Quantcast
Channel: EdgeRouter topics
Viewing all 20028 articles
Browse latest View live

EdgeRouter 8 pro serious problem

$
0
0

Hello guys,

 

after 2 years of continoues use i had a problem with ER-8...

 

I tried to recover all the settings but nothing is working... i did a hard reset i start to setup from zero but nothing is working well... 

Please check the screenshot i attach...

 

Screen Shot 2017-08-10 at 12.46.02.png


EdgeRouter 8 pro strange problem

$
0
0

Hello guys,

 

after 2 years of continoues use i had a problem with ER-8...

 

I tried to recover all the settings but nothing is working... i did a hard reset i start to setup from zero but nothing is working well... 

Please check the screenshot i attach...

 

Screen Shot 2017-08-10 at 12.46.02.png

ER-X as a guest router behind another router

$
0
0

Hi there,

I bought my first ER-X and would like to set up a special guest eth network behind another router.

This is the scheme of the network:

 

WAN <--> Fritz!-Router (192.168.2.100) <--> WLAN-Bridge  to another Buildung <--> several company PCs on a switch - and on that switch comes the ER-X.

 

I now want to add the ER-X behind the last switch with

ETH0 - company network 192.168.2.0 (attached to company network switch)
ETH1 - guest network 1 (192.168.10.0) -> only internet access via eth0 to WAN via Fritz!-Router 192.168.2.100 with own DHCP-Range. The guest network may not have any access to PCs on 192.168.2.x.

 

I think I have to set up ER-X as source NAT on 192.168.10.0 with destination 192.168.2.100 and configure an DHCP. But neither of both work. Maybe I'm totally wrong?

 

Thanks for helping me.

 

 

ubnt@ubnt:~$ show configuration
firewall {
}
interfaces {
    ethernet eth0 {
        address 192.168.2.102/24
    }
    ethernet eth1 {
        address 192.168.10.1/24
    }
    ethernet eth2 {
    }
    ethernet eth3 {
    }
    ethernet eth4 {
    }
    loopback lo {
    }
    switch switch0 {
    }
}
service {
    dhcp-server {
        shared-network-name DHCP-Guest1 {
            subnet 192.168.10.0/24 {
                default-router 192.168.10.1
                dns-server 192.168.2.100
                start 192.168.10.2 {
                    stop 192.168.10.10
                }
            }
        }
    }
    dns {
        forwarding {
            listen-on eth1
            listen-on eth1.1001
        }
    }
    gui {
    }
    nat {
        rule 5000 {
            description Guest1
            destination {
                address 192.168.2.100
            }
            log disable
            outbound-interface eth0
            protocol all
            source {
                address 192.168.10.0/24
            }
            type masquerade
        }
    }
    ssh {
    }
}

Packet drops destined for 10.0.1.255

$
0
0

I have two LANs, 10.0.1.1/24 (main LAN on eth1) and 10.0.2.1/24 (IoT and wifi on eth2).

 

The firewall rule eth2/local drops packets every second and when I look at the logs it seemes like it is my main computer (that is on 10.0.1.6) trying to connect to 10.0.1.255 that is the cause of this. Im a bit perplexed how this is possible when the computer is on a different interface??? And what is 10.0.1.255?

 

kernel: cavium_delete_hndl / IPsec (vti) flap

$
0
0

 

Hi,

I have some tunnel flap, I have weird error logs. Any ideas ?

 

show version 
Version:      v1.9.7
HW model:     EdgeRouter Pro 8-Port

 

 

