Quantcast
Channel: EdgeRouter topics
Viewing all 20028 articles
Browse latest View live

Invalid login after 1.9.7 update

$
0
0

Hi All,

 

Just updated my ERLite from 1.9.1.1 to 1.9.7. Works great, network came right back up after reboot, including my IPv6 config.

 

There's only one small issue... my login is no longer recognized by the GUI nor via SSH. The default ubnt/ubnt doesn't work either. Is this any sort of a known issue, preferably with a workaround?

 

I'll do a factory reset if necessary but in a fit of carelessness I didn't backup my config first, and I've made changes since the last backup.

 

Thanks,

Allen


L2TP VPN can't reach remote IP's

$
0
0

I just got a ER-X and setup L2TP.  I can connect to the VPN and reach the routers web page.  I cannot ping the other devices on the remote network.  I've never owned one of these routers before so I don't know what to provide for someone to help me.

IPv6 ATT Uverse - ER-X

$
0
0

I've been trying to get IPv6 to work with and 5268AC with the ER-X set in DMZ+. I've managed to get an Ipv6 assigned to the ER-X and can ping out from CLI to IPv6. Has anyone had any luck getting IPv6 working?

 

show interfaces:

Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface    IP Address                        S/L  Description                 
---------    ----------                        ---  -----------                 
eth0         99.111.XXX.XXX/23                 u/u  Internet                    
             2602:306:36fd:8720:822a:XXXX:XXX:XXX/64
eth1         -                                 u/u  Local                       
eth2         -                                 u/D  Local                       
eth3         -                                 u/u  Local                       
eth4         -                                 u/u  WiFi                        
lo           127.0.0.1/8                       u/u                              
             ::1/128                          
switch0      10.2.13.1/24                      u/u  Local                       
switch0.200  10.2.15.1/24                      u/u  IoT                         
switch0.300  10.2.16.1/24                      u/u  Guest   
Firewall Rules                           
-------------------------------------------------------------------------------- IPv6 Firewall "WANv6_IN": Active on (eth0,IN) rule action proto packets bytes ---- ------ ----- ------- ----- 10 accept all 0 0 condition - state RELATED,ESTABLISHED 20 drop all 0 0 condition - state INVALID 10000 drop all 0 0 condition - LOG enabled -------------------------------------------------------------------------------- IPv6 Firewall "WANv6_LOCAL": Active on (eth0,LOCAL) rule action proto packets bytes ---- ------ ----- ------- ----- 10 accept all 5 520 condition - state RELATED,ESTABLISHED 20 drop all 0 0 condition - state INVALID 30 accept ipv6-icmp 114 11192 40 accept udp 0 0 condition - udp spt:dhcpv6-server dpt:dhcpv6-client 10000 drop all 69 12076 condition - LOG enabled
show interfaces switch switch0: 

address 10.2.13.1/24 description Local ipv6 { address { autoconf } router-advert { cur-hop-limit 64 link-mtu 0 managed-flag false max-interval 600 other-config-flag false reachable-time 0 retrans-timer 0 send-advert true } } mtu 1500 switch-port { interface eth1 { } interface eth2 { } interface eth3 { } interface eth4 { vlan { vid 200 vid 300 } } vlan-aware enable } vif 200 { address 10.2.15.1/24 description IoT mtu 1500 } vif 300 { address 10.2.16.1/24 description Guest mtu 1500 }

ER-Pro not reachable via IPv4 | v1.9.7 | nf_conntrack: table full, dropping packet

$
0
0

Hey Guys,

 

today i did a

 

iptables --list -vn
iptables --list -vn -t nat

 

That commands loaded serval modules like nf_conntrack_ipv4, nf_nat_ipv4, xt_tcpudp, iptable_filter and so on.

