Czesc,

zrobie na razie obraz z najnowszego AA, moze po zmianach w mac80211 cos sie poprawilo - a tak naprawde co co mam zglosic linux-wireless - przeciez na debianie mi chodzi bez problemu na WIndach tez.

Witam,

Może ktoś ma jakiś pomysl, jak zmusic sterownik – lub zmodyfikowac skrypty jakies aby zadziałała mi super karta wifi podlaczona do routera.

idea jest taka, ze mamy AP dalllekkkkoooo od nas – z czym się jest w stanie połączyć tylko ALFA z mala antenka kierunkowa – do kilometra mamy zasxieg z AP w okolicy a lokalnie nasz routerek sieje wifi do laptopikow i mamy kontakt ze swiatem. Kozyastalem z tego na wczasach ale siec była typu open – teraz chciałem sobie przygotowac routerek już na tip top na przyszłość, a tu chyba mam problem. Pomijając to ze ALFA swietnie otwiera zabezpieczone sieci .

Podlaczylem karte ALFA AWUS036h do USB routera rtl8187 zainstalowalem oczywiście.

Wszystko w sierpniu sprawdzałem chodzilo, wgrałem nawet tego samego bina openwrt i config. Działało na sieci Open, na wpa2 wpa cos nie bardzo chodzi. Caly czas nawet jak się polaczy to mija ulamek sekundy i się rozlacza. Próbowałem tez na releasie OpenWrt 38286 – i efekt jest ten sam.

Wydaje mi się ze tu problem jest ze sterownikiem

IEEE 802.11bg po zmianie /etc/config wireless na rtl8187 – karta nie laduje się mogole a



Ale jak wiadomo zgłasza od razu radio0(rtl8187) Interface not supported

Wifi pokazuje zazwyczaj 1 komunikat

Command failed: Device or resorce busy (-16)


Iw pokazuje:


root@OpenWrt:/# iw phy0 info
Wiphy phy0
        Band 1:
                Frequencies:
                        * 2412 MHz [1] (20.0 dBm)
                        * 2417 MHz [2] (20.0 dBm)
                        * 2422 MHz [3] (20.0 dBm)
                        * 2427 MHz [4] (20.0 dBm)
                        * 2432 MHz [5] (20.0 dBm)
                        * 2437 MHz [6] (20.0 dBm)
                        * 2442 MHz [7] (20.0 dBm)
                        * 2447 MHz [8] (20.0 dBm)
                        * 2452 MHz [9] (20.0 dBm)
                        * 2457 MHz [10] (20.0 dBm)
                        * 2462 MHz [11] (20.0 dBm)
                        * 2467 MHz [12] (20.0 dBm) (passive scanning, no IBSS)
                        * 2472 MHz [13] (20.0 dBm) (passive scanning, no IBSS)
                        * 2484 MHz [14] (20.0 dBm) (passive scanning, no IBSS)
                Bitrates (non-HT):
                        * 1.0 Mbps
                        * 2.0 Mbps
                        * 5.5 Mbps
                        * 11.0 Mbps
                        * 6.0 Mbps
                        * 9.0 Mbps
                        * 12.0 Mbps
                        * 18.0 Mbps
                        * 24.0 Mbps
                        * 36.0 Mbps
                        * 48.0 Mbps
                        * 54.0 Mbps
        max # scan SSIDs: 4
        max scan IEs length: 2285 bytes
        Coverage class: 0 (up to 0m)
        Supported Ciphers:
                * WEP40 (00-0f-ac:1)
                * WEP104 (00-0f-ac:5)
                * TKIP (00-0f-ac:2)
                * CCMP (00-0f-ac:4)
        Available Antennas: TX 0 RX 0
        Supported interface modes:
                 * IBSS
                 * managed
                 * monitor
        software interface modes (can always be added):
                 * monitor
        interface combinations are not supported
        Supported commands:
                 * new_interface
                 * set_interface
                 * new_key
                 * start_ap
                 * new_station
                 * new_mpath
                 * set_mesh_config
                 * set_bss
                 * authenticate
                 * associate
                 * deauthenticate
                 * disassociate
                 * join_ibss
                 * join_mesh
                 * set_tx_bitrate_mask
                 * frame
                 * frame_wait_cancel
                 * set_wiphy_netns
                 * set_channel
                 * set_wds_peer
                 * probe_client
                 * set_noack_map
                 * register_beacons
                 * Unknown command (89)
                 * Unknown command (92)
                 * testmode
                 * connect
                 * disconnect
        Supported TX frame types:
                 * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
                 * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
                 * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
                 * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
                 * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
                 * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
                 * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
                 * (null): 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
        Supported RX frame types:
                 * IBSS: 0x40 0xb0 0xc0 0xd0
                 * managed: 0x40 0xd0
                 * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
                 * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
                 * mesh point: 0xb0 0xc0 0xd0
                 * P2P-client: 0x40 0xd0
                 * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
                 * (null): 0x40 0xd0
        Device supports RSN-IBSS.
        HT Capability overrides:
                 * MCS: ff ff ff ff ff ff ff ff ff ff
                 * maximum A-MSDU length
                 * supported channel width
                 * short GI for 40 MHz
                 * max A-MPDU length exponent
                 * min MPDU start spacing
        Device supports TX status socket option.
        Device supports HT-IBSS.
root@OpenWrt:/#

