Files
vps/hosts/gw.md
T

4.5 KiB
Raw Blame History

gw — EdgeRouter X primary LAN gateway

Role and access

Item Value
Role Primary router for the 192.168.66.0/24 and 192.168.55.0/24 LANs
IPv4 192.168.66.254
Verified hostname gw
SSH ssh -4 zhiqiang@192.168.66.254
Platform Ubiquiti EdgeRouter X 5-Port, EdgeOS v3.0.1 (Build 5862409)
Kernel 4.14.54-UBNT
Time zone Asia/Shanghai

Use zhiqiang as the default account for all routine gateway operations. Its key-only SSH login and passwordless sudo were verified on 2026-08-04; use BatchMode=yes for unattended read-only checks. ubnt remains an existing administrative account, but is not the routine operations entry point.

Do not store account passwords, PPPoE credentials, SSH keys, configuration password hashes, or UISP/UNMS connection strings in this repository. Both administrative accounts have EdgeOS configuration and sudo privileges. Verify a new SSH host key out of band before accepting it.

Network topology

Interface Address / role
eth0 192.168.66.254/24; LAN 66
switch0 (eth1eth3) 192.168.55.254/24; LAN 55
eth4 WAN physical port; PPPoE uplink
pppoe0 WAN default route; MTU 1492; IPv6 prefix delegation /60

IPv6 prefix delegation assigns SLAAC-capable /64 networks to both LANs. eth4 applies the WAN IPv4 and IPv6 firewall policies.

Detailed effective configuration, including firewall binding and WAN exposure, is recorded in the EdgeRouter X configuration record.

Services and policy

  • DHCP serves both LANs with 24-hour leases. Client DNS is 192.168.66.36. Pools are .38.243 on both networks; selected infrastructure and client addresses have static mappings. The UniFi controller is advertised as 192.168.66.46.
  • DNS forwarding listens on eth0 and switch0 with a cache size of 512.
  • WAN NAT masquerades all IPv4 traffic leaving pppoe0.
  • WAN_IN and WAN_LOCAL default to drop, permitting established/related sessions and rejecting invalid state. Equivalent IPv6 policies permit necessary ICMPv6 and DHCPv6 traffic.
  • LAN_IN defines a default drop plus explicit 55 → 66 and 66 → 55 allows, but it is not currently applied to an interface. The active inter-VLAN posture is therefore ordinary routed access: LAN55 and LAN66 can communicate bidirectionally unless a different active policy intervenes. LAN_OUT is likewise defined but inactive; WAN policies are active on pppoe0.
  • Management services: SSH on TCP 22; EdgeOS GUI on HTTP 80 and HTTPS 443.

Safe inspection

Use the EdgeOS operational CLI for routine inspection. show configuration commands can expose credentials and remote-management tokens, so either avoid copying it or filter sensitive lines before recording output.

ssh -4 -o BatchMode=yes zhiqiang@192.168.66.254
show version
show interfaces
show ip route
show system uptime
show firewall

The official EdgeOS User Guide explains that a firewall policy is a ruleset and must be applied to the relevant interface/direction to take effect. Use the operational show firewall output—not merely the configured rule definitions—to determine the effective policy.

Maintenance notes

  • EdgeOS writes persistent changes through its configuration tree: enter configure, make the intended change, then run commit and save.
  • The current SSH service reported a non-post-quantum key-exchange warning. Treat any cryptography or SSH-policy maintenance as a planned, lockout-safe change following the repository SSH safety procedure.
  • This device is distinct from gfw.windy.lan (192.168.66.1), the OpenWrt OpenClash gateway. Do not apply OpenWrt procedures to this router.

Verification record

Configuration and reachability were checked by read-only SSH on 2026-08-04. No network policy changes were made during that inspection. The zhiqiang account password was subsequently rotated using the EdgeOS configuration tree and verified by a separate SSH login; the password is intentionally not recorded here.

Inter-VLAN access was rechecked by read-only SSH on 2026-08-05. A probe sourced from 192.168.55.254 reached the UniFi controller at 192.168.66.46 with 3/3 ICMP replies. This supports the AP Inform path to 192.168.66.46:9080; the controller listener and an online LAN55 AP provide the corresponding application-level evidence. No firewall changes were made.