 

After a few hours, my router was not reachable anymore via IPv4. Ping did not response and i were not able to ssh to the device via IPv4. So i tried to ping / ssh via IPv6 and that was full funtional. After issue "dmesg" on that host i got this results:

 

Aug  6 23:02:56 at-sbg-itz-tz-k10-r10-bgp02 kernel: nf_conntrack: table full, dropping packet
Aug  6 23:03:02 at-sbg-itz-tz-k10-r10-bgp02 kernel: last message repeated 9 times
Aug  6 23:03:02 at-sbg-itz-tz-k10-r10-bgp02 kernel: net_ratelimit: 2950 callbacks suppressed
Aug  6 23:03:02 at-sbg-itz-tz-k10-r10-bgp02 kernel: nf_conntrack: table full, dropping packet
Aug  6 23:03:07 at-sbg-itz-tz-k10-r10-bgp02 kernel: last message repeated 9 times
Aug  6 23:03:07 at-sbg-itz-tz-k10-r10-bgp02 kernel: net_ratelimit: 3352 callbacks suppressed
Aug  6 23:03:07 at-sbg-itz-tz-k10-r10-bgp02 kernel: nf_conntrack: table full, dropping packet
Aug  6 23:03:12 at-sbg-itz-tz-k10-r10-bgp02 kernel: last message repeated 9 times
Aug  6 23:03:12 at-sbg-itz-tz-k10-r10-bgp02 kernel: net_ratelimit: 3105 callbacks suppressed
Aug  6 23:03:12 at-sbg-itz-tz-k10-r10-bgp02 kernel: nf_conntrack: table full, dropping packet
Aug  6 23:03:17 at-sbg-itz-tz-k10-r10-bgp02 kernel: last message repeated 9 times
Aug  6 23:03:17 at-sbg-itz-tz-k10-r10-bgp02 kernel: net_ratelimit: 3079 callbacks suppressed
Aug  6 23:03:17 at-sbg-itz-tz-k10-r10-bgp02 kernel: nf_conntrack: table full, dropping packet

i run "lsmod" and begun to remove nf_* modules. After removing all modules with nf_* router was back on IPv4 and routing was functional.

 

So guys, is that a issue ubnt should work on, or did i hit some limits?

 

Kill your router by issueing "iptables"-Command is a little bit crazy.

 

"Batch" block inter vlan

$
0
0

Hi everyone,

I am looking for a way to block inter vlan communication.

I have a lot of VLAN

Mainly it's

1 : Management

2 : No Auth

3 : Printer

4 : Security

5 : Server

11 thru 30 : Zone 1, 2, 3, etc.

 

11 thru 30 need be isolated from each other and 1,2,4,5 but they need to communicate to the 3 which is shared printer.

Is there an easy way to configure this with something like group?

 

Regards,

iLevac

Connecting ER-X SFP to TRENDnet TEG-S51SFP Switch

$
0
0

I'm trying to connect a TRENDnet TEG-S51SFP switch to my Edgerouter ER-X SFP via their SFP slots.

 

The Edgerouter reports that the SFP port is up as follows:

 

Port eth5
Enabled
Link: up
1000/full
PoE: not supported
Vendor: 10Gtek
Part:  ASF85-24-X2-D
Temp:  41.109 C
Tx/Rx Power:  0.20 mW /0.15 mW

 

The TRENDnet switch reports that its SFP port is active, as well (i.e., the indicator light is green).

 

The problem is that when I connect my laptop to the TRENDnet switch, it can't see the Edgerouter (at 192.168.1.1) and takes a self-assigned IP address (e.g., 169.254.167.57) and is unable to get to the Internet.

 

By the way, if I connect the TRENDnet switch to my network via one of its ethernet port, it works fine.

 

Am I missing a setting, or am I seeing some sort of SFP incompatibility?

Disallow access of random devices in our corporate ethernet interface/ports

$
0
0

I need to be able to lock all of our ethernet interface/ports in our office to only recognize the devices that have been approved for use in our company (desktops, printers, scanners). Is there a way to do this? I can filter the MAC address but is this sufficient?

 

 

I have a Edgerouter and Edgeswitch with VLANS (Guest, Corporate, Phone, Management). Firewalls are set such that access and communication between VLAN devices is not allowed unless your in the Management VLAN.

 

I am fairly new with networking, VLANS, firewalls rules... so any help would be greatly appreaciated.

EDGE Router Lite 3 Port migration to Ubiquiti USG-Pro

$
0
0

 

 Hi

Im doing a little background work before buying the Ubiquiti USG-PRO 4

I own a Edge Router Lite 3 port and would like without having to manually create all the firewall rules migrate over the settings, is it possible to export them via CLI on the Edge Router and inport them into the Ubiquiti USG-Pro?