Pozdrawiam,

Witam,


Mialem dziwny problem (raczej kolega)

Po wgraniu na 2 routerach GG, i zestawieniu ich w WDS maksymalnie laczyly sie na 150 ze soba, na oirginalnych softach w trybie auto lacza sie na 300 - co moze byc tego przyczyna ?


To miałem tak:
TP-Link TL-WR941ND
Firmware Version:
oryginalny przedtem i teraz Tp-linka:
3.13.9 Build 120201 Rel.54965n

Gargoyle:
gargoyle_1.5.10-ar71xx-generic-tl-wr941nd-v2-squashfs-factory.bin


tu przyklad 1 z routerow


Ktos mial podobne problemy ?

pepe2k napisał/a:
roblad napisał/a:

to jest te 27 dBm czy tylko 23 dBm dla 1943 ND

No nie ma 27 dBm... 1043ND potrafi maksymalnie, w zależności od kanału, 23-24 dBm.

roblad napisał/a:

po ustawieniu na 27 wydaje mi sie ze mam sygnal lepszy

Tylko Ci się wydaje.

chyba tak - ale bylem choc przez chwile szczesliwy - mozna w gargoyle zmienic to zeby faktyczne mozliwosci pokazywal a nie urojone w interfejsie www

Ostatecznie wybralem rozwiazanie gdzie dziala mwan3 i openvpn
WAN2 i tak mam za innym wirewalem z routera xx wiec dalem imput ACCEPT

Dodalem jeszcze role dot VPN

  * Forward 'lan' -> 'wan'
   * Forward 'lan' -> 'wan2'
   * Forward 'lan' -> 'wan3'
   * Forward 'lan' -> 'vpn'
   * Forward 'vpn' -> 'wan'
   * Forward 'vpn' -> 'wan2'


trzeba bylo jeszcze powielic forward portow tak jak dla wan to tez na wan2


moj konfig firewala wyglada tak

config defaults
        option syn_flood '1'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'

config zone
        option name 'lan'
        option network 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option conntrack '1'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan wan3'
        option conntrack '1'

config forwarding
        option src 'lan'
        option dest 'wan'

config zone
        option name 'wan2'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan2'
        option conntrack '1'

config forwarding
        option src 'lan'
        option dest 'wan2'

config zone
        option name 'wan3'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan3'
        option conntrack '1'

config forwarding
        option src 'lan'
        option dest 'wan3'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-Ping'
        option src 'wan2'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-Ping'
        option src 'wan3'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option src_ip 'fe80::/10'
        option src_port '547'
        option dest_ip 'fe80::/10'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config include
        option path '/etc/firewall.user'

config include
        option path '/usr/lib/gargoyle_firewall_util/gargoyle_additions.firewall'

config include 'openvpn_include_file'
        option path '/etc/openvpn.firewall'
        option reload '1'