root@ERL-Tommy-GNET:/home/patrykw# tail -f /var/log/messages
Aug 10 06:04:17 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 80000000892e4400 x->sa_handle            (nil)
Aug 10 06:04:17 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008d71dc00 x->sa_handle            (nil)
Aug 10 06:04:55 ERL-Tommy-GNET OSPF[3251]:  OSPF-6: ADJCHG: Process 0, Nbr 10.254.5.1 on vti3:10.0.80.14: Full to Down, InactivityTimer.
Aug 10 06:05:30 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008d8f5000 x->sa_handle            (nil)
Aug 10 06:05:30 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089b8d400 x->sa_handle            (nil)
Aug 10 06:06:00 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008caf5400 x->sa_handle            (nil)
Aug 10 06:06:00 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008d94dc00 x->sa_handle            (nil)
Aug 10 06:06:22 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089b89400 x->sa_handle            (nil)
Aug 10 06:06:22 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089144800 x->sa_handle            (nil)
Aug 10 06:05:30 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008d8f5000 x->sa_handle            (nil)
Aug 10 06:05:30 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089b8d400 x->sa_handle            (nil)
Aug 10 06:06:00 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008caf5400 x->sa_handle            (nil)
Aug 10 06:06:00 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008d94dc00 x->sa_handle            (nil)
Aug 10 06:06:22 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089b89400 x->sa_handle            (nil)
Aug 10 06:06:22 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089144800 x->sa_handle            (nil)
Aug 10 06:08:52 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008dce0c00 x->sa_handle            (nil)
Aug 10 06:08:52 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:05:30 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008d8f5000 x->sa_handle            (nil)
Aug 10 06:05:30 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089b8d400 x->sa_handle            (nil)
Aug 10 06:06:00 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008caf5400 x->sa_handle            (nil)
Aug 10 06:06:00 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008d94dc00 x->sa_handle            (nil)
Aug 10 06:06:22 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089b89400 x->sa_handle            (nil)
Aug 10 06:06:22 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089144800 x->sa_handle            (nil)
Aug 10 06:08:52 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008dce0c00 x->sa_handle            (nil)
Aug 10 06:08:52 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:08:52 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:09:12 ERL-Tommy-GNET OSPF[3251]:  OSPF-6: ADJCHG: Process 0, Nbr 10.254.5.1 on vti3:10.0.80.14: Loading to Full, LoadingDone.
Aug 10 06:22:14 ERL-Tommy-GNET sshd[27724]: PAM service(sshd) ignoring max retries; 6 > 3
Aug 10 06:26:09 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008dce0c00 x->sa_handle            (nil)
Aug 10 06:26:09 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:26:09 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008ca02800 x->sa_handle            (nil)
Aug 10 06:26:09 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:26:09 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008dce0c00 x->sa_handle            (nil)
Aug 10 06:26:09 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:26:09 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:26:58 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008da1fc00 x->sa_handle            (nil)
Aug 10 06:26:58 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008dce0c00 x->sa_handle            (nil)
Aug 10 06:26:58 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008960dc00 x->sa_handle            (nil)
Aug 10 06:26:58 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008991e000 x->sa_handle            (nil)
Aug 10 06:26:58 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 800000008dc4e400 x->sa_handle            (nil)
Aug 10 06:27:32 ERL-Tommy-GNET OSPF[3251]:  OSPF-6: ADJCHG: Process 0, Nbr 10.254.5.1 on vti3:10.0.80.14: Full to Down, InactivityTimer.
Aug 10 06:29:31 ERL-Tommy-GNET kernel: cavium_delete_hndl : NULL Sa/SA Handle : with x 8000000089964800 x->sa_handle            (nil)
Aug 10 06:29:31 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:29:31 ERL-Tommy-GNET kernel: cavium_alloc_n_fill: Cipher/Digest not supported. 
Aug 10 06:29:42 ERL-Tommy-GNET OSPF[3251]:  OSPF-6: ADJCHG: Process 0, Nbr 10.254.5.1 on vti3:10.0.80.14: Loading to Full, LoadingDone.

PVID 1

$
0
0

In my test lab, I am running a 'router on a stick' design. My firewall interface that connects to the switch doesn't use vlan 1 or know about vlan 1. The switch has 5 vlans on it and vlan 1 is excluded everywhere. My management vlan is 100 and under IPv4 connectivity I assigned the switch an IP from 192.168.100.0 /24 subnet and set the management vlan to 100. However, I noticed that the PVID (when I hover over a port) is still set to 1.

 

questions

 

1- Does it matter if the PVID is 1 if I am not using vlan 1 anywhere? I realize that any untagged packets can pottentially be marked as vlan 1 if the tagging/untagging/excluding isn't done properly (If I leave the switch as is).

 

2- I thought changing the management vlan to 100 might change the PVID to 100, as well, I guess not. I can get to the CLI if it will be easier/quicker to configure the PVID for the rest of the ports.

 

Personally, I don't see a reason to use a PVID value (in my current setup). I know all networks are different and I realize that might not be the case for everyone.

Edge Router X - Festival

$
0
0

So this year I'm wanting to switch from the Mikrotik CCR to the edge router X & hopefully you can advise or answer some questions.

 

I'll have about 16 wifi locations & want to have less management done on the router with the below;

 

On the X can i have e.g Vlan 10 with a DHCP of 250 IP configured onto 3 different AP-AC-Pro units all using the same vlan & ip pool ? So AP1 is production office AP2 is Site office & AP3 is HQ. 

 

 

At any given stage there will be roughly 800 IP's used. The router will also be blocking the usual stuff on "switch/in" under firewall rules.

 

The controller software will be hosted on a windows server on the same lan as the router & rocket-prism-ac unit.

 

ERP-8 Kernel Panic: Task init:1 Blocked for more than 120 Seconds.

$
0
0

I have an ERP-8 running 1.9.7 and about 30 minutes ago it had a kernel panic and restarted.

Whats bothering me is why did "init" hang? I don't see any information in the syslog that could help.

