4.5 KiB
gw — EdgeRouter X primary LAN gateway
Role and access
| Item | Value |
|---|---|
| Role | Primary router for the 192.168.66.0/24 and 192.168.55.0/24 LANs |
| IPv4 | 192.168.66.254 |
| Verified hostname | gw |
| SSH | ssh -4 zhiqiang@192.168.66.254 |
| Platform | Ubiquiti EdgeRouter X 5-Port, EdgeOS v3.0.1 (Build 5862409) |
| Kernel | 4.14.54-UBNT |
| Time zone | Asia/Shanghai |
Use zhiqiang as the default account for all routine gateway operations. Its
key-only SSH login and passwordless sudo were verified on 2026-08-04; use
BatchMode=yes for unattended read-only checks. ubnt remains an existing
administrative account, but is not the routine operations entry point.
Do not store account passwords, PPPoE credentials, SSH keys, configuration password hashes, or UISP/UNMS connection strings in this repository. Both administrative accounts have EdgeOS configuration and sudo privileges. Verify a new SSH host key out of band before accepting it.
Network topology
| Interface | Address / role |
|---|---|
eth0 |
192.168.66.254/24; LAN 66 |
switch0 (eth1–eth3) |
192.168.55.254/24; LAN 55 |
eth4 |
WAN physical port; PPPoE uplink |
pppoe0 |
WAN default route; MTU 1492; IPv6 prefix delegation /60 |
IPv6 prefix delegation assigns SLAAC-capable /64 networks to both LANs.
eth4 applies the WAN IPv4 and IPv6 firewall policies.
Detailed effective configuration, including firewall binding and WAN exposure, is recorded in the EdgeRouter X configuration record.
Services and policy
- DHCP serves both LANs with 24-hour leases. Client DNS is
192.168.66.36. Pools are.38–.243on both networks; selected infrastructure and client addresses have static mappings. The UniFi controller is advertised as192.168.66.46. - DNS forwarding listens on
eth0andswitch0with a cache size of 512. - WAN NAT masquerades all IPv4 traffic leaving
pppoe0. WAN_INandWAN_LOCALdefault to drop, permitting established/related sessions and rejecting invalid state. Equivalent IPv6 policies permit necessary ICMPv6 and DHCPv6 traffic.LAN_INdefines a default drop plus explicit55 → 66and66 → 55allows, but it is not currently applied to an interface. The active inter-VLAN posture is therefore ordinary routed access: LAN55 and LAN66 can communicate bidirectionally unless a different active policy intervenes.LAN_OUTis likewise defined but inactive; WAN policies are active onpppoe0.- Management services: SSH on TCP 22; EdgeOS GUI on HTTP 80 and HTTPS 443.
Safe inspection
Use the EdgeOS operational CLI for routine inspection. show configuration commands can expose credentials and remote-management tokens, so either avoid
copying it or filter sensitive lines before recording output.
ssh -4 -o BatchMode=yes zhiqiang@192.168.66.254
show version
show interfaces
show ip route
show system uptime
show firewall
The official EdgeOS User Guide
explains that a firewall policy is a ruleset and must be applied to the
relevant interface/direction to take effect. Use the operational show firewall output—not merely the configured rule definitions—to determine the
effective policy.
Maintenance notes
- EdgeOS writes persistent changes through its configuration tree: enter
configure, make the intended change, then runcommitandsave. - The current SSH service reported a non-post-quantum key-exchange warning. Treat any cryptography or SSH-policy maintenance as a planned, lockout-safe change following the repository SSH safety procedure.
- This device is distinct from
gfw.windy.lan(192.168.66.1), the OpenWrt OpenClash gateway. Do not apply OpenWrt procedures to this router.
Verification record
Configuration and reachability were checked by read-only SSH on 2026-08-04.
No network policy changes were made during that inspection. The zhiqiang
account password was subsequently rotated using the EdgeOS configuration tree
and verified by a separate SSH login; the password is intentionally not
recorded here.
Inter-VLAN access was rechecked by read-only SSH on 2026-08-05. A probe sourced
from 192.168.55.254 reached the UniFi controller at 192.168.66.46 with
3/3 ICMP replies. This supports the AP Inform path to
192.168.66.46:9080; the controller listener and an online LAN55 AP provide
the corresponding application-level evidence. No firewall changes were made.