config include 'miniupnpd'
        option type 'script'
        option path '/usr/share/miniupnpd/firewall.include'
        option family 'IPv4'
        option reload '1'

config zone 'vpn_zone'
        option name 'vpn'
        option network 'vpn'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        option mtu_fix '1'
        option masq '1'

config forwarding 'vpn_lan_forwarding'
        option src 'lan'
        option dest 'vpn'

config remote_accept 'ra_openvpn'
        option zone 'wan'
        option local_port '8086'
        option remote_port '8086'
        option proto 'udp'

config remote_accept 'ra_openvpn_2'       
        option zone 'wan2'                  
        option local_port '8086'
        option remote_port '8086'    
        option proto 'udp'   

config forwarding 'vpn_wan_forwarding'
        option src 'vpn'
        option dest 'wan'

config forwarding 'vpn_wan2_forwarding'      
        option src 'vpn'       
        option dest 'wan2'   
        
config remote_accept 'ra_443_8085'
        option local_port '443'
        option remote_port '8085'
        option proto 'tcp'
        option zone 'wan'

                                                
config remote_accept 'ra_443_8085_wan2'     
        option local_port '443'        
        option remote_port '8085'      
        option proto 'tcp'        
        option zone 'wan2' 

i smiga

A co do routerow TENDA czy PENTAGRAM

to jest tam wiele ciekawych opcji po wyexportowaniu ustawien tworzy sie plik

RouterCfm.cfg

w ktorym mozna nawet ustawic sobie opcje klienta wifi

jest opcja do ustawienia serwera czasu, szereg blokad oraz parametry radia

ja sobie dodalem trase statyczna i zaczytalem to spowrotem do routera

#The following line must not be removed.
Default
WebInit=en
HostName=Pent
Login=admin
Password=admin
OperationMode=1
Platform=RT3052
wanConnectionMode=DHCP
wan_ipaddr=0.0.0.0
wan_netmask=0.0.0.0
wan_gateway=0.0.0.0
wan_primary_dns=208.67.222.222
wan_secondary_dns=208.67.222.220
wan_pppoe_user=pppoe_user
wan_pppoe_pass=pppoe_passwd
wan_pppoe_mtu=1460
wan_pppoe_mru=1460
wan_l2tp_server=l2tp_server
wan_l2tp_user=l2tp_user
wan_l2tp_pass=l2tp_passwd
wan_l2tp_mode=1
wan_l2tp_ip=0.0.0.0
wan_l2tp_netmask=0.0.0.0
wan_l2tp_gateway=0.0.0.0
wan_pptp_server=pptp_server
wan_pptp_user=pptp_user
wan_pptp_pass=pptp_passwd
wan_pptp_mtu=1478
wan_pptp_mode=0
wan_pptp_ip=192.168.1.1
TZ=13
TZSel=26
NTPServerIP=
NTPSync=
DDNSProvider=0
DDNS=
DDNSAccount=
DDNSPassword=
CountryRegion=1
CountryRegionABand=7
CountryCode=CN     <<< to jest ciekawe bo mamy najwieksza moz i dmucha radiem jak trzeba
BssidNum=1
SSID1=robert_private_2_net_tel
WirelessMode=9
TxRate=0
Channel=2
BasicRate=15
BeaconPeriod=50
DtimPeriod=1
TxPower=100
DisableOLBC=0
BGProtection=0
TxAntenna=
RxAntenna=
TxPreamble=0
RTSThreshold=2347
FragThreshold=2346
TxBurst=0
PktAggregate=0
TurboRate=0
WmmCapable=0
APAifsn=3;7;1;1
APCwmin=4;4;3;2
APCwmax=6;10;4;3
APTxop=0;0;94;47
APACM=0;0;0;0
BSSAifsn=3;7;2;2
BSSCwmin=4;4;3;2