Thanks
 

 

 


EdgeRouter X crash and reboot

$
0
0

Just had my EdgeRouter X crash and reboot on me.  I was able to jump on the console and saw this:

 

INFO: task init:1 blocked for more than 120 seconds.
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
Kernel panic - not syncing: hung_task: blocked tasks
Rebooting in 60 seconds..
*** NMI Watchdog interrupt on Core 0x01 ***
        $0      0x0000000000000000      at      0x0000000010108ce0
        v0      0x0002ab7d9d113638      v1      0xffffffffc0690000
        a0      0x000000000007a120      a1      0x00000000000001f4
        a2      0x0002ab7d9d18d758      a3      0x0000000000000001
        a4      0x0002ab7d9d155acf      a5      0x0000000000000001
        a6      0x800000000178e9e8      a7      0xffffffffc07c0000
        t0      0x00000000a0000000      t1      0xffffffffc07c0000
        t2      0x000000000000003c      t3      0x000000000000ea60
        s0      0x00000000000023f0      s1      0x0000000000000055
        s2      0x00000000000024b8      s3      0x0000000000000001
        s4      0xffffffffc07b0000      s5      0x00000000000003e8
        s6      0xffffffffc07b0000      s7      0x00000000003fffff
        t8      0x0000000000000001      t9      0xffffffffc07c0000
        k0      0x0000000000000000      k1      0x0000000000000011
        gp      0x800000041c328000      sp      0x800000041c32bcc0
        s8      0xffffffffc0590000      ra      0xffffffffc04ee104
        err_epc 0xffffffffc00079d8      epc     0xffffffffc00a42b0
        status  0x0000000010588ce4      cause   0x0000000040808c00
        sum0    0x000000f100000000      en0     0x0000000100000000
*** Chip soft reset soon ***

Looking for valid bootloader image....
Jumping to start of image at address 0xbfc80000

It took 20 minutes just to reload the config which it loaded successfully but that seems like a long time.

 

Thanks,

 

->g.

EdgeMAX EdgeRouter software version v1.9.7+hotfix.1 has been released!

$
0
0

See release notes here:

https://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMAX-EdgeRouter-software-security-release-v1-9-7-hotfix-1/ba-p/2019161

 

This is 1.9.7+hotfix.1 release fixes major bugs and security issues that were found in 1.9.7 release:

  • [UNMS] Fix bug when configuration was randomly reset to default values after upgrade if UNMS service was configured. Discussed here
  • [SSH] Fix security vulnerability via SSH when operator user was able to read/write configuration and gain full admin privileges
  • [OpenVPN] Backport patch for multiple OpenVPN vulnerabilities (CVE-2017-7508, CVE-2017-7520 and CVE-2017-7521). Discussed here.

 

Known major issues that are not yet fixed:

  • Load-balancing is broken. Discussed here

 

 

Problem with DDNS with Dual WAN setup.

$
0
0

Hi All,

 

I have port FW my synology NAS port to access it from the Internet, however, I want to use BOTH WAN for this purpose, (I see we can only choose one WAN for POrt FW, no idea why), the reason is my NAS Synology is also used to update the DDNS address @ noip (to the external IP). The Port FW is done on WAN1, but since I have set up load balancing, the external IP on my NAS keeps changing, and in turn, the NAS also keeps changing/updating the external IP on no-ip. This makes my access to the NAS .. troublesome via DDN. When edge router (due to load balancing) updates the external IP  to WAN1 on my NAS then I am able to access, but its random and when it changes to WAN2, I cannot access my NAS via sam DDN ...... I need a permanent solution.

 

Something like Synology NAS always stays to WAN1, OR Port FW can be done from both WAN interfaces, so what ever be the external IP set on NAS I will be able to access it from the Internet.

 

Hope people can understand my issue here and provide me a permanent solution.

 

Regards

Sammy

Remove VLAN1 from a specific port

$
0
0

I've got an ER Lite connected to an upstream Cisco switch through eth0.  On the ER, I have two vlans setup to pass tagged traffic to the Cisco.  I would like to remove VLAN1 from eth0 so that ONLY tagged traffic is sent to/from the Cisco switch.

