51

(73 odpowiedzi, napisanych Sprzęt / Hardware)

Dobra, mała poprawka, komenda wykonywała się tylko potrzeba było czasu:

 # for i in 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16; do cat /dev/mtd$i > /var/
usb_disk/mtd$i; done

cat: can't open '/dev/mtd12': No such device
cat: can't open '/dev/mtd13': No such device
cat: can't open '/dev/mtd14': No such file or directory
cat: can't open '/dev/mtd15': No such file or directory
cat: can't open '/dev/mtd16': No such file or directory
~ # cat /proc/mtd > /var/usb_disk/mtd.txt


W takim razie pytanie, bo podążam za tą instrukcją:

STEP 3: Booting initramfs image:

Method 1: using initramfs as temporary kernel
This exploits the fact, that kernel and rootfs MTD devices are
consecutive on NAND flash, so from within stock image, an initramfs can
be written to this area and booted by U-boot on next reboot, because it
uses "nboot" command which isn't limited by kernel partition size.
- Download a pair of -intermediate-*.bin images. Together they form an
  initramfs image to be written from within stock firmware, allowing
  OpenWrt installation.
- Copy over /usr/bin/flash_eraseall and /usr/bin/nandwrite utilities to
  /tmp. This is critical for installation, as erasing rootfs will cut
  you off from those tools on flash!
- After backing up the previous MTD contents, write the images to the
  respective MTD devices
  # /tmp/flash_eraseall /dev/<kernel-mtd>
  # /tmp/nandwrite /dev/<kernel-mtd> \
  /var/usb_disk/openwrt-ath79-zte-mf286-intermediate-kernel.bin
  # /tmp/flash_eraseall /dev/<kernel-mtd>
  # /tmp/nandwrite /dev/<rootfs-mtd> \
  /var/usb_disk/openwrt-ath79-zte-mf286-intermediate-rootfs.bin
- Ensure that no bad blocks were present on the devices while writing.
  If they were present, you may need to change split offset between
  kernel and rootfs parts, so U-boot reads a valid uImage after skipping
  the bad blocks.
- If write is OK, reboot the device, it will reboot to OpenWrt
  initramfs.
- After rebooting, SSH into the device and use sysupgrade to perform
  proper installation.

"Download a pair of -intermediate-*.bin images." - pytanie gdzie mogę pobrać te obrazy, albo w jaki sposób je przygotować i co mi jest do tego potrzebne? Muszę mieć Linuxa? Z góry dziękuję.

52

(73 odpowiedzi, napisanych Sprzęt / Hardware)

Podepnę się pod temat, mam podobny problem MF286 tylko soft ZTE_DNA_MF286_B16, podpinam uart (ch340 z aliexpress) transmisja 115200 i na początku mam krzaki a potem lecą napisy, również nie mogę zatrzymać bootowania, próbowałem z exploitem, zalogowałem się po telnecie, komenda wyświetlania partycji zadziałała, jednak jak wklepuje komendę do zgrania partycji nic się nie dzieje- pendrive sformatowany na FAT…
Przyznam się, że to pierwszy raz.
Jakieś sugestie?

53

(11 odpowiedzi, napisanych Oprogramowanie / Software)

Coś się zmieniło może w tej materii?jest jakaś wtyczka, która zadziała podobnie jak przeglądarka Brave?

54

(4 odpowiedzi, napisanych Oprogramowanie / Software)

Jak jakieś 4 lata temu prosiłem UPC o przełączenie Connect Boxa w tryb bridge to na infolinii od razu dostałem informację, że nie będzie działać ipv6, także tak mają od dawna i pewnie już nie będą tego zmieniać, bo na koniec umowy za wszelką cenę chcieli mnie namówić na przejście do PLAY-gdzie bridge już nie mieli. Jedyny pozytyw jaki pamiętam z UPC to stałe zewnętrzne IP za free po przełączeniu w tryb bridge, bo dziś to już rarytas.