BSSCwmax=10;10;4;3
BSSTxop=0;0;94;47
BSSACM=0;0;0;0
AckPolicy=0;0;0;0
APSDCapable=0
DLSCapable=0
NoForwarding=0
NoForwardingBTNBSSID=0
HideSSID=0
ShortSlot=0
AutoChannelSelect=0
SecurityMode=0
VLANEnable=0
VLANName=
VLANID=0
VLANPriority=0
WscConfMode=0
WscConfStatus=2
WscAKMP=1
WscConfigured=0
WscModeOption=0
WscActionIndex=9
WscPinCode=
WscRegResult=1
WscUseUPnP=1
WscUseUFD=0
WscSSID=RalinkInitialAP
WscKeyMGMT=WPA-EAP
WscConfigMethod=138
HT_HTC=1
HT_RDG=1
HT_LinkAdapt=0
HT_OpMode=0
HT_MpduDensity=5
HT_EXTCHA=6
HT_BW=1
HT_AutoBA=1
HT_BADecline=0
HT_AMSDU=1
HT_BAWinSize=64
HT_GI=1
HT_STBC=1
HT_MCS=33
HT_PROTECT=1
HT_MIMOPS=3
HT_40MHZ_INTOLERANT=0
HT_TxStream=2
HT_RxStream=2
NintendoCapable=0
AccessPolicy0=0
AccessControlList0=
AccessPolicy1=0
AccessControlList1=
AccessPolicy2=0
AccessControlList2=
AccessPolicy3=0
AccessControlList3=
WdsEnable=0
WdsEncrypType=NONE
WdsList=
WdsKey=
WirelessEvent=0
RADIUS_Server=0
RADIUS_Port=1812
RADIUS_Key=
RADIUS_Acct_Server=
RADIUS_Acct_Port=1813
RADIUS_Acct_Key=
session_timeout_interval=3600
idle_timeout_interval=0
staWirelessMode=9
SinglePortFW1=
static_route_0=192.168.100.0;255.255.255.0;192.168.200.100
static_route_1=
static_route_2=
static_route_3=
static_route_4=
static_route_5=
static_route_6=
static_route_7=
static_route_8=
static_route_9=
static_route_10=
static_route_11=
static_route_12=
static_route_13=
static_route_14=
static_route_15=
wan_l2tp_mtu=1460
wan_l2tp_wip=
wan_l2tp_wmask=
wan_l2tp_wgw=
TimeMode=1
AcessPolicy=2
AccessControlList=
SSID2=
WPAPSK2=
Key1Str2=
Key2Str2=
Key3Str2=
Key4Str2=
own_ip_addr=192.168.200.1
EAPifname=br0
PreAuthifname=br0
macCloneEnabled=0
macCloneMac=
pptpMPPE=0
dynamicMTU=1500
staticMTU=1500
TendaVer=6
upnpEnabled=0
pppoeREnabled=0
dhcpStatic1=
dhcpStatic2=
dhcpStatic3=
dhcpipmacbind=0
dhcpipmaclist=
wan_1x_name=
wan_1x_pass=
x1AdrMode=1
x1_Mtu=1500
sta_ssid=
sta_mac=
sta_channel=6
sta_sec=3
sta_pass=
sta_wpaAlgorithms=1
sta_wep_key_index=4
sta_wep_mode=0
sta_wep_key_fmt=1
sta_wep_key_1=
sta_wep_key_2=
sta_wep_key_3=
sta_wep_key_4=
tc_enable=0
tc_isp_uprate=512
tc_isp_downrate=2048
tc_list_1=
tc_list_2=
tc_list_3=
tc_list_4=
tc_list_5=
tc_list_6=
tc_list_7=
tc_list_8=
tc_list_9=
tc_list_10=
tc_list_11=
tc_list_12=
tc_list_13=
tc_list_14=
tc_list_15=
tc_list_16=
tc_list_17=
tc_list_18=
tc_list_19=
tc_list_20=
pt_enable=0
pt_list_1=
pt_list_2=
pt_list_3=
pt_list_4=
pt_list_5=
pt_list_6=
pt_list_7=
pt_list_8=
pt_list_9=
pt_list_10=
nat_alg=11111
fmg_enable_manage=0
fmg_email_enable=0
fmg_email_smtpServer=
fmg_email_fromAddress=
fmg_email_toAddress=
fmg_email_userName=
fmg_email_password=
fmg_email_sendTime=60
fmg_email_issendByTime=0
fmg_email_issendByNum=1
fmg_email_sendNum=200
WirelessEnable=1
ApClinetEnable=0
NetAccountEnable=0
wwan_disable_nat=0
DHCP_plus_Name=
DHCP_plus_Pwd=
wpsMode=0
HT_DisallowTKIP=1

to jest te 27 dBm czy tylko 23 dBm dla 1943 ND - po ustawieniu na 27 wydaje mi sie ze mam sygnal lepszy ale zaraz sam router zmienia na 23 dBm i tu nie wiem o co chodzi.