 

I can't remove VLAN1 on the Cisco as I'm using it to manage bridge devices between the switch and the ER.

 

If I disable eth0 (but not either eth0.xxx), the interface will drop.

 

Any ideas?

Solution for client losing IPv6 connectivity after PPPoE re-assign the new prefix

$
0
0

I've tried to ask for help on the forum with no luck. After lots of trial and error, I finally figure out how to solve this issue (at least in my use case).

 

Background:

ER-X with 1.9.7 firmware. Using eth4 as wan port and binds the rest ports as switch0.

 

Symptoms:

Many ISP, including mine, reset residential users' PPPoE conneciton periodically to re-assign new IPv4 address and IPv6 prefix. When that happens, switch0 and devices under it will receive and set the IPv6 addresses along with the old ones. And all devices will continue to use the old IPv6 address as default address, which causes users to lose all IPv6 connectives.

 

Analysis:

When PPPoE is disconnected, switch0 still holds the old IPv6 addresses. At the meantime, "radvd" keeps advertising IPv6 prefixes based on the adresses binding on switch0. This makes Mac/PC believes that both IPv6 prefixes are all valid and will choose to use the old IPv6 address as long as the old one is still in the AdvPreferredLifetime time slot.

 

Solution:

Removing old IPv6 addresses from switch0 while PPPoE is disconnected. When the PPPoE connection is up/connected again, a new IPv6 address and prefix will binds on switch0. Since radvd only adverties the IPv6 addresses binding on switch0, it no longer advertises the old IPv6 prefixes. From device's perspective, when it receive a new router advertisement (RA) which doesn't have the existing prefix but a new one. It will consider the old IPv6 addresses as "detached" and setup a new IPv6 address based on RA. The old address will still remain in your system but it doesn't matter (it will be removed by OS when "vaild timelife" is reached).

 

You can fix the problem by following the steps shown below:

 

For tech tech savvy users:

1. ssh -2 [your_account]@your.edge.os.ip

2. sudo vi /etc/ppp/ip-down.d/remove_invalidv6.sh 
#!/bin/sh /sbin/ifconfig switch0 | grep -ivE 'fe80' | grep 'inet6' | awk '{print $3}' | while read -r ipv6addr ; do echo "Removing $ipv6addr from switch0" >> /tmp/ipv6_remove.log /sbin/ip -6 addr del $ipv6addr dev switch0 done /etc/init.d/radvd restart 3. exit vi and type: chmod +x /etc/ppp/ip-down.d/remove_invalidv6.sh

 

For non-tech related users:

1. ssh into your Edgerouter or opens CLI via WebUI

2. type: sudo curl https://cdn.rawgit.com/clyang/44ee7b6caca471d45b4c0ee2bc1d1aab/raw/1a0ec4bad0f03e1d2b67b19d929ef7e63591ab82/remove_invalidv6.sh -o /etc/ppp/ip-down.d/remove_invalidv6.sh

3. type: sudo chmod +x /etc/ppp/ip-down.d/remove_invalidv6.sh

Just in case if you want to have a look on "remove_invalidv6.sh". That's everything! You don't even have to reboot Edgerouter!

 

Hope this article can help others with the same annoying issue.

 

Happy hacking!

ER PoE VPN Connection Failures

$
0
0
I just recently switched over to ATT Gigpapower fiber connection and my VPN is no longer working with my ER PoE router. They gave me their modem, Arris NVG599, which I have gone through and disabled all firewall rules and set it up in Passthrough mode. I wanted to see if some of you could take a look at my config an help figure out what is going on... Thanks! Config attached.

How to block an IP address on the Lan side

$
0
0

How to block an Ip address on the Lan side my Edge Router Lite has an 10.1.19.XXX  output on Etho1

I have an Ip 10.1.19.150  I need to block .  


See why BGP routes are not being accepted

$
0
0

Quagga is completely and utterly infuriating. But that's not news. Anyway.

 

I have two BGP peers on my EdgeRouter X. One works fine, the other does not.

 

They are both using the same prefix filters, which obviously rules that out. 

 

In both cases, I am receiving routes from the peers.

show ip bgp neighbors a.a.a.a received-routes
show ip bgp neighbors b.b.b.b received-routes

... both show the expected routes. However, when asking for which routes were accepted:

show ip bgp neighbors a.a.a.a routes
show ip bgp neighbors b.b.b.b routes

... only the first peer shows me any accepted routes. The second peer is accepting no routes.