 

Right before init stopped responding the router was doing a string of DHCPDISCOVERs and DHCPOFFERS to one of our sonos players. It did 3 pairs of DHCPDISCOVER and OFFER in the span of about 5 seconds then 3 seconds later init stopped responding which caused the router to reboot.

 

At this point I've been testing out DNS cache at 8000 entries to reduce the number of DNS misses in cache. I have about 60 - 70 devices on the LAN, and around 50 - 60 devices on Wifi. Unfortunately I can't see how much RAM was being used at the time of the panic, nor can I see CPU useage.

 

Looking at the syslog now I'm seeing a lot of DHCPDISCOVER and OFFERs from the same sonos player. Could so many requests cause init to hang?  

 

Let me know if posting the config would help.


Replace Netgear Blackhawk AC1900 router with Edgerouter Lite

$
0
0

I have a Blackhawk AC1900 with terrible throughput, getting 9 mbps download on a 90 mbps download lan. Can't find how to change the port speed, must be in auto, and I don't think you can change it!

 

I want to put in a Edgerouter lite. I have a static IP, sub, and gateway on the Blackhawk. Using 8.8.8.4 as DNS. I am using default 192.168.1.x ip schema to 15 Ubuiquity AC acess points on 2 different floors at client. I am using 2 cat5 cables on the blackhawk LAN 1&2 ports, one to each level going to switches. (one on each floor)

 

I think I understand you cannot have the same schema on eth 1 and 2, but you can bridge them so you can route the 2 cat 5 lines to the 2 different floors? I see where to change port speeds to 100FULL where they need to be.

 

How do I go about assigning the ISP static info, and bridging the 2 ports? I do not need VPN, virtual LANS, firewall, or any other features. I just to need to send the 192.168.1.x schema to both floors, and let the Edgerouter be DHCP, to provide wifi coverage from access points.

 

I have a Watchguard Firewall T30 in bridge mode, 1 cat 5 going to Blackhawk wan port right now. All access points are acting as 1 SSID. Want the Edgerouter Lite for increased thruput.

 

Do I bridge, use port eth1&2 for the 2 cat 5 lines going to the switches?

 

Thank you all so much!

Brian

You must be joking ... ER-8-XG ... 18 mpps ...

$
0
0

Whaaaaat, only 18 mpps? That is 9,8 GBit @ 64 Byte packets.

 

If you have a 10 GBit Connection to an ISP, you can be DDoSed and your Router is dead. You are not able to insert Blackhole-Routes on your BGP-Upstream-Peer.

 

Mikrotik 72 Core 8-SFP+ have 120 Mio. packets in bridge-mode and 86 Mio. packets in routing-mode.

 

Why was UBNT choosing CN7360 and not CN7890?

 

Are there any plans for hardware-upgrade to get all ports routing in wirespeed at 64 bytes?

Web UI inop fromIPad

$
0
0

Through search, I found out this problem has been discussed but didn't see any easy fix. 

 

PROBLEM

 

Login into the Edgerouter X using IPad Safari and the GUI is grayed out (see pic).  Had FW 1.9.1.1 so uploaded 1.9.7.    The problem exists with both. No problem when using a laptop running windows 10. Any easy fix?

 

Router Randomly Crashing, Kernel Panic - (With Log)

$
0
0

  

 

Anyone available that can glance at this dump to see if this looks like a hardware issue or something else? I believe the version is 1.9.1.1 but this crash has been happening randomly for awhile, finally got a console cable on it to catch the crash. This is an ERPro that is consistently moving around 700mbps or so. 

 

Welcome to EdgeOS Router ttyS0

By logging in, accessing, or using the Ubiquiti product, you
acknowledge that you have read and understood the Ubiquiti
License Agreement (available in the Web UI at, by default,
http://192.168.1.1) and agree to be bound by its terms.

