docs: verify gw switch0 as limited capture point — SE5420 single-uplink (eth1 up, eth2/3 down), LAN55 wired hosts behind SE5420; record EdgeOS 3 CLI/access quirks (W1N-207)

This commit is contained in:
windyboy
2026-08-22 10:44:20 +08:00
parent 6b298491a8
commit aaa4ee312e
3 changed files with 67 additions and 27 deletions
+4 -2
View File
@@ -41,8 +41,10 @@ from each section below.
``` ```
> **SE5420 live (2026-08-22):** TP-Link `TL-SE5420` (purchased 2026-08-09) is > **SE5420 live (2026-08-22):** TP-Link `TL-SE5420` (purchased 2026-08-09) is
> online — management `192.168.66.253` reachable, web UI on :80/:443 (verified > online — management `192.168.66.253` reachable, web UI on :80/:443; LAN55
> 2026-08-22); migration status per the deployment plan > 上联为 ER-X `switch0` **单口**`eth1` up、`eth2`/`eth3` down2026-08-22
> 只读核实)→ `switch0` 不再是 LAN55 全量抓包点(同段有线单播在 SE5420 本地
> 交换),全量点只能靠 SE5420 port mirroring。迁移状态见部署计划
> [lan-se5420-deployment-guide.md](lan-se5420-deployment-guide.md). Design/planning refs: > [lan-se5420-deployment-guide.md](lan-se5420-deployment-guide.md). Design/planning refs:
> [lan-erx-se5420-network.md](lan-erx-se5420-network.md), > [lan-erx-se5420-network.md](lan-erx-se5420-network.md),
> [lan-core-switch-upgrade-plan.md](lan-core-switch-upgrade-plan.md). > [lan-core-switch-upgrade-plan.md](lan-core-switch-upgrade-plan.md).
+24
View File
@@ -34,6 +34,18 @@ new SSH host key out of band before accepting it.
IPv6 prefix delegation assigns SLAAC-capable `/64` networks to both LANs. IPv6 prefix delegation assigns SLAAC-capable `/64` networks to both LANs.
`eth4` applies the WAN IPv4 and IPv6 firewall policies. `eth4` applies the WAN IPv4 and IPv6 firewall policies.
**SE5420 single-uplink topology (verified 2026-08-22):** the TP-Link `TL-SE5420`
core switch is deployed — management `192.168.66.253` (TP-Link OUI `f8:c9:03`,
web UI on :80/:443). The LAN55 uplink into `switch0` is a **single member
port**: `eth1` link up, `eth2`/`eth3` down. All LAN55 wired devices (hass
`.11`, Aqara M3 `.248`, SmartThings `.48`, UAP-AC-Lite `.5`) are reached via
`switch0` behind that one uplink, so same-segment wired↔wired unicast is
switched locally on the SE5420 and never reaches the ER-X. The switch FDB is
hardware-offloaded and not readable from the ER-X (`brctl showmacs switch0`
"Operation not supported"; `show mac-address-table` / `show ethernet-switch`
are not available on this EdgeOS build) — port link state (`show interfaces
ethernet`) plus ARP are the reliable topology checks.
Detailed effective configuration, including firewall binding and WAN exposure, Detailed effective configuration, including firewall binding and WAN exposure,
is recorded in [the EdgeRouter X configuration record](../docs/edgerouter-x-configuration.md). is recorded in [the EdgeRouter X configuration record](../docs/edgerouter-x-configuration.md).
@@ -100,6 +112,11 @@ The `zhiqiang` account logs into `vbash`, not the EdgeOS CLI, so operational
commands must be invoked through `/opt/vyatta/bin/vyatta-op-cmd-wrapper` and commands must be invoked through `/opt/vyatta/bin/vyatta-op-cmd-wrapper` and
depend on its passwordless `sudo`. The `ubnt` account lands directly in the depend on its passwordless `sudo`. The `ubnt` account lands directly in the
operational CLI, where the same commands are entered without the wrapper. operational CLI, where the same commands are entered without the wrapper.
`show`/`configure` are interactive-only aliases (from
`/etc/bash_completion.d/vyatta-{op,cfg}`, loaded via `~/.bashrc`), so a
non-interactive `ssh ubnt@… 'show …'` also fails — from a script use the op
wrapper above, or `_vyatta_op_run` after sourcing `vyatta-op` with
`vyatta_op_templates=/opt/vyatta/share/vyatta-op/templates`.
## Maintenance notes ## Maintenance notes
@@ -135,3 +152,10 @@ addresses from the router's RAs. No configuration changes were made.
`34:98:7a:27:7f:08`(动态租约 .145hostname `matter`)。保留 .45 从未被租出。 `34:98:7a:27:7f:08`(动态租约 .145hostname `matter`)。保留 .45 从未被租出。
修正需在 `service dhcp-server shared-network-name LAN2 ... static-mapping matter` 修正需在 `service dhcp-server shared-network-name LAN2 ... static-mapping matter`
里把 MAC 改为 `34:98:7a:27:7f:08`(或删除该保留),**未执行**。 里把 MAC 改为 `34:98:7a:27:7f:08`(或删除该保留),**未执行**。
**SE5420 部署 + switch0 单上联(2026-08-22 只读核实):** `switch0` 成员口
`eth1` link up、`eth2`/`eth3` down(单上联);SE5420 管理面 `192.168.66.253`
在线(TP-Link OUI `f8:c9:03`:80/:443);ARP 显示 LAN55 主机(hass `.11`
M3 `.248`、SmartThings `.48`、UAP-AC-Lite `.5`)全部经 switch0 可达。含义:
`switch0` 不再是 LAN55 的全量抓包点(同段有线单播在 SE5420 本地交换),详见
[runbooks/matter-packet-capture.md](../runbooks/matter-packet-capture.md)。
+39 -25
View File
@@ -36,9 +36,9 @@ capture on hass `end0`. Use the AP `br0` point for wireless-device or
phone-driven flows (a wireless client's unicast to/from its AP is only visible phone-driven flows (a wireless client's unicast to/from its AP is only visible
there). there).