 

I thought that maybe the problem is that Quagga does not see the next-hop as routable, but both routes exist in the routing table.

 

The only difference being that, in case a.a.a.a, both peers are in the same single /30. In case b.b.b.b, the peers are not in the same /30, but are instead point-to-point with static /32 interface routes configured. 

 

Does this mean that the ER-X is not capable of using a point-to-point link for BGP? Is there some way around this?

 

Is it possible to see why Quagga is rejecting the routes? Is that logged anywhere?

 

Any thoughts appreciated.

New Edgerouter Pro unresponsive

$
0
0

Hi everyone,

 

First time posting here.  I did find the same issue posted, but it didn't appear to have a resolution, so I thought I'd try again.  I recently purchased an Edgerouter ERPro-8 for our office.  Initial setup was easy -- I was only using eth0 for the WAN connection, and eth1 for our local network.  I also upgraded the firmware to the newest available (1.9.7).  It ran perfectly for about two days.  Then it suddenly became unresponsive.  Computers on our office network could no longer access the internet.  I couldn't access the GUI through the LAN IP address, and it stopped responding to pings, although the network activity LEDs continued to work as normal.  I restarted the router several times, and the problem persisted.  So I pulled the router from the rack and attached my computer to it through the console port.  When booting, the router appears to function normally up to a point, at which it hangs for about 15 seconds, and then reboots, displaying the same information repeatedly in an endless loop.  Any help would be appreciated.

 

This is the output from the console (which it simply repeats over and over):

 

U-Boot 2012.04.01 (UBNT Build ID: 4670715-g7c4b1d0) (Build time: May 27 2014 - 11:19:05)

Skipping PCIe port 0 BIST, in EP mode, can't tell if clocked.
Skipping PCIe port 1 BIST, reset not done. (port not configured)
BIST check passed.
UBNT_E200 r1:0, r2:17, serial #: F09FC20501A8
MPR 13-00317-17
Core clock: 1000 MHz, IO clock: 600 MHz, DDR clock: 533 MHz (1066 Mhz DDR)
Base DRAM address used by u-boot: 0x8f800000, size: 0x800000
DRAM: 2 GiB

Reg: 0x0 0x0
Reg: 0x1 0x0
Reg: 0x2 0xFFFFFFFFC0735CD8
Reg: 0x3 0xFFFFFFFFC0000000
Reg: 0x4 0xFFFFFFFFC0000000
Reg: 0x5 0x800000008F800000
Reg: 0x6 0xFFFFFFFFC0437A74
Reg: 0x7 0x400000
Reg: 0x8 0xFFFFFFFFC008F020
Reg: 0x9 0x800000008F88F020
Reg: 0xA 0xFFFFFFFFC008F020
Reg: 0xB 0xFFFFFFFFC0000CA8
Reg: 0xC 0x0
Reg: 0xD 0x1C004066C
Reg: 0xE 0xC0080CA8C0085E30
Reg: 0xF 0x0
Reg: 0x10 0x735CD8
Reg: 0x11 0xFFFFFFFFFFFFFFFF
Reg: 0x12 0x400000
Reg: 0x13 0x800000008F800000
Reg: 0x14 0x8FF35CD8
Reg: 0x15 0x715CC0
Reg: 0x16 0x8FF35FB0
Reg: 0x17 0xFFFFFFFFFFFFFFFF
Reg: 0x18 0x0
Reg: 0x19 0xFFFFFFFFC0001200
Reg: 0x1A 0xFFFFFFFFFFFF97F8
Reg: 0x1B 0xFFFFFFFFFFFF97F8
Reg: 0x1C 0xFFFFFFFFC008D880
Reg: 0x1D 0xFFFFFFFFC0715CC0
Reg: 0x1E 0x3C33192DC8D8995D
Reg: 0x1F 0xFFFFFFFFC0037A74
s0x505000E6
caus�: 0xC
Reg: 0x0 0x0
Reg: 0x1 0x0
Reg: 0x2 0xC
Reg: 0x3 0xFFFFFFFFC0000000
Reg: 0x4 0xFFFFFFFFC0FF17AF
Reg: 0x5 0x20
Reg: 0x6 0x1F
Reg: 0x7 0x400000
Reg: 0x8 0x8001180000000800
Reg: 0x9 0xFFFFFFFFC0FF17AF
Reg: 0xA 0x0
Reg: 0xB 0xFFFFFFFFFFFFFFFF
Reg: 0xC 0xFFFFFFFFC0001A3C
Reg: 0xD 0x1C004066C
Reg: 0xE 0xC0080CA8C0085E30
Reg: 0xF 0x0
Reg: 0x10 0x735CD8
Reg: 0x11 0xFFFFFFFFFFFFFFFF
Reg: 0x12 0x400000
Reg: 0x13 0x800000008F800000
Reg: 0x14 0x8FF35CD8
Reg: 0x15 0x715CC0
Reg: 0x16 0x8FF35FB0
Reg: 0x17 0xFFFFFFFFFFFFFFFF
Reg: 0x18 0xFFFFFFFFBFC01604
Reg: 0x19 0xFFFFFFFFC00013D0
Reg: 0x1A 0xFFFFFFFFFFFF97F8
Reg: 0x1B 0xFFFFFFFFFFFF97F8
Reg: 0x1C 0xFFFFFFFFBFC8D880
Reg: 0x1D 0xFFFFFFFFFFFF97F8
Reg: 0x1E 0x3C33192DC8D8995D
Reg: 0x1F 0xFFFFFFFFBFC0161C
s0x505000E6
caus�: 0x8 (TLB

