, same-segment traffic switches - locally on the SE5420 and never reaches `switch0`. In that state `switch0` - sees only: cross-subnet (66↔55) unicast, gateway-bound traffic, and LAN55 - mDNS multicast (flooded) — **not a full mirror**. The full-mirror point - becomes the SE5420 itself, which cannot run tcpdump (port mirroring only). -- **Before using this point**, run these read-only checks from a machine with - gw SSH access: + only while devices plug directly into the ER-X. EdgeOS ships tcpdump; + `tcpdump -ni switch0` follows Linux bridge semantics. +- **Live topology (verified 2026-08-22): the SE5420 core switch is deployed** + (management `192.168.66.253` up — TP-Link OUI `f8:c9:03`, web UI on + :80/:443) and the ER-X uplink is a **single switch0 member port**: `eth1` + link up, `eth2`/`eth3` down. All LAN55 wired devices (hass `.11`, Aqara M3 + `.248`, SmartThings `.48`, UAP-AC-Lite `.5`) are reached via `switch0` + behind that one uplink. Same-segment wired↔wired unicast switches locally on + the SE5420 and never reaches `switch0`. +- **What `switch0` still sees:** cross-subnet (66↔55) unicast, traffic to/from + the gateway itself (DHCP, DNS forwarding, port-forwards), and LAN55 mDNS + multicast (flooded up the uplink). Use it only for those flows; for a full + commissioning conversation use the hass `end0` or AP `br0` point instead. +- **Full mirror:** only via SE5420 port mirroring (the switch cannot run + tcpdump). Not configured; out of scope here. +- **Verification commands (EdgeOS v3.0.1 build 5862409):** + - Interactive: `ssh ubnt@192.168.66.254` (or `zhiqiang`), then + `show interfaces ethernet` — port link states are the decisive check + (`eth1` up + `eth2`/`eth3` down = single uplink). `configure` (config + mode) also accepts `show ...`. + - Non-interactive (agent/script): `show`/`configure` are interactive-only + aliases on this build; use the op wrapper: + ```bash + ssh ubnt@192.168.66.254 '/opt/vyatta/bin/vyatta-op-cmd-wrapper show interfaces ethernet' + ``` + - `show ethernet-switch port all` and `show mac-address-table` are NOT + available on this build; the switch FDB is hardware-offloaded + (`brctl showmacs switch0` → "Operation not supported"). Port link state + + ARP (`show arp`) are the reliable checks. + - SE5420 liveness: `ping 192.168.66.253` and `:80/:443`. +- Sample capture at this point (cross-segment/gateway/mDNS flows only; + tcpdump needs root — `zhiqiang` has passwordless sudo): ```bash - ssh -4 zhiqiang@192.168.66.254 'show interfaces ethernet' # which switch0 member ports have link - ssh -4 zhiqiang@192.168.66.254 'show ethernet-switch port all' # per-port MAC table - ssh -4 zhiqiang@192.168.66.254 'show mac-address-table' # where LAN55 wired devices land + ssh zhiqiang@192.168.66.254 "sudo -n tcpdump -ni switch0 -s 0 'udp port 5353 or tcp port 5540 or tcp port 5552'" ``` - - LAN55 wired devices all on a single member port → single uplink confirmed; - `tcpdump -ni switch0 …` is then valid with the limited coverage above. - - Devices spread across `eth1`–`eth3` → SE5420 not in the LAN55 path; - `switch0` is the full mirror point. - - Until one of these is confirmed, do not treat `switch0` as a capture point. ## Pass criteria