55

(712 odpowiedzi, napisanych Sprzęt / Hardware)

janusz07 napisał/a:

ten router w spoczynku bierze 6-7W a przy pełnym obciążeniu jakieś 15W 2Gbps na wifi (testowane wielokrotnie) ,więc co trzeba podłączyć do USB żeby przekroczyć moc zasilacza org.?
sam nic tam nie mam w piętę ale ciekawi mnie co tam podpinacie że zasilacz nie wyrabia.

Pendrive Sandisk Ultra Flair 512GB, może to kwestia kolejności uruchamiania procesów, bo ja problemów z zasięgiem nie mam tylko zauważyłem, że po restarcie najpóźniej wstaje sieć 5GHz, też sprawdzę po weekendzie ile bierze z Pendrivem a ile bez, może to kwestia egzemplarza.

56

(712 odpowiedzi, napisanych Sprzęt / Hardware)

ad2014 napisał/a:

Za telewizorem  - to raczej nie najlepsze  miejsce na router  . Co do usb u mnie zauważyłem pogorszenie sygnału  na 5GHz, wolniejszy start tego radia po podłączeniu pena . Po podpięciu przez hub - kabel ok 1m  dalej  pogorszenie  - ale jak właczyłem dodatkowe zasilanie huba - czyli hub aktywny , wszystkie  problemy zniknęły . Czyżby jakiś związek z zasilaniem usb ?

Zgadzam się, ale żona nie chce patrzeć na moje graty????.
Zgadzam się z Tobą, też zauważyłem, że WI-FI 5GHz wstaje wolniej po restarcie, generalnie router ma 1GB ram i przy włączonej Sambie, miniDLNA i wireguardzie zużywa 95% pamięci, po zmianie ustawień w miniDLNA na tylko pliki wideo udało się zejść do 75%. Myślę, że chyba prądu mu nie brakuje tym bardziej, że to tylko pendrive a nie dysk np talerzowy, zasilacz ten oryginalny ma 36W jak dobrze widziałem. Może trzeba mu zapodać jeszcze mocniejszy?Generalnie jak za te pieniądze to i tak nadal jestem zdania, że to był super zakup.

57

(712 odpowiedzi, napisanych Sprzęt / Hardware)

Witam,
Też od dziś jestem szczęśliwym posiadaczem EX5601-T1, wgrane 24.10 od Cezarego. Jest w 100% wart swojej ceny, do tej pory używałem zestawu Asus TUF-AX3000 na oryginale i Netgear R6220 z openwrt. Asus kupiony z myślą o mocnym szybkim WI-FI6, USB z multimediami i wireguardzie,no ale działanie wireguarda okazało się mułem z wodorostami, więc z pomocą przyszedł Netgear R6220 na openwrt głównie do obsługi wireguarda z wyłączonym WI-FI.
Generalnie jeśli chodzi o pokrycie sygnału WI-FI mimo, że Asus ma 4 zewnętrzne anteny i był przymocowany za telewizorem i jego anteny wystawały powyżej, to transfery jakie osiągam na Zyxelu, po zamontowaniu go w tym samym miejscu, są identyczne a nawet zauważyłem, że na balkonie w odległości około 10m przez dwie ściany(mieszkanie płaskie) Asus miał problem i telefon momentalnie po wyjściu na balkon przełączał się na 5G. Na Zyxelu zasięg się pojawił co jest miłą niespodzianką.
USB 3.0 z podpiętym pendrivem działa prawidłowo z sambą i miniDLNA do telewizora i transfery są identyczne jak w przypadku Asusa, podejrzewam, że z dyskiem SSD byłyby lepsze ale nie sprawdzałem.
Wireguard tak samo, transfery na łączu Netii 600/100 nie odbiegają od Netgeara.
Generalnie radzi sobie z PPPoe i póki co działam bez radiatorów.
Cieszy fakt, że teraz wszystko czego potrzebowałem, działa mi z jednego pudła a nie z dwóch jak do tej pory.

58

(201 odpowiedzi, napisanych Oprogramowanie / Software)

Czy jest jakiś skrypt, który wysyłałby maila z informacją jaki aktualnie jest zewnętrzny adres IP?mam zmienne IP i chciałbym aby router wysłał mi powiadomienie o ponownym zestawieniu połączenia z aktualnym adresem.