�epc: 0xFFFFFFFFC008F098
ba0xFFFFFFFFC0FF17AF

0xFFFFFFFFFF00FFFF

 

Jumping to start of image at address 0xbfca0000

Edgerouter Lite-3 Site-to-Site IPSEC with Cisco ASA

$
0
0

For running some tests on a few new temporarysites I have bought some Edgerouter Lite-3 as I did not receive funding to buy Cisco equipment. As I have seen many good stories about connectivity between the EdgeMax products and Cisco I figured I try it out.

 

I'm running in to some issues and I hope it is to my lack of experience with the products. First I'll try to explain the site infrastructure;

 

SITE A: This is where the Cisco ASA is located

WAN IP: x.x.x.y

IKE:

HASH sha512

Encryption aes256

Authenthication pre-share

DH 5

Mode Main Mode

 

ESP

hash sha512

encryption aes256
SEL 28800

Mode: Tunnel

PFS Disabled

 

Subnet 10.10.10.0/24

 

SITE B: This is where the Edgeroute Lite is located with the following vpn configuration; (remove any identifiers)

WAN IP: y.y.y.x

 

ipsec {
auto-firewall-nat-exclude enable
disable-uniqreqids
esp-group *** {
compression disable
lifetime 28800
mode tunnel
pfs disable
proposal 1 {
encryption aes256
hash sha512
}
}
ike-group *** {
lifetime 28800
proposal 1 {
dh-group 5
encryption aes256
hash sha512
}
}
logging {
log-level 2
log-modes ike
log-modes esp
log-modes cfg
}
nat-traversal disable
site-to-site {
peer x.x.x.y {
authentication {
mode pre-shared-secret
pre-shared-secret thisisasecretMan Happy
}
connection-type initiate
default-esp-group ***
ike-group ***
local-address y.y.y.x
tunnel 1 {
esp-group ***
local {
prefix 10.10.11.0/24
}
remote {
prefix 10.10.10.0/24
}
}
}
}
}

 

However nothing seems to happen after configuring the vpn. I do not see any traffic on the ASA side and when checking the logging on the Edgerouter I do not see anything in the log except for the startup: The restart VPN command does work, but doesn't get things going;

Aug 7 21:37:13 00[DMN] Starting IKE charon daemon (strongSwan 5.2.2, Linux 3.10.20-UBNT, mips64)

show vpn ipsec sa

<empty result>

show vpn ipsec status

 IPSec Process Running PID: 9048

0 Active IPsec Tunnels

 

 

I have changed the loglevel as you can see in the config but I see nothing;

When I'm trying to get some more info with "sudo swanctl --log" I expect to see some more details, but the log is empty.