Router login: Unhandled kernel unaligned access[#1]:
CPU: 0 PID: 862 Comm: kworker/0:0 Tainted: P           O 3.10.20-UBNT #1
Workqueue: events flow_cache_gc_task
task: 8000000089393600 ti: 800000007e56c000 task.ti: 800000007e56c000
$ 0   : 0000000000000000 0000000050109ce1 0000000000000000 ffffffffc04b3380
$ 4   : ffffffffc0080a20 ffffffffffff8100 0010000000000008 0010000000000000
$ 8   : 0000000050109ce3 0000000000000000 0000000000000010 8000000002c703c8
$12   : 0000000000800010 0000000000000010 0000000000000000 0000000000000000
$16   : 0010000000000000 800000007e56fb50 ffffffffdce80000 ffffffffc03dddfc
$20   : 0000000000000000 ffffffffc03dde1c 0000000000000037 8000000002c70b18
$24   : ffffffffdce80000 0000000000000000
$28   : 800000007e56c000 800000007e56faf0 0000000000000001 0010000000000008
Hi    : 0000000000000005
Lo    : 333333333333333b
epc   : ffffffffc0080a38 do_ade+0x778/0xe10
    Tainted: P           O
ra    : 0010000000000008 0x10000000000008
Status: 50109ce3        KX SX UX KERNEL EXL IE
Cause : 00800010
BadVA : 0010000000000000
PrId  : 000d9301 (Cavium Octeon II)
Modules linked in: authenc xfrm4_mode_transport sha256_generic xfrm6_mode_tunnel deflate zlib_deflate xfrm_user xfrm4_tunnel tunnel4 ipcomp xfrm_ipcomp esp4 ah4 ip_vti xfrm4_mode_tunnel ip_tunnel 8021q garp stp llc xt_multiport xt_nat xt_policy xt_tcpudp xt_limit xt_LOG xt_comment xt_set xt_conntrack ip_set_bitmap_port ip6table_mangle ip6table_filter ip6table_raw ip6_tables iptable_nat nf_conntrack_ipv4 nf_defrag_ipv4 nf_nat_ipv4 iptable_mangle xt_CT iptable_raw nf_nat_pptp nf_conntrack_pptp nf_conntrack_proto_gre nf_nat_h323 nf_conntrack_h323 nf_nat_sip nf_conntrack_sip nf_nat_proto_gre nf_nat_tftp nf_nat_ftp nf_nat nf_conntrack_tftp nf_conntrack_ftp nf_conntrack ip_set_hash_net ip_set nfnetlink iptable_filter ip_tables x_tables cvm_ipsec_kame(O) ipv6 imq cavium_ip_offload(PO) ubnt_nf_app(PO) tdts(PO) octeon_rng rng_core octeon_ethernet mdio_octeon of_mdio ethernet_mem octeon_common ubnt_platform(PO) libphy
Process kworker/0:0 (pid: 862, threadinfo=800000007e56c000, task=8000000089393600, tls=0000000000000000)
Stack : 0000000000000000 8000000002c70b18 ffffffffc0630000 ffffffffc0630000
          80000000830b02d0 800000008c871338 ffffffffc05a0000 8000000002c74400
          0000000000000000 0000000000000000 0000000000000000 ffffffffc0078f20
          0000000000000000 0000000050109ce1 ffffffffc05a0000 ffffffffc0620000
          0010000000000000 0000000000000000 ffffffffc059a428 0010000000000000
          ffffffffc06203c8 8000000042650000 8000000002c703c8 8000000002c703c8
          800000008c2ac2f8 000000000000cfd7 000000000000cfd8 0000000000000000
          80000000830b02d0 800000008c871338 ffffffffc05a0000 8000000002c74400
          0000000000000000 0000000000000000 0000000000000000 8000000002c70b18
          0000000000000000 0000000000000010 0000000000800400 ffffffffc016dce4
          ...
Call Trace:
[<ffffffffc0080a38>] do_ade+0x778/0xe10
[<ffffffffc0078f20>] ret_from_exception+0x0/0xc
[<ffffffffc03dddfc>] flow_cache_gc_task+0x7c/0xc0
[<ffffffffc00c370c>] process_one_work+0x26c/0x4a8
[<ffffffffc00c3e7c>] worker_thread+0x144/0x480
[<ffffffffc00cbc0c>] kthread+0xa4/0xb0
[<ffffffffc0078f70>] ret_from_kernel_thread+0x14/0x1c


Code: 00d91024  1440ff40  00000000 <6a160000> 6e160007  24030000  1460ff78  00000000  0802023f
---[ end trace 392c274b7abff8da ]---
[sched_delayed] sched: RT throttling activated
Fatal exception: panic in 5 seconds[
[[[[[[ REMOVED LOG ENTRIES AS THEY CONTAIN PUBLIC IPS, ALL JUST FIREWALL DROP LOGS, WILL SEND TO UBNT DEVS IF NEEDED ]]]]]]]

Kernel panic - not syncing: Fatal exception
Rebooting in 60 seconds..
*** NMI Watchdog interrupt on Core 0x00 ***
        $0      0x0000000000000000      at      0x0000000050109ce0
        v0      0x0002b53beb120ff8      v1      0xffffffffc0630000
        a0      0x00000000000f4240      a1      0x00000000000003e8
        a2      0x0002b53beb215238      a3      0x0000000000000001
        a4      0x0002b53beb213d3e      a5      0x0000000000000001
        a6      0x0000000000000003      a7      0xffffffffc0760000
        t0      0x0000000000000018      t1      0xffffffffc0760000
        t2      0x000000000000003c      t3      0x000000000000ea60
        s0      0x0000000000001324      s1      0x0000000000000010
        s2      0x0000000000001388      s3      0x0000000000000001
        s4      0xffffffffc0750000      s5      0x00000000000003e8
        s6      0xffffffffc0750000      s7      0x8000000002c70b18
        t8      0x0000000000000001      t9      0x0000000000000000
        k0      0x000000007fb83a90      k1      0x800000008942ffe0
        gp      0x800000007e56c000      sp      0x800000007e56f840
        s8      0x0000000000000001      ra      0xffffffffc049b5f0
        err_epc 0xffffffffc000788c      epc     0x00000000774e8504
        status  0x0000000050589ce4      cause   0x0000000040808c20
        sum0    0x0004000100008000      en0     0x0900200500008000
*** Chip soft reset soon ***
Jumping to start of image at address 0xbfca0000