A third candidate point, `gw` `switch0`, is topology-dependent and is **not yet A third point, `gw` `switch0`, is **verified as a limited capture point**
a documented capture point** — see (cross-subnet/gateway/mDNS flows only — not a full mirror of LAN55) — see
[Conditional capture point: gw switch0](#conditional-capture-point-gw-switch0). [Capture point: gw switch0](#capture-point-gw-switch0).
## Ownership ## Ownership
@@ -248,33 +248,47 @@ ssh zhiqiangf@192.168.55.5 "tcpdump -ni br0 -s 0 -C 5 -W 12 -w /tmp/matter-\$(da
For the hass point, prefix the same commands with For the hass point, prefix the same commands with
`ssh hassio@hass.windy.lan "sudo -n -i tcpdump -ni end0 …"`. `ssh hassio@hass.windy.lan "sudo -n -i tcpdump -ni end0 …"`.
## Conditional capture point: gw switch0 ## Capture point: gw switch0
**Status: NOT yet a documented capture point.** Its coverage depends on the **Status: verified 2026-08-22 — limited capture point; NOT a full mirror of
live topology; verify before relying on it. LAN55.**
- `gw` `switch0` (`eth1``eth3`, `192.168.55.254/24`) is LAN55's L2 aggregation - `gw` `switch0` (`eth1``eth3`, `192.168.55.254/24`) is LAN55's L2 aggregation
point only while devices plug directly into the ER-X. EdgeOS ships tcpdump, only while devices plug directly into the ER-X. EdgeOS ships tcpdump;
and `tcpdump -ni switch0` follows Linux bridge semantics. `tcpdump -ni switch0` follows Linux bridge semantics.
- **Live state (verified 2026-08-22): the SE5420 core switch is deployed** - **Live topology (verified 2026-08-22): the SE5420 core switch is deployed**
(management `192.168.66.253` reachable; TP-Link "Web Switch" on :80/:443). (management `192.168.66.253` up — TP-Link OUI `f8:c9:03`, web UI on
With the flat-VLAN55 single-uplink design, same-segment traffic switches :80/:443) and the ER-X uplink is a **single switch0 member port**: `eth1`
locally on the SE5420 and never reaches `switch0`. In that state `switch0` link up, `eth2`/`eth3` down. All LAN55 wired devices (hass `.11`, Aqara M3
sees only: cross-subnet (66↔55) unicast, gateway-bound traffic, and LAN55 `.248`, SmartThings `.48`, UAP-AC-Lite `.5`) are reached via `switch0`
mDNS multicast (flooded) — **not a full mirror**. The full-mirror point behind that one uplink. Same-segment wired↔wired unicast switches locally on
becomes the SE5420 itself, which cannot run tcpdump (port mirroring only). the SE5420 and never reaches `switch0`.
- **Before using this point**, run these read-only checks from a machine with - **What `switch0` still sees:** cross-subnet (66↔55) unicast, traffic to/from
gw SSH access: the gateway itself (DHCP, DNS forwarding, port-forwards), and LAN55 mDNS
multicast (flooded up the uplink). Use it only for those flows; for a full
commissioning conversation use the hass `end0` or AP `br0` point instead.
- **Full mirror:** only via SE5420 port mirroring (the switch cannot run
tcpdump). Not configured; out of scope here.
- **Verification commands (EdgeOS v3.0.1 build 5862409):**
- Interactive: `ssh ubnt@192.168.66.254` (or `zhiqiang`), then
`show interfaces ethernet` — port link states are the decisive check
(`eth1` up + `eth2`/`eth3` down = single uplink). `configure` (config
mode) also accepts `show ...`.
- Non-interactive (agent/script): `show`/`configure` are interactive-only
aliases on this build; use the op wrapper:
```bash
ssh ubnt@192.168.66.254 '/opt/vyatta/bin/vyatta-op-cmd-wrapper show interfaces ethernet'
```
- `show ethernet-switch port all` and `show mac-address-table` are NOT
available on this build; the switch FDB is hardware-offloaded
(`brctl showmacs switch0` → "Operation not supported"). Port link state
+ ARP (`show arp`) are the reliable checks.
- SE5420 liveness: `ping 192.168.66.253` and `:80/:443`.
- Sample capture at this point (cross-segment/gateway/mDNS flows only;
tcpdump needs root — `zhiqiang` has passwordless sudo):
```bash ```bash
ssh -4 zhiqiang@192.168.66.254 'show interfaces ethernet' # which switch0 member ports have link ssh zhiqiang@192.168.66.254 "sudo -n tcpdump -ni switch0 -s 0 'udp port 5353 or tcp port 5540 or tcp port 5552'"
ssh -4 zhiqiang@192.168.66.254 'show ethernet-switch port all' # per-port MAC table
ssh -4 zhiqiang@192.168.66.254 'show mac-address-table' # where LAN55 wired devices land
``` ```
- LAN55 wired devices all on a single member port → single uplink confirmed;
`tcpdump -ni switch0 …` is then valid with the limited coverage above.
- Devices spread across `eth1``eth3` → SE5420 not in the LAN55 path;
`switch0` is the full mirror point.
- Until one of these is confirmed, do not treat `switch0` as a capture point.
## Pass criteria ## Pass criteria