59

(860 odpowiedzi, napisanych Oprogramowanie / Software)

Zadam może głupie pytanie-Coś się zmieniło w 23.05 w firewallu? Po aktualizacji nie mogę zalogować się po WAN, jak to naprawić?

60

(45 odpowiedzi, napisanych Oprogramowanie / Software)

Witam, co powinienem zrobić, żeby po podłączeniu się do serwera przez wireguard mieć możliwość dostępu do routera i jego lanu klienta, klient nie ma zewnętrznego IP, więc nie można zrobić serwera

zmieniłem smile

Serwer

root@OpenWrt:~# uci show network
network.loopback=interface
network.loopback.ifname='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.ula_prefix='fd1b:3a0b:f9ea::/48'
network.lan=interface
network.lan.type='bridge'
network.lan.ifname='eth0.1'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.wan=interface
network.wan.ifname='eth0.2'
network.wan.proto='dhcp'
network.wan6=interface
network.wan6.ifname='eth0.2'
network.wan6.proto='dhcpv6'
network.@switch[0]=switch
network.@switch[0].name='switch0'
network.@switch[0].reset='1'
network.@switch[0].enable_vlan='1'
network.@switch_vlan[0]=switch_vlan
network.@switch_vlan[0].device='switch0'
network.@switch_vlan[0].vlan='1'
network.@switch_vlan[0].ports='1 2 3 0t'
network.@switch_vlan[1]=switch_vlan
network.@switch_vlan[1].device='switch0'
network.@switch_vlan[1].vlan='2'
network.@switch_vlan[1].ports='4 0t'
network.wg0=interface
network.wg0.proto='wireguard'
network.wg0.private_key='wKYxtcK7EtQzXTBc09b1W00PzicpYlC7cu1Pksxs938='
network.wg0.listen_port='55056'
network.wg0.addresses='10.9.0.1/24'
network.@wireguard_wg0[0]=wireguard_wg0
network.@wireguard_wg0[0].public_key='oPbcupGFWoPHiDNFISEHcpnF6ft64U12jD0G0L3NCUI='
network.@wireguard_wg0[0].route_allowed_ips='1'
network.@wireguard_wg0[0].allowed_ips='10.9.0.2/32'
network.@wireguard_wg0[0].persistent_keepalive='25'
network.@wireguard_wg0[0].description='openwrt'
network.@wireguard_wg0[1]=wireguard_wg0
network.@wireguard_wg0[1].persistent_keepalive='25'
network.@wireguard_wg0[1].public_key='Rr0o7xVdV02s3JJERODa+cvTfB0Kk562QEZTMaYVoy0='
network.@wireguard_wg0[1].description='iPhone'
network.@wireguard_wg0[1].allowed_ips='10.9.0.3/32'
network.@wireguard_wg0[1].route_allowed_ips='1'