U-Boot 2012.04.01 (UBNT Build ID: 4670715-g7c4b1d0) (Build time: May 27 2014 - 11:19:05)

Skipping PCIe port 0 BIST, in EP mode, can't tell if clocked.
Skipping PCIe port 1 BIST, reset not done. (port not configured)
BIST check passed.
UBNT_E200 r1:0, r2:17, serial #: 802AA88FAB7A
MPR 13-00317-17
Core clock: 1000 MHz, IO clock: 600 MHz, DDR clock: 533 MHz (1066 Mhz DDR)
Base DRAM address used by u-boot: 0x8f800000, size: 0x800000
DRAM: 2 GiB
Clearing DRAM...... done
Flash: 8 MiB
Net:   octeth0, octeth1, octeth2, octeth3, octeth4, octeth5, octeth6, octeth7
MMC:   Octeon MMC/SD0: 0
USB:   USB EHCI 1.00
scanning bus for devices... 1 USB Device(s) found
Type the command 'usb start' to scan for USB storage devices.

Hit any key to stop autoboot:  0
reading vmlinux.64

6435976 bytes read
argv[2]: numcores=2
argv[3]: endbootargs
Allocating memory for mapped kernel segment, alignment: 0x400000
Allocated memory for ELF segment: addr: 0x400000, size 0x77cd00
## Loading big-endian Linux kernel with entry point: 0x80000000008995d0 ...
Bootloader: Done loading app on coremask: 0x3
Starting cores 0x3
Linux version 3.10.20-UBNT (root@ubnt-builder2) (gcc version 4.7.0 (Cavium Inc. Version: SDK_3_1_0_p2 build 34) ) #1 SMP Sat Apr 22 06:58:28 PDT 2017
CVMSEG size: 2 cache lines (256 bytes)
Cavium Inc. SDK-3.1
bootconsole [early0] enabled
CPU revision is: 000d9301 (Cavium Octeon II)
Checking for the multiply/shift bug... no.
Checking for the daddiu bug... no.
Determined physical RAM map:
 memory: 000000000e400000 @ 0000000000c00000 (usable)
 memory: 0000000000c00000 @ 000000000f200000 (usable)
 memory: 000000006f800000 @ 0000000020000000 (usable)
 memory: 00000000005e2000 @ 0000000000400000 (usable)
 memory: 000000000004e000 @ 00000000009e2000 (usable after init)
Wasting 57344 bytes for tracking 1024 unused pages
Using passed Device Tree <8000000000080000>.
software IO TLB [mem 0x02c0a000-0x02c4a000] (0MB) mapped at [8000000002c0a000-8000000002c49fff]
Zone ranges:
  DMA32    [mem 0x00400000-0xefffffff]
  Normal   empty
Movable zone start for each node
Early memory node ranges
  node   0: [mem 0x00400000-0x00a2ffff]
  node   0: [mem 0x00c00000-0x0effffff]
  node   0: [mem 0x0f200000-0x0fdfffff]
  node   0: [mem 0x20000000-0x8f7fffff]
Primary instruction cache 37kB, virtually tagged, 37 way, 8 sets, linesize 128 bytes.
Primary data cache 32kB, 32-way, 8 sets, linesize 128 bytes.
Secondary unified cache 1024kB, 16-way, 512 sets, linesize 128 bytes.
PERCPU: Embedded 10 pages/cpu @8000000002c6f000 s11904 r8192 d20864 u40960
Built 1 zonelists in Zone order, mobility grouping on.  Total pages: 512622
Kernel command line:  root=/dev/mmcblk0p2 rootdelay=10 rw rootsqimg=squashfs.img rootsqwdir=w mtdparts=phys_mapped_flash:640k(boot0),640k(boot1),64k(eeprom) console=ttyS0,115200
PID hash table entries: 4096 (order: 3, 32768 bytes)
Dentry cache hash table entries: 262144 (order: 9, 2097152 bytes)
Inode-cache hash table entries: 131072 (order: 8, 1048576 bytes)
Memory: 2040272k/2078912k available (4760k kernel code, 38640k reserved, 1261k data, 312k init, 0k highmem)
Hierarchical RCU implementation.
        Additional per-CPU info printed with stalls.
NR_IRQS:255
Calibrating delay loop (skipped) preset value.. 2000.00 BogoMIPS (lpj=10000000)
pid_max: default: 32768 minimum: 501
Security Framework initialized
Mount-cache hash table entries: 256
Checking for the daddi bug... no.
SMP: Booting CPU01 (CoreId  1)...
CPU revision is: 000d9301 (Cavium Octeon II)
Brought up 2 CPUs
NET: Registered protocol family 16
PTP Clock: Using sclk reference at 600000000 Hz
bio: create slab <bio-0> at 0