 

For the time being I have completely removed the firewall on the WAN interface on the edgerouter, accepting all packets and protocols so this cannot be an issue;

 

When I check the traffic going out of the edgerouter with tcpdump I do not see any connection attempts whatsoever. If I connect my laptop to the edgerouter I have functional internet and I can reach the ASA's ip address.

 

Can anyone point me in the right direction?


Very thankful for any insight. If you require any additional info, please don't hesitate to ask 

Sharing Internet connection with 6 neighbour

$
0
0

Hi,

 

I'm looking the build a setup to share my internet with 5 other condo.  They are using netflix and torrent dowload.  So I want to protect the connectivity and provide a good security area.  So I think a router with Qos for each VLAN is a good approach, but witch equipement do you propose ? I was hesiting between the edge router X and the Uinifi Security gateway.  What is the benifit of the cloud key ?  And finaly, a small switch 8-60W would be probaly good.  But someone have experience regarding Qos/shapping nd vlan on these switch ?

 

thanks !

1.9.7 - Kernel Panic - BUG: soft lockup - CPU#0 stuck for 22s! [swapper/0:0]

$
0
0

I started experiencing random router reboots on an EdgePoint R8 about 2 weeks ago out of nowhere (uptime prior to this was ~1 month). It was running 1.9.0 at the time. I upgraded it to 1.9.7 and the issues continued. We swapped the R8 with a brand new one and the issues continued. We thought maybe it was power, so we swapped it from DC to POE-in power, and the issue happened once that night but went away for a week until today. I was able to capture the console output just before the reboot - as I suspected it is a kernel panic.

 

I did some searching and it appears that this has been an ongoing issue through many firmware versions with no real solution (see here and here and here).

 

 

BUG: soft lockup - CPU#0 stuck for 22s! [swapper/0:0]
Kernel panic - not syncing: softlockup: hung tasks
Rebooting in 60 seconds..
*** NMI Watchdog interrupt on Core 0x00 ***
        $0      0x0000000000000000      at      0x0000000050101ce0
        v0      0x00014141e6178114      v1      0xffffffffc0630000
        a0      0x00000000000927c0      a1      0x0000000000000258
        a2      0x00014141e620a8d4      a3      0x0000000000000001
        a4      0x00014141e61a033e      a5      0x0000000000000001
        a6      0x0000000000000003      a7      0xffffffffc0760000
        t0      0x0000000000000018      t1      0xffffffffc0760000
        t2      0x000000000000003c      t3      0x000000000000ea60
        s0      0x000000000000238c      s1      0x0000000000000054
        s2      0x00000000000023f0      s3      0x0000000000000000
        s4      0xffffffffc0750000      s5      0x00000000000003e8
        s6      0xffffffffc0750000      s7      0x0000000000000001
        t8      0x0000000000000001      t9      0x0000000000000000
        k0      0x0000000000000000      k1      0x0f0000000234f247
        gp      0xffffffffc057c000      sp      0xffffffffc057f480
        s8      0x0002176c55fd7c91      ra      0xffffffffc049b5f0
        err_epc 0xffffffffc0007888      epc     0xffffffffc00f8dd0
        status  0x0000000050581ce4      cause   0x0000000040808c08
        sum0    0x0004000100000000      en0     0x0900200500008000
*** Chip soft reset soon ***
Jumping to start of image at address 0xbfca0000
$ show ubnt offload

IP offload module   : loaded
IPv4
  forwarding: enabled
  vlan      : enabled
  pppoe     : disabled
  gre       : enabled
IPv6
  forwarding: disabled
  vlan      : disabled
  pppoe     : disabled

IPSec offload module: loaded

Traffic Analysis    :
  export    : disabled
  dpi       : disabled
    version       : 1.302
$ show hardware power
Power Usage -
System input voltage      : 50.99 V
Terminal block current    : 0.00 mA
POE-IN ETH0 current       : 305.98 mA
POE-IN ETH8 current       : 0.00 mA
System power consumption  : 15.60 W
Power Slot -
Power slot info is not supported on this platform
$ show hardware temperature
Temperature:
Board (CPU):42 C
CPU:49 C
Board (PHY):45 C
PHY:57 C

 

 

Anyone else seeing this? Any thoughts?

 

Viewing all 20028 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>