121 lines
5.2 KiB
Markdown
121 lines
5.2 KiB
Markdown
# EdgeRouter X configuration record
|
||
|
||
This is a read-only, sanitized configuration record for
|
||
[gw](../hosts/gw.md), taken on 2026-08-05. It intentionally excludes PPPoE
|
||
credentials, user/password configuration, key material, and full DHCP client
|
||
or reservation inventories.
|
||
|
||
## Platform and topology
|
||
|
||
| Item | Current configuration |
|
||
|---|---|
|
||
| Appliance / OS | EdgeRouter X 5-Port; EdgeOS `v3.0.1` build `5862409` |
|
||
| WAN physical interface | `eth4`, described as `Internet (PPPoE)` |
|
||
| WAN routed interface | `pppoe0`; dynamic IPv4 default route; MTU `1492` |
|
||
| LAN66 | `eth0`, `192.168.66.254/24` |
|
||
| LAN55 | `switch0`, `192.168.55.254/24`; member ports `eth1`–`eth3` |
|
||
| IPv4 routing | Both LAN prefixes are directly connected; default route is through `pppoe0` |
|
||
|
||
Despite its name, LAN55 is not currently an 802.1Q VLAN configuration:
|
||
`switch0` has `vlan-aware` disabled. It is a separate Layer-3 subnet carried
|
||
by the built-in switch ports, while LAN66 is connected through `eth0`.
|
||
|
||
## IPv6
|
||
|
||
The PPPoE uplink requests a delegated `/60`, enables rapid commit and assigns
|
||
SLAAC-capable `/64` networks to the LANs:
|
||
|
||
| Interface | Delegated prefix slot | Router address suffix |
|
||
|---|---|---|
|
||
| `eth0` (LAN66) | `:1` | `::1` |
|
||
| `switch0` (LAN55) | `:2` | `::1` |
|
||
|
||
IPv6 has a default route through `pppoe0`. The currently delegated prefixes
|
||
are dynamic and are deliberately not treated as persistent configuration
|
||
facts.
|
||
|
||
## Effective firewall policy
|
||
|
||
| Ruleset | Direction / attachment | Effective policy |
|
||
|---|---|---|
|
||
| `WAN_IN` | `pppoe0`, IPv4 `in` | Active; default drop; permits established/related, drops invalid |
|
||
| `WAN_LOCAL` | `pppoe0`, IPv4 `local` | Active; default drop; permits established/related, drops invalid |
|
||
| `WANv6_IN` | `pppoe0`, IPv6 `in` | Active; default drop; permits established/related and ICMPv6; drops invalid |
|
||
| `WANv6_LOCAL` | `pppoe0`, IPv6 `local` | Active; default drop; permits established/related, ICMPv6, and DHCPv6 replies; drops invalid |
|
||
| `LAN_IN` | None | Inactive; configured default drop with explicit LAN55 ↔ LAN66 allows |
|
||
| `LAN_OUT` | None | Inactive; configured default drop with an Internet allow |
|
||
|
||
Therefore, LAN55 and LAN66 currently have ordinary bidirectional routed
|
||
access. The configured `LAN_IN`/`LAN_OUT` rules do **not** enforce an access
|
||
boundary because neither is bound to an interface. From source
|
||
`192.168.55.254`, the controller at `192.168.66.46` replied to 3/3 ICMP probes
|
||
on 2026-08-05. The online LAN55 AP also confirms the operational Inform path
|
||
to `192.168.66.46:9080`.
|
||
|
||
Global firewall settings enable normal ICMP echo replies, disable broadcast
|
||
ping and IPv4/IPv6 source routing, enable SYN cookies and martian logging, set
|
||
an MSS clamp of `1412`, and leave source validation disabled. Receive redirects
|
||
are disabled; IPv4 send redirects remain enabled.
|
||
|
||
The [official EdgeOS User Guide](https://dl.ubnt.com/guides/edgemax/EdgeOS_UG.pdf)
|
||
describes the distinction: a firewall policy is a ruleset that must be applied
|
||
to its target interface and direction before it affects traffic.
|
||
|
||
## NAT and inbound exposure
|
||
|
||
IPv4 traffic leaving `pppoe0` is covered by NAT masquerade rule `5010`.
|
||
Port-forward auto-firewall and hairpin NAT are enabled. The configured WAN
|
||
forwards are below; their external reachability was not tested in this review.
|
||
|
||
| WAN protocol / port | Internal destination | Purpose |
|
||
|---|---|---|
|
||
| TCP/UDP `8123` | `192.168.55.11:8123` | Home Assistant |
|
||
| TCP/UDP `51413` | `192.168.66.51:51413` | Transmission |
|
||
| TCP/UDP `5822` | `192.168.66.36:22` | SSH forward |
|
||
| TCP/UDP `1194` | `192.168.66.32:1194` | OpenVPN |
|
||
|
||
Treat every forward as an intentional public attack surface. Changes require
|
||
the normal firewall/change review and external verification from a trusted
|
||
network.
|
||
|
||
## LAN services
|
||
|
||
| Service | LAN66 | LAN55 |
|
||
|---|---|---|
|
||
| DHCP pool | `.38`–`.243` | `.38`–`.243` |
|
||
| Default gateway | `.254` | `.254` |
|
||
| DNS server handed out | `192.168.66.36` | `192.168.66.36` |
|
||
| Lease duration | 24 hours | 24 hours |
|
||
| UniFi Controller DHCP option | `192.168.66.46` | `192.168.66.46` |
|
||
|
||
DNS forwarding listens on `eth0` and `switch0` with a cache size of `512`.
|
||
Management services are SSH/TCP `22`, HTTP/TCP `80`, and HTTPS/TCP `443`.
|
||
Since no active LAN-local firewall is documented, treat access to this gateway
|
||
management plane from either LAN as permitted unless verified otherwise.
|
||
|
||
Infrastructure devices, including the two APs and the UniFi controller, have
|
||
DHCP static mappings. Keep the authoritative full mapping list only in the
|
||
gateway configuration; do not copy unrelated household device inventories into
|
||
this operations repository.
|
||
|
||
## Acceleration and maintenance implications
|
||
|
||
At verification time, `show ubnt offload` reported that both IPSec and HWNAT
|
||
offload modules were not loaded. No `system offload` enablement was present in
|
||
the inspected configuration. This may constrain routing/NAT throughput under
|
||
load; it is an observation, not authorization to alter the router.
|
||
|
||
Use these safe effective-state checks after any planned change:
|
||
|
||
```bash
|
||
show interfaces
|
||
show ip route
|
||
show ipv6 route
|
||
show firewall
|
||
show nat rules
|
||
show ubnt offload
|
||
```
|
||
|
||
Avoid recording raw `show configuration commands` output: it includes PPPoE
|
||
credentials and may include other secrets.
|