usbcore: registered new interface driver usbfs
usbcore: registered new interface driver hub
usbcore: registered new device driver usb
Switching to clocksource OCTEON_CVMCOUNT
NET: Registered protocol family 2
TCP established hash table entries: 16384 (order: 6, 262144 bytes)
TCP bind hash table entries: 16384 (order: 6, 262144 bytes)
TCP: Hash tables configured (established 16384 bind 16384)
TCP: reno registered
UDP hash table entries: 1024 (order: 3, 32768 bytes)
UDP-Lite hash table entries: 1024 (order: 3, 32768 bytes)
NET: Registered protocol family 1
octeon_pci_console: Console not created.
/proc/octeon_perf: Octeon performance counter interface loaded
HugeTLB registered 2 MB page size, pre-allocated 0 pages
squashfs: version 4.0 (2009/01/31) Phillip Lougher
Registering unionfs 2.5.13 (for 3.10.34)
msgmni has been set to 3984
io scheduler noop registered
io scheduler cfq registered (default)
Serial: 8250/16550 driver, 6 ports, IRQ sharing disabled
1180000000800.serial: ttyS0 at MMIO 0x1180000000800 (irq = 34) is a OCTEON
console [ttyS0] enabled, bootconsole disabled
console [ttyS0] enabled, bootconsole disabled
1180000000c00.serial: ttyS1 at MMIO 0x1180000000c00 (irq = 35) is a OCTEON
loop: module loaded
ehci_hcd: USB 2.0 'Enhanced' Host Controller (EHCI) Driver
octeon-ehci 16f0000000000.ehci: Octeon EHCI
octeon-ehci 16f0000000000.ehci: new USB bus registered, assigned bus number 1
octeon-ehci 16f0000000000.ehci: irq 56, io mem 0x16f0000000000
octeon-ehci 16f0000000000.ehci: USB 2.0 started, EHCI 1.00
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 2 ports detected
ohci_hcd: USB 1.1 'Open' Host Controller (OHCI) Driver
octeon-ohci 16f0000000400.ohci: Octeon OHCI
octeon-ohci 16f0000000400.ohci: new USB bus registered, assigned bus number 2
octeon-ohci 16f0000000400.ohci: irq 56, io mem 0x16f0000000400
hub 2-0:1.0: USB hub found
hub 2-0:1.0: 2 ports detected
i2c-octeon 1180000001000.i2c: version 2.5
i2c-octeon 1180000001200.i2c: version 2.5
octeon_wdt: Initial granularity 5 Sec
TCP: cubic registered
NET: Registered protocol family 17
NET: Registered protocol family 15
Bootbus flash: Setting flash for 8MB flash at 0x1f400000
phys_mapped_flash: Found 1 x16 devices at 0x0 in 8-bit bank. Manufacturer ID 0x0000c2 Chip ID 0x0000c9
Amd/Fujitsu Extended Query Table at 0x0040
  Amd/Fujitsu Extended Query version 1.1.
phys_mapped_flash: Swapping erase regions for top-boot CFI table.
number of CFI chips: 1
3 cmdlinepart partitions found on MTD device phys_mapped_flash
Creating 3 MTD partitions on "phys_mapped_flash":
0x000000000000-0x0000000a0000 : "boot0"
0x0000000a0000-0x000000140000 : "boot1"
mmc0: BKOPS_EN bit is not set
0x000000140000-0x000000150000 : "eeprom"
mmc0: new high speed DDR MMC card at address 0001
Waiting 10sec before mounting root device...
mmcblk0: mmc0:0001 SEM04G 3.68 GiB
mmcblk0boot0: mmc0:0001 SEM04G partition 1 2.00 MiB
mmcblk0boot1: mmc0:0001 SEM04G partition 2 2.00 MiB
mmcblk0rpmb: mmc0:0001 SEM04G partition 3 2.00 MiB
 mmcblk0: p1 p2
 mmcblk0boot1: unknown partition table
 mmcblk0boot0: unknown partition table
kjournald starting.  Commit interval 3 seconds
EXT3-fs (mmcblk0p2): using internal journal
EXT3-fs (mmcblk0p2): recovery complete
EXT3-fs (mmcblk0p2): mounted filesystem with journal data mode
VFS: Mounted root (unionfs filesystem) on device 0:11.
Freeing unused kernel memory: 312K (ffffffffc05e2000 - ffffffffc0630000)
Algorithmics/MIPS FPU Emulator v1.5
INIT: version 2.88 booting
INIT: Entering runlevel: 2
Starting network plug daemon: netplugd.
[ ok ] Starting routing daemon: rib nsm ribd.
[ ok ] Starting EdgeOS router: migrate rl-system configure.

