# gw — EdgeRouter X primary LAN gateway ## Role and access | Item | Value | |---|---| | Role | Primary router for the `192.168.66.0/24` and `192.168.55.0/24` LANs | | IPv4 | `192.168.66.254` | | Verified hostname | `gw` | | SSH | `ssh -4 zhiqiang@192.168.66.254` | | Platform | Ubiquiti EdgeRouter X 5-Port, EdgeOS `v3.0.1` (Build `5862409`) | | Kernel | `4.14.54-UBNT` | | Time zone | `Asia/Shanghai` | Use `zhiqiang` as the default account for all routine gateway operations. Its key-only SSH login and passwordless `sudo` were verified on 2026-08-04; use `BatchMode=yes` for unattended read-only checks. `ubnt` remains an existing administrative account, but is not the routine operations entry point. Do not store account passwords, PPPoE credentials, SSH keys, configuration password hashes, or UISP/UNMS connection strings in this repository. Both administrative accounts have EdgeOS configuration and sudo privileges. Verify a new SSH host key out of band before accepting it. ## Network topology | Interface | Address / role | |---|---| | `eth0` | `192.168.66.254/24`; LAN 66 | | `switch0` (`eth1`–`eth3`) | `192.168.55.254/24`; LAN 55 | | `eth4` | WAN physical port; PPPoE uplink | | `pppoe0` | WAN default route; MTU `1492`; IPv6 prefix delegation `/60` | IPv6 prefix delegation assigns SLAAC-capable `/64` networks to both LANs. `eth4` applies the WAN IPv4 and IPv6 firewall policies. Detailed effective configuration, including firewall binding and WAN exposure, is recorded in [the EdgeRouter X configuration record](../docs/edgerouter-x-configuration.md). ## Services and policy - DHCP serves both LANs with 24-hour leases. Client DNS is `192.168.66.36`. Pools are `.38`–`.243` on both networks; selected infrastructure and client addresses have static mappings. The UniFi controller is advertised as `192.168.66.46`. - DNS forwarding listens on `eth0` and `switch0` with a cache size of 512. - WAN NAT masquerades all IPv4 traffic leaving `pppoe0`. - `WAN_IN` and `WAN_LOCAL` default to drop, permitting established/related sessions and rejecting invalid state. Equivalent IPv6 policies permit necessary ICMPv6 and DHCPv6 traffic. - `LAN_IN` defines a default drop plus explicit `55 → 66` and `66 → 55` allows, but it is **not currently applied to an interface**. The active inter-VLAN posture is therefore ordinary routed access: LAN55 and LAN66 can communicate bidirectionally unless a different active policy intervenes. `LAN_OUT` is likewise defined but inactive; WAN policies are active on `pppoe0`. - Management services: SSH on TCP 22; EdgeOS GUI on HTTP 80 and HTTPS 443. ## Safe inspection Use the EdgeOS operational CLI for routine inspection. `show configuration commands` can expose credentials and remote-management tokens, so either avoid copying it or filter sensitive lines before recording output. ```bash ssh -4 -o BatchMode=yes zhiqiang@192.168.66.254 show version show interfaces show ip route show system uptime show firewall ``` The [official EdgeOS User Guide](https://dl.ubnt.com/guides/edgemax/EdgeOS_UG.pdf) explains that a firewall policy is a ruleset and must be applied to the relevant interface/direction to take effect. Use the operational `show firewall` output—not merely the configured rule definitions—to determine the effective policy. ## Maintenance notes - EdgeOS writes persistent changes through its configuration tree: enter `configure`, make the intended change, then run `commit` and `save`. - The current SSH service reported a non-post-quantum key-exchange warning. Treat any cryptography or SSH-policy maintenance as a planned, lockout-safe change following the repository SSH safety procedure. - This device is distinct from `gfw.windy.lan` (`192.168.66.1`), the OpenWrt OpenClash gateway. Do not apply OpenWrt procedures to this router. ## Verification record Configuration and reachability were checked by read-only SSH on 2026-08-04. No network policy changes were made during that inspection. The `zhiqiang` account password was subsequently rotated using the EdgeOS configuration tree and verified by a separate SSH login; the password is intentionally not recorded here. Inter-VLAN access was rechecked by read-only SSH on 2026-08-05. A probe sourced from `192.168.55.254` reached the UniFi controller at `192.168.66.46` with 3/3 ICMP replies. This supports the AP Inform path to `192.168.66.46:9080`; the controller listener and an online LAN55 AP provide the corresponding application-level evidence. No firewall changes were made.