i firewall
firewall.@defaults[0]=defaults
firewall.@defaults[0].syn_flood='1'
firewall.@defaults[0].input='ACCEPT'
firewall.@defaults[0].output='ACCEPT'
firewall.@defaults[0].forward='REJECT'
firewall.@zone[0]=zone
firewall.@zone[0].name='lan'
firewall.@zone[0].network='lan'
firewall.@zone[0].input='ACCEPT'
firewall.@zone[0].output='ACCEPT'
firewall.@zone[0].forward='ACCEPT'
firewall.@zone[1]=zone
firewall.@zone[1].name='wan'
firewall.@zone[1].network='wan' 'wan6'
firewall.@zone[1].input='REJECT'
firewall.@zone[1].output='ACCEPT'
firewall.@zone[1].forward='REJECT'
firewall.@zone[1].masq='1'
firewall.@zone[1].mtu_fix='1'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src='lan'
firewall.@forwarding[0].dest='wan'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].src_ip='fc00::/6'
firewall.@rule[3].dest_ip='fc00::/6'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Input'
firewall.@rule[5].src='wan'
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-ICMPv6-Forward'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='*'
firewall.@rule[6].proto='icmp'
firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[6].limit='1000/sec'
firewall.@rule[6].family='ipv6'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-IPSec-ESP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].proto='esp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].name='Allow-ISAKMP'
firewall.@rule[8].src='wan'
firewall.@rule[8].dest='lan'
firewall.@rule[8].dest_port='500'
firewall.@rule[8].proto='udp'
firewall.@rule[8].target='ACCEPT'
firewall.@include[0]=include
firewall.@include[0].path='/etc/firewall.user'
firewall.@rule[9]=rule
firewall.@rule[9].src='wan'
firewall.@rule[9].target='ACCEPT'
firewall.@rule[9].proto='udp'
firewall.@rule[9].dest_port='55056'
firewall.@rule[9].name='wireguard'
firewall.@zone[2]=zone
firewall.@zone[2].name='wg'
firewall.@zone[2].input='ACCEPT'
firewall.@zone[2].forward='ACCEPT'
firewall.@zone[2].output='ACCEPT'
firewall.@zone[2].masq='1'
firewall.@zone[2].network='wg0'
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].src='wg'
firewall.@forwarding[1].dest='wan'
firewall.@forwarding[2]=forwarding
firewall.@forwarding[2].src='wan'
firewall.@forwarding[2].dest='wg'
firewall.@forwarding[3]=forwarding
firewall.@forwarding[3].src='wg'
firewall.@forwarding[3].dest='lan'
firewall.@forwarding[4]=forwarding
firewall.@forwarding[4].src='lan'
firewall.@forwarding[4].dest='wg'
firewall.@rule[10]=rule
firewall.@rule[10].target='ACCEPT'
firewall.@rule[10].src='*'
firewall.@rule[10].name='Allow-Wireguard-Inbound'

klient

network.loopback=interface
network.loopback.device='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.packet_steering='1'
network.globals.ula_prefix='fdd0:4d80:b236::/48'
network.@device[0]=device
network.@device[0].name='br-lan'
network.@device[0].type='bridge'
network.@device[0].ports='lan1' 'lan2' 'lan3' 'lan4'
network.lan=interface
network.lan.device='br-lan'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.wan=interface
network.wan.device='wan'
network.wan.proto='dhcp'
network.wan6=interface
network.wan6.device='wan'
network.wan6.proto='dhcpv6'
network.wg0=interface
network.wg0.proto='wireguard'
network.wg0.private_key='aBfKrL6VMceXtOkAgfuEBo3w9lulcXYWorfQ7tx0xWI='
network.wg0.addresses='10.9.0.2/32'
network.wg0.listen_port='55056'
network.wg0.peerdns='0'
network.wg0.dns='10.9.0.1'
network.@wireguard_wg0[0]=wireguard_wg0
network.@wireguard_wg0[0].route_allowed_ips='1'
network.@wireguard_wg0[0].allowed_ips='0.0.0.0/0'
network.@wireguard_wg0[0].endpoint_host='31.179.93.62'
network.@wireguard_wg0[0].persistent_keepalive='25'
network.@wireguard_wg0[0].description='Openwrt'
network.@wireguard_wg0[0].public_key='CD3kpyz6+ZTsh0a0g4uJu/ege386wDuBB9RhmaOfG3A='
network.@wireguard_wg0[0].endpoint_port='55056'