Welcome to EdgeOS Router ttyS0

By logging in, accessing, or using the Ubiquiti product, you
acknowledge that you have read and understood the Ubiquiti
License Agreement (available in the Web UI at, by default,
http://192.168.1.1) and agree to be bound by its terms.

Router login:

 

EdgeRouter 5-PoE: New homelab - config suggestions?

$
0
0

Hello,

 

Recently, I've set up my homelab virtualization from scratch (migrated from Hyper-V to ESXi) and I thought it was a good time to create a new network topology as well. My vSwitch topology on the hypervisor consists of several VLANs:

 

esxi_network.png

 

Interface configuration on EdgeRouter 5-PoE looks like this:

edgeos.png

 

As you can see, interface eth0 is used for WAN, eth1.X are gateways for VLANs on the hypervisor. Switch-ports eth2-4 are used for my client LAN. UniFi AP AC Lite is currently connected on eth4 with PoE.

 

My specs:

WAN - 100/100 Mbps verified speed.

EdgeRouter 5-PoE: 1.9.7+hotfix.1 firmware

 

Time for some questions now:

 

1. I would like to throttle the client LAN so no device can max out the WAN bandwith. I want to have some reservation for the server VLANs. I have practiced a bit with Smart Queue, but as I'm aware, I cannot use it together with hardware offloading for vlan, forwarding etc. (which is currently enabled) so performance will be degraded, right? What would be a decent solution for this problem?

 

2. I want to configure two VLANs for the client LAN:

On the UniFi AP I would like to have two SSIDs, for instance:

 

192.168.5.0/24 - VLAN 5 - LAN

192.168.6.0/24 - VLAN 6 - Guest LAN

 

So basically ports eth2-3 should be aware of the 192.168.5.0/24 network and eth4 of both LAN and Guest VLAN. I'm not sure if I should assign those VLANs on switch0 or interface level?

 

3. InterVLAN routing is on as default. I would like to limit access only to SSH and HTTPS ports from my client LAN. I guess I have to toy a bit with firewall on EdgeOS. Are there any good docs / tips on how to configure it?

 

I would like to have some feedback from any of you that are experienced in advanced networking. Since I'm new to Ubiquiti gear, I need to do much more documentation reading, but it would be nice to get some relevant feedback from you guys so maybe I'll get more ideas how to configure the rest of my network.

EdgePoint POE Startup failure

$
0
0

So I have a EP-6 powered with a 2.5 amps power supply running a powerbeam 500 and three litebeam 120's. 

Whenever I restart the EP however, the device 'forgets' the POE state on eth0 (the powerbeam/backhaul) which is extremely problematic. The interface says 24v is being pushed to the PB but no connection. When turning POE off/on the connection gets established and the PB comes online.

 

Is this a known issue?

Edge Router Port Forwarding

$
0
0

Hello Gents

Is there a manual or some video on easy port forwarding with the edge router line I am not a wizard but it seems awfully complicated just to forward a port UBNT needs to make it easier. Thanks in advance


routing table issues

$
0
0

I had a weird problem this morning. I was investigating a problem someone reported to me and when I ping'ed I saw

 

ping 10.12.0.253
PING 10.12.0.253 (10.12.0.253) 56(84) bytes of data.
From 10.15.1.253 icmp_seq=1 Destination Host Unreachable
From 10.15.1.253 icmp_seq=2 Destination Host Unreachable
From 10.15.1.253 icmp_seq=3 Destination Host Unreachable
64 bytes from 10.12.0.253: icmp_req=4 ttl=62 time=1.62 ms
64 bytes from 10.12.0.253: icmp_req=5 ttl=62 time=1.70 ms
64 bytes from 10.12.0.253: icmp_req=6 ttl=62 time=1.52 ms
64 bytes from 10.12.0.253: icmp_req=7 ttl=62 time=1.62 ms
64 bytes from 10.12.0.253: icmp_req=9 ttl=62 time=1.61 ms
64 bytes from 10.12.0.253: icmp_req=10 ttl=62 time=1.58 ms
From 10.15.1.253 icmp_seq=8 Destination Host Unreachable
^C
--- 10.12.0.253 ping statistics ---
12 packets transmitted, 6 received, +4 errors, 50% packet loss, time 11013ms
rtt min/avg/max/mdev = 1.521/1.613/1.709/0.068 ms, pipe 3