Cos nie bardzo na tym routerze xx zrobilem po ciezkich akcjach (TENDA -zmiana poprzez wyexportowanie konfiguracji - backup i dopisanie wsekcji static route statycznego routingu - ale zadzialalo)

mam taka tabele:

Destination IP           Subnet Mask              Gateway               Metric   Interface
239.255.255.250          255.255.255.255     0.0.0.0                         0     br0
xxx.xxx.xxx.xxx          255.255.255.224     0.0.0.0                         0         eth2.2
192.168.100.0          255.255.255.0     192.168.200.100     0     br0
192.168.200.0          255.255.255.0      0.0.0.0                         0            br0
0.0.0.0                          0.0.0.0                      xxx.xxx.xxx.xxx         0      eth2.2

Druga strona jest taka:

Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         10.0.0.1        0.0.0.0         UG    10     0        0 eth0.2
0.0.0.0         192.168.200.1   0.0.0.0         UG    20     0        0 eth0.3
0.0.0.0         10.64.64.64     0.0.0.0         UG    30     0        0 3g-wan3
10.0.0.0        0.0.0.0         255.255.255.0   U     10     0        0 eth0.2
10.8.0.0        0.0.0.0         255.255.255.0   U     0      0        0 tun0
10.64.64.64     0.0.0.0         255.255.255.255 UH    0      0        0 3g-wan3
192.168.100.0   0.0.0.0         255.255.255.0   U     0      0        0 br-lan
192.168.200.0   0.0.0.0         255.255.255.0   U     20     0        0 eth0.3


no i nie widac z xx LAN na yy


moze cos na firewalu trzeba przestawic albo jeszcze jakis routing dodac

Z sieci 192.168.200.0 moge sie tylko pingowac na 192.168.100.100 inne adresy sa niewidoczne zadna usluga na 192.168.100.100 nie jest dostepna 80/443 porty


moj firewal

config defaults
        option syn_flood '1'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'

config zone
        option name 'lan'
        option network 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option conntrack '1'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan wan2 wan3'
        option conntrack '1'

config forwarding
        option src 'lan'
        option dest 'wan'

config zone
        option name 'wan2'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan2'
        option conntrack '1'

config forwarding
        option src 'lan'
        option dest 'wan2'

config zone
        option name 'wan3'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan3'
        option conntrack '1'

config forwarding
        option src 'lan'
        option dest 'wan3'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-Ping'
        option src 'wan2'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-Ping'
        option src 'wan3'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option src_ip 'fe80::/10'
        option src_port '547'
        option dest_ip 'fe80::/10'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config include
        option path '/etc/firewall.user'

config include
        option path '/usr/lib/gargoyle_firewall_util/gargoyle_additions.firewall'

config include 'openvpn_include_file'
        option path '/etc/openvpn.firewall'
        option reload '1'

config include 'miniupnpd'
        option type 'script'
        option path '/usr/share/miniupnpd/firewall.include'
        option family 'IPv4'
        option reload '1'

config zone 'vpn_zone'
        option name 'vpn'
        option network 'vpn'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        option mtu_fix '1'
        option masq '1'

config forwarding 'vpn_lan_forwarding'
        option src 'lan'
        option dest 'vpn'

config remote_accept 'ra_openvpn'
        option zone 'wan'
        option local_port '8086'
        option remote_port '8086'
        option proto 'udp'

config forwarding 'vpn_wan_forwarding'
        option src 'vpn'
        option dest 'wan'

config remote_accept 'ra_443_8085'
        option local_port '443'
        option remote_port '8085'
        option proto 'tcp'
        option zone 'wan'