firewall.@defaults[0]=defaults
firewall.@defaults[0].syn_flood='1'
firewall.@defaults[0].input='ACCEPT'
firewall.@defaults[0].output='ACCEPT'
firewall.@defaults[0].forward='REJECT'
firewall.@zone[0]=zone
firewall.@zone[0].name='lan'
firewall.@zone[0].network='lan'
firewall.@zone[0].input='ACCEPT'
firewall.@zone[0].output='ACCEPT'
firewall.@zone[0].forward='ACCEPT'
firewall.@zone[1]=zone
firewall.@zone[1].name='wan'
firewall.@zone[1].network='wan' 'wan6'
firewall.@zone[1].input='REJECT'
firewall.@zone[1].output='ACCEPT'
firewall.@zone[1].forward='REJECT'
firewall.@zone[1].masq='1'
firewall.@zone[1].mtu_fix='1'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src='lan'
firewall.@forwarding[0].dest='wan'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].src_ip='fc00::/6'
firewall.@rule[3].dest_ip='fc00::/6'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Input'
firewall.@rule[5].src='wan'
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-ICMPv6-Forward'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='*'
firewall.@rule[6].proto='icmp'
firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[6].limit='1000/sec'
firewall.@rule[6].family='ipv6'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-IPSec-ESP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].proto='esp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].name='Allow-ISAKMP'
firewall.@rule[8].src='wan'
firewall.@rule[8].dest='lan'
firewall.@rule[8].dest_port='500'
firewall.@rule[8].proto='udp'
firewall.@rule[8].target='ACCEPT'
firewall.@rule[9]=rule
firewall.@rule[9].name='Support-UDP-Traceroute'
firewall.@rule[9].src='wan'
firewall.@rule[9].dest_port='33434:33689'
firewall.@rule[9].proto='udp'
firewall.@rule[9].family='ipv4'
firewall.@rule[9].target='REJECT'
firewall.@rule[9].enabled='false'
firewall.@include[0]=include
firewall.@include[0].path='/etc/firewall.user'
firewall.@rule[10]=rule
firewall.@rule[10].src='wan'
firewall.@rule[10].target='ACCEPT'
firewall.@rule[10].proto='udp'
firewall.@rule[10].name='wireguard'
firewall.@rule[10].dest_port='55056'
firewall.@zone[2]=zone
firewall.@zone[2].name='wg'
firewall.@zone[2].input='ACCEPT'
firewall.@zone[2].forward='ACCEPT'
firewall.@zone[2].output='ACCEPT'
firewall.@zone[2].masq='1'
firewall.@zone[2].network='wg0'
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].src='wg'
firewall.@forwarding[1].dest='wan'
firewall.@forwarding[2]=forwarding
firewall.@forwarding[2].src='wan'
firewall.@forwarding[2].dest='wg'
firewall.@forwarding[3]=forwarding
firewall.@forwarding[3].src='wg'
firewall.@forwarding[3].dest='lan'
firewall.@forwarding[4]=forwarding
firewall.@forwarding[4].src='lan'
firewall.@forwarding[4].dest='wg'
firewall.@rule[11]=rule
firewall.@rule[11].name='Allow-Wireguard-Inbound'
firewall.@rule[11].src='*'
firewall.@rule[11].target='ACCEPT'

Mam skonfigurowany tunel na dwóch routerach w innych sieciach, po utracie zasilania na kliencie pojawia się problem z ponownym połączeniem z serwerem, muszę wtedy zresetować interfejs wg0 albo zrobić restart serwera, żeby połączenie wróciło- jest to o tyle dziwne, że mam też skonfigurowanego klienta na telefonie i za każdym razem łapie połączenie od razu- co może być przyczyną? Wszystko konfigurowane według poradnika.

Ja np. używam moich WR740N - 2 x jako most WDS, a jeden jako relayd klient.
Mam kompilacje z:
- Luci,
- replayd,
- wiregaurd,
- statystyki
Wyrzucone:
- IPv6
- dnsmasq
- opkg
- ppp
- firewall (iptables)

Potrzebuje takiej kompilacji na 4 x , żeby był wireguard i luci, sam robiłeś? Podzielisz się?

Niestety nie udało mi się doinstalować WireGuard z poziomu GUI wyświetla informacje, że pakiet kmod-wireguard jest niedostępny.. poszperałem trochę w sieci i znalazłem firmware OpenWrt 19.07 z zaimplementowanym WireGuard ale bez GUI i z wyciętym OPKG:
https://openwrt.ashus.net/19.07.7-targe … wireguard/
Modifications against default tiny packages:
- removed PPP support
- removed OPKG
- added relayd
- added wireguard
- replaced wpad-mini by wpad-basic
Pytanie brzmi, czy do tego firmware jest możliwość wgrać Luci?żeby można było w ludzki sposób tym zarządzać ? Jeśli tak to pytanie jak?

to teraz nie wiem czy nie ma miejsca czy się nie da
Collected errors:
* satisfy_dependencies_for: Cannot satisfy the following dependencies for luci-app-wireguard:
*     libc
* opkg_install_cmd: Cannot install package luci-app-wireguard.

A wireguard na tym da rade zainstalować?

68

(45 odpowiedzi, napisanych Oprogramowanie / Software)

Działa, dzięki wielkie połączenie jest zamierzony cel osiągnięty.

69

(45 odpowiedzi, napisanych Oprogramowanie / Software)

ustawiłem co dalej smile

70

(45 odpowiedzi, napisanych Oprogramowanie / Software)

Ustawiłem przekierowanie tylko pytanie czy zewnętrzny i wewnętrzny port ma być taki sam ? Czy ustawić tylko zewnętrzny port na 55055 a wewnętrzny pozostawić pusty?

71

(45 odpowiedzi, napisanych Oprogramowanie / Software)

Nie przekierowałem portów, nie jestem aż tak zdolny smile
Co w takim razie powinienem zmienić w serwerze a co w TP linku, proszę łopatologicznie.
Potrzebuje oszukać pudełko, że nie jest po za siecią UPC.

72

(45 odpowiedzi, napisanych Oprogramowanie / Software)

Witam
pozwolę sobie dokleić mój problem i nie zakładać nowego tematu,
tunel połączony ale nie ma internetu na kliencie. Robiłem według poradnika.
Serwer (RaspberryPi z OpenWRT) podpięty do routera jako LAN do podpiętego TP LINK do Compala z UPC w trybie bridge

Konfiguracja sieci:
network.loopback=interface
network.loopback.device='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.ula_prefix='fd10:6957:7b56::/48'
network.@device[0]=device
network.@device[0].name='br-lan'
network.@device[0].type='bridge'
network.@device[0].ports='eth0'
network.lan=interface
network.lan.device='br-lan'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.lan.oriti='dhcp'
network.lan.proto='dhcp'
network.wan=interface
network.wan.proto='dhcp'
network.wan.device='eth0'
network.wg0=interface
network.wg0.proto='wireguard'
network.wg0.private_key='yJn4rOyeiuXp65HmKI94m0cB9xOfvdZcR6kbClQ8ukA='
network.wg0.addresses='10.9.0.1/24'
network.wg0.listen_port='55055'
network.@wireguard_wg0[0]=wireguard_wg0
network.@wireguard_wg0[0].public_key='UBIH5up9WNmJh1TH+7qtA1lhHE5DmwuNedt4phBAgWs='
network.@wireguard_wg0[0].route_allowed_ips='1'
network.@wireguard_wg0[0].allowed_ips='10.9.0.2/32'
network.@wireguard_wg0[0].persistent_keepalive='25'
network.@wireguard_wg0[0].description='openwrt'
Firewall
firewall.@defaults[0]=defaults
firewall.@defaults[0].input='ACCEPT'
firewall.@defaults[0].output='ACCEPT'
firewall.@defaults[0].forward='REJECT'
firewall.@defaults[0].synflood_protect='1'
firewall.lan=zone
firewall.lan.name='lan'
firewall.lan.input='ACCEPT'
firewall.lan.output='ACCEPT'
firewall.lan.forward='ACCEPT'
firewall.lan.network='lan' '' 'wan'
firewall.wan=zone
firewall.wan.name='wan'
firewall.wan.output='ACCEPT'
firewall.wan.masq='1'
firewall.wan.mtu_fix='1'
firewall.wan.input='REJECT'
firewall.wan.forward='REJECT'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src='lan'
firewall.@forwarding[0].dest='wan'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].src_ip='fc00::/6'
firewall.@rule[3].dest_ip='fc00::/6'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Input'
firewall.@rule[5].src='wan'
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-ICMPv6-Forward'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='*'
firewall.@rule[6].proto='icmp'
firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[6].limit='1000/sec'
firewall.@rule[6].family='ipv6'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-IPSec-ESP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].proto='esp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].name='Allow-ISAKMP'
firewall.@rule[8].src='wan'
firewall.@rule[8].dest='lan'
firewall.@rule[8].dest_port='500'
firewall.@rule[8].proto='udp'
firewall.@rule[8].target='ACCEPT'
firewall.@rule[9]=rule
firewall.@rule[9].name='Support-UDP-Traceroute'
firewall.@rule[9].src='wan'
firewall.@rule[9].dest_port='33434:33689'
firewall.@rule[9].proto='udp'
firewall.@rule[9].family='ipv4'
firewall.@rule[9].target='REJECT'
firewall.@rule[9].enabled='0'
firewall.@include[0]=include
firewall.@include[0].path='/etc/firewall.user'
firewall.@rule[10]=rule
firewall.@rule[10].target='ACCEPT'
firewall.@rule[10].proto='udp'
firewall.@rule[10].dest_port='55055'
firewall.@rule[10].name='wireguard'
firewall.@rule[10].src='wan'
firewall.@zone[2]=zone
firewall.@zone[2].name='wg'
firewall.@zone[2].input='ACCEPT'
firewall.@zone[2].forward='ACCEPT'
firewall.@zone[2].output='ACCEPT'
firewall.@zone[2].masq='1'
firewall.@zone[2].network='wg0'
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].src='wg'
firewall.@forwarding[1].dest='wan'
firewall.@forwarding[2]=forwarding
firewall.@forwarding[2].src='wan'
firewall.@forwarding[2].dest='wg'
firewall.@forwarding[3]=forwarding
firewall.@forwarding[3].src='wg'
firewall.@forwarding[3].dest='lan'
firewall.@forwarding[4]=forwarding
firewall.@forwarding[4].src='lan'
firewall.@forwarding[4].dest='wg'
firewall.wg=rule
firewall.wg.name='Allow-WireGuard'
firewall.wg.proto='udp'
firewall.wg.target='ACCEPT'
firewall.wg.src='wan'

interface: wg0
  public key: udbh56ZwEUupE74ZgxmRtYKJxH+4iKvt1R/h72B+qSk=
  private key: (hidden)
  listening port: 55055

peer: UBIH5up9WNmJh1TH+7qtA1lhHE5DmwuNedt4phBAgWs=
  endpoint: 46.134.155.68:9591
  allowed ips: 10.9.0.2/32
  latest handshake: 37 seconds ago
  transfer: 45.37 KiB received, 1.29 KiB sent
  persistent keepalive: every 25 seconds

Klient (TP link Archer C6 z OpenWRT) jako LAN podpięty pod modem Orange LTE
Konfiguracja sieci

network.loopback=interface
network.loopback.device='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.packet_steering='1'
network.globals.ula_prefix='fddf:ac12:0ce8::/48'
network.@device[0]=device
network.@device[0].name='br-lan'
network.@device[0].type='bridge'
network.@device[0].ports='lan1' 'lan2' 'lan3' 'lan4'
network.lan=interface
network.lan.device='br-lan'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.wan=interface
network.wan.device='wan'
network.wan.proto='dhcp'
network.wan6=interface
network.wan6.device='wan'
network.wan6.proto='dhcpv6'
network.wg0=interface
network.wg0.proto='wireguard'
network.wg0.private_key='YE2nZqB+vTTfAiYRmf2yDbpUxxS7li9a9qO1NxVmdWg='
network.wg0.addresses='10.9.0.2/32'
network.wg0.peerdns='0'
network.wg0.dns='192.168.0.1'
network.wg0.listen_port='55055'
network.@wireguard_wg0[0]=wireguard_wg0
network.@wireguard_wg0[0].public_key='udbh56ZwEUupE74ZgxmRtYKJxH+4iKvt1R/h72B+qSk='
network.@wireguard_wg0[0].route_allowed_ips='1'
network.@wireguard_wg0[0].endpoint_host='31.179.93.62'
network.@wireguard_wg0[0].persistent_keepalive='25'
network.@wireguard_wg0[0].description='openwrt'
network.@wireguard_wg0[0].allowed_ips='0.0.0.0/0'
network.@wireguard_wg0[0].endpoint_port=‚55055'

Konfiguracja Firewall

firewall.@defaults[0]=defaults
firewall.@defaults[0].input='ACCEPT'
firewall.@defaults[0].output='ACCEPT'
firewall.@defaults[0].forward='REJECT'
firewall.@defaults[0].synflood_protect='1'
firewall.@zone[0]=zone
firewall.@zone[0].name='lan'
firewall.@zone[0].network='lan'
firewall.@zone[0].input='ACCEPT'
firewall.@zone[0].output='ACCEPT'
firewall.@zone[0].forward='ACCEPT'
firewall.@zone[1]=zone
firewall.@zone[1].name='wan'
firewall.@zone[1].input='REJECT'
firewall.@zone[1].output='ACCEPT'
firewall.@zone[1].forward='REJECT'
firewall.@zone[1].masq='1'
firewall.@zone[1].mtu_fix='1'
firewall.@zone[1].network='wan6' 'wan' 'wg0'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src='lan'
firewall.@forwarding[0].dest='wan'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].src_ip='fc00::/6'
firewall.@rule[3].dest_ip='fc00::/6'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Input'
firewall.@rule[5].src='wan'
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-ICMPv6-Forward'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='*'
firewall.@rule[6].proto='icmp'
firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[6].limit='1000/sec'
firewall.@rule[6].family='ipv6'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-IPSec-ESP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].proto='esp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].name='Allow-ISAKMP'
firewall.@rule[8].src='wan'
firewall.@rule[8].dest='lan'
firewall.@rule[8].dest_port='500'
firewall.@rule[8].proto='udp'
firewall.@rule[8].target='ACCEPT'
firewall.@rule[9]=rule
firewall.@rule[9].name='Support-UDP-Traceroute'
firewall.@rule[9].src='wan'
firewall.@rule[9].dest_port='33434:33689'
firewall.@rule[9].proto='udp'
firewall.@rule[9].family='ipv4'
firewall.@rule[9].target='REJECT'
firewall.@rule[9].enabled='false'
firewall.@include[0]=include
firewall.@include[0].path='/etc/firewall.user'
firewall.@rule[10]=rule
firewall.@rule[10].src='wan'
firewall.@rule[10].target='ACCEPT'
firewall.@rule[10].proto='udp'
firewall.@rule[10].dest_port='55055'
firewall.@rule[10].name='wireguard'
firewall.@zone[2]=zone
firewall.@zone[2].name='wg'
firewall.@zone[2].input='ACCEPT'
firewall.@zone[2].forward='ACCEPT'
firewall.@zone[2].output='ACCEPT'
firewall.@zone[2].masq='1'
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].src='wg'
firewall.@forwarding[1].dest='wan'
firewall.@forwarding[2]=forwarding
firewall.@forwarding[2].src='wan'
firewall.@forwarding[2].dest='wg'
firewall.@forwarding[3]=forwarding
firewall.@forwarding[3].src='wg'
firewall.@forwarding[3].dest='lan'
firewall.@forwarding[4]=forwarding
firewall.@forwarding[4].src='lan'
firewall.@forwarding[4].dest=‚wg'

interface: wg0
  public key: UBIH5up9WNmJh1TH+7qtA1lhHE5DmwuNedt4phBAgWs=
  private key: (hidden)
  listening port: 55055

peer: udbh56ZwEUupE74ZgxmRtYKJxH+4iKvt1R/h72B+qSk=
  endpoint: 31.179.93.62:55055
  allowed ips: 0.0.0.0/0
  latest handshake: 1 minute, 19 seconds ago
  transfer: 316 B received, 27.93 KiB sent
  persistent keepalive: every 25 seconds


Co jest nie tak? 5 razy już resetowałem do ustawień fabrycznych i ustawiałem od nowa, jestem w tym nowy ,potrzebuje mieć na kliencie IP z UPC, żeby mieć możliwość korzystania z UPC TV BOX.
Proszę o pomoc.