So I look at the routing table and see:

run show ip route 10.12.0.253
Routing entry for 10.12.0.0/16
  Known via "ospf", distance 110, metric 111,  External Route Tag: 0, best
  Last update 2d04h42m ago
  * is directly connected, eth0
  * 10.15.1.252, via eth0

O E1 *> 0.0.0.0/0 [110/110] via 10.15.1.251, eth0, 6d23h28m
O    *> 10.11.0.0/24 [110/112] is directly connected, eth0, 2d04h44m
     *>              [110/112] via 10.15.1.252, eth0, 2d04h44m
O    *> 10.12.0.0/16 [110/111] is directly connected, eth0, 2d04h44m
     *>              [110/111] via 10.15.1.252, eth0, 2d04h44m
C    *> 10.15.0.0/16 is directly connected, eth0
O       10.15.0.0/16 [110/100] is directly connected, eth0, 3d00h51m
C    *> 127.0.0.0/8 is directly connected, lo
O    *> 192.168.12.248/30 [110/10100] via 10.15.1.251, eth0, 6d23h28m
O    *> 192.168.12.252/30 [110/101] via 10.15.1.254, eth0, 6d23h28m
     *>                   [110/101] via 10.15.1.252, eth0, 6d23h28m


 show ip route connected
IP Route Table for VRF "default"
C    *> 10.15.0.0/16 is directly connected, eth0
C    *> 127.0.0.0/8 is directly connected, lo

 

I am not sure where the directtly connected eth0 came from and after a reboot it's gone and everything pings fine.

 

Also when I rebooted another problem seemed to get triggered, in another edgerouter on the network connected to a metroE, it stopped hearing routes via ospf over the metroE. It's routes on the other side of the metro E were being seen just fine. I had to 'clear ip ospf proceess' to clear this condition. I saw another thread about missing ospf routes on the forum here and in looking at the logs I got a duplicate router ID message right at the same time on the router. I know none of the router IDs are duplicated. Anyone have any ideas on what to look at?

Terrible CS for Support

$
0
0
Hello, I had my 4 month old Edge Router X die and I have supported a Warranty request. I was wondering if anyone has even looked at it since Monday. I have reset settings and then reconfigured multiple times and settings do not stay. Every one raves online about Ubnt products for price and features. No support and only last a few months.

ER-X-SFP FW upgrade causes POE ports to disconnect

$
0
0

With both the 1.9.7 and hotfix.1 I'm getting disconnects on eth ports to UAP's and UAP-AC-Lites.

If I reboot the router or disable POE then re-enable it, the devices power back on, but of course I shouldn't have to do this.

Anyone else seeing this issue?

 

It doesn't happen to all my edgerouters, but it's strange.

Some have 2 POE ports configured, and 1 port/AP may be find and the other needs the POE disabled and re-enabled.

EdgeOS v1.9.7+hotfix.1: DHCP service - mismatch between UI and backend.

$
0
0

Hi all,

 

there is a mismatch in the implementation of DHCP domain-search options in the frontend UI and the backend perl script.

 

The frontend UI uses the domain form field to populate both the domain-name and domain-search option values in the generated dhcpd.conf file.

 

The backend peal script at /opt/vyatta/sbin/dhcpd-config.pl has code that uses the first value of that form field to populate the domain-name option in dhcpd.conf and - in case there are multiple values in the form field - joins all values to a neat comma seperated list for the domain-search option.

 

I think the backend looks fine and the way it uses a single form field to populate two different dhcpd options looks smart enough to suite everyones needs - the first value as domain-name and all values in the domain-search.

 

Now comes the UI problem.

 

The domain form field utilizes some validators from edge.min.js that are checking if the size exceeds 63 characters, contains whitespace, non alphanumeric/hyphen characters and other things - thus preventing the domain-search option in dhcpd.conf to be populated with more than a single entry.

 

Is there a way to fix the UI in a future EdgeOS release?

Send public IP through VLAN to television set-top box

$
0
0

Hi all

 

I just bought an EdgeRouter POE, EdgeSwitch 8-150W and a Unifi AP AC HD. I have an issue in setting up one particular setup fro making my television set-top box interactive. 
My ISP requires that the set-top box receives a public IP for interactivity. Normally i would just put a switch in front of my router, but because I also want to attach my TV and PS4 cabled (not w/ wifi) and I only have one cable present, I want to do this with VLANs. Default VLAN for the TV and PS4 in my LAN at 192.168.1.1/24 range. Another VLAN would have to send the public IP to the set-top box. 

 

I can't seem to figure out how to get this working and the overflow of info of the past few days is making my vision on this very blurry, jumping from one solution to another. 

Can someone help me here? 

Many thanks in advance

 

Joachim

Viewing all 20028 articles
Browse latest View live