nmap

Starting Nmap 6.40 ( http://nmap.org ) at 2013-10-13 00:26 CEST
NSE: Loaded 110 scripts for scanning.
NSE: Script Pre-scanning.
Initiating Ping Scan at 00:26
Scanning 192.168.100.100 [4 ports]
Completed Ping Scan at 00:26, 0.05s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 00:26
Completed Parallel DNS resolution of 1 host. at 00:26, 13.00s elapsed
Initiating SYN Stealth Scan at 00:26
Scanning 192.168.100.100 [1000 ports]
Increasing send delay for 192.168.100.100 from 0 to 5 due to 35 out of 86 dropped probes since last increase.
Increasing send delay for 192.168.100.100 from 5 to 10 due to 15 out of 36 dropped probes since last increase.
Completed SYN Stealth Scan at 00:27, 38.14s elapsed (1000 total ports)
Initiating Service scan at 00:27
Initiating OS detection (try #1) against 192.168.100.100
Retrying OS detection (try #2) against 192.168.100.100
Initiating Traceroute at 00:27
Completed Traceroute at 00:27, 0.01s elapsed
Initiating Parallel DNS resolution of 2 hosts. at 00:27
Completed Parallel DNS resolution of 2 hosts. at 00:27, 13.00s elapsed
NSE: Script scanning 192.168.100.100.
Initiating NSE at 00:27
Completed NSE at 00:27, 0.00s elapsed
Nmap scan report for 192.168.100.100
Host is up (0.0023s latency).
All 1000 scanned ports on 192.168.100.100 are closed
Too many fingerprints match this host to give specific OS details
Network Distance: 2 hops

TRACEROUTE (using port 3306/tcp)
HOP RTT     ADDRESS
1   7.82 ms 192.168.200.1
2   4.69 ms 192.168.100.100

NSE: Script Post-scanning.
Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 67.53 seconds
           Raw packets sent: 2009 (89.512KB) | Rcvd: 1032 (42.804KB)

Po zmianie w zone wan2

        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'

zobaczylem port https na ktorym mam forward zrobiony na wan do widzenia na zewnatrz

wydaje mi sie ze role w firewalu dla zone wan jest nadpisana dla wan2

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan wan2 wan3'    <<<<< to jest chyba problemem, ale jak to obejsc jak sie chce miec openvpn i mwana3
        option conntrack '1'

config defaults
        option syn_flood '1'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'

config zone
        option name 'lan'
        option network 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option conntrack '1'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan wan2 wan3'
        option conntrack '1'

config forwarding
        option src 'lan'
        option dest 'wan'

config zone
        option name 'wan2'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan2'
        option conntrack '1'

w firewalu gdzies jest problem bo jak zmienilem

w zonie

        option network 'wan wan2 wan3'
        option network 'wan  wan3'

to zaczelo forwardowac pakiety

Ktos moze pomoc w prawidlowej konfiguracji firewala ?

czy jak zostawie
    option network 'wan  wan3'
w zonie 'wan'

to wszystko mi bedize dzialac prawidlowo z uslugami czy gdzies cos nie zglupieje ?

Czy ktos ma pomysl jak to ustawic ?

834

(21 odpowiedzi, napisanych Oprogramowanie / Software)

Z tymi przekierowaniami jest cos nie tak,

Mam taki problem, ze niby jest przekierowany 433 na 8085 i dziala tylko jakis czas - w logachj nie moge nic znalezc - wyglada na to ze kladzie sie usluga i nie ma na serwerze http juz nasluchiwania na tym porcie po pewnym czasie. Po doswierzeniu opcji w www znowu sie pojawia i jakis czas chodzi.

Moze da sie jakos loga jakiegos ustawic zeby to podejzec co sie dzieje.

Tak szczegolnie 2 parametry

option beacon_int '40'
option short_preamble '1'

Tak, dopuszcone jest tez wiele innych rzeczy a my potrzebujemy czasami ciut wiecej - tu przyklad Alfy - piekna sprawa, kiedys udalo mi sie lacznosc nawiazac na 2 km poprzez Alfe w