Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Pages: 1 2 3 [4]

Author Topic: Ubiquiti Edgerouter X  (Read 10656 times)

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #45 on: May 18, 2018, 10:06:52 PM »

As it stands you do not have any VLAN's created. I feel that with the desired setup that you described, you should only need to create 1 VLAN for your guest network for the 192.168.2.x range. In my setup that I described, it's a little more complex as I'm planning to add a VLAN aware switch into the mix for additional ports around the home.

Go ahead and create 1 VLAN for the 192.168.2.x range. Then in the Actions > Config menu for "switch0" check the VLAN Aware option and only check the box for eth4 leaving the other ports un-checked. Then in "vid" enter the VLAN ID number that you used for the 192.168.2.x VLAN. Leave "pvid" blank.


i tried this, and it totally borked the edgerouter, complete loss of all network connectivity.
had to factory reset it. didn't have a backup of the config so had to rebuild.

i've now created a back file so can try again, but maybe the suggested method won't work?



the point it failed was when i did

Quote
Then in the Actions > Config menu for "switch0" check the VLAN Aware option and only check the box for eth4 leaving the other ports un-checked. Then in "vid" enter the VLAN ID number that you used for the 192.168.2.x VLAN. Leave "pvid" blank.
« Last Edit: May 18, 2018, 10:41:43 PM by chenks »
Logged

MrMike

  • Member
  • **
  • Posts: 41
Re: Ubiquiti Edgerouter X
« Reply #46 on: May 20, 2018, 11:05:11 PM »

Apologies, I didn't see that you updated your last post with more information. Are you still unable to get it working, or did you have success?
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #47 on: May 21, 2018, 08:16:08 AM »

i haven't re-attempted yet.
it's currently sitting as the previous post.
the "guest" VLAN has been created but i haven't attempted to turn VLAN aware on, as that's where it went wrong last time.
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #48 on: June 05, 2018, 08:17:07 PM »

well i finally managed to get the 2 LAN setup working
main LAN 192.168.1.x, VLAN for guest wifi 192.168.2.x
all devices getting the correct IP for the network they are connected to.

haven't attempted setting the firewall yet so that anything on 192.168.2.x is totally device isolated.
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #49 on: June 07, 2018, 11:22:02 AM »

As posted previously, this guide takes you through creating the firewall rules to block users on the guest Wi-Fi (in my case VLAN ID 10), from accessing other VLAN's - https://help.ubnt.com/hc/en-us/articles/115012700967-EdgeRouter-VLAN-Aware-Switch0-with-Inter-VLAN-Firewall-Limiting

My main firewall rules page once done - https://i.imgur.com/r1500I6.png

@MrMike i've pretty much got this going now.
could you show me a screengrab of the 1 rule in BLOCK_LAN_IN and the 3 rules in BLOCK_LAN_LOCAL ?
so i can compare with mine?
Logged

MrMike

  • Member
  • **
  • Posts: 41
Re: Ubiquiti Edgerouter X
« Reply #50 on: June 07, 2018, 04:00:26 PM »

I have included all relevant screens in the image below. The "Allow ICMP" rule was added because one of my devices were complaining it couldn't ping the router, so it's not a mandatory requirement.

https://i.imgur.com/LNajWiY.jpg
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #51 on: June 07, 2018, 04:08:27 PM »

yeah i might allow ICMP as a default as you never know later on when something might not like it being disabled.
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #52 on: June 07, 2018, 04:27:00 PM »

ah ok, i was 90% there, but is the Firewall/Nat Group i didn't have.
i'm not sure which IP address i'm supposed to put in there.

in the Allow ICMP rule, i put the 192.168.2.x variant (as opposed to 192.168.1.x), as 2.x is the IP range of the VLAN that is being restricted.
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #53 on: June 07, 2018, 08:05:34 PM »

i worked out the firewall group.
i used 192.168.0.0/16 as all my local LANs are in the 192.168.1.x range.

so that seems like the local LAN side of things is now all working as required.
192.168.1.x full local LAN access and internet
192.168.2.x fully isolated LAN and internet

now i'm going to look at the OpenVPN server side of things.
Logged

MrMike

  • Member
  • **
  • Posts: 41
Re: Ubiquiti Edgerouter X
« Reply #54 on: June 08, 2018, 06:58:15 PM »

Good to hear that you're all up and running on the VLAN side of things. Be sure to take a config backup to make restoring nice and straight forward in the case of an emergency.

I've got a dedicated OpenVPN server on my network, so no need to run it on the EdgeRouter itself. But the videos I linked earlier in this thread should get you up and running.
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Ubiquiti Edgerouter X
« Reply #55 on: June 08, 2018, 07:03:25 PM »

yeah i've got two backup (1 LAN config & VLAN config).

yeah i've got a pi zero running just OpenVPN, but if i can get that on the Edgerouter then it's one less thing to need powered up :)
Logged
Pages: 1 2 3 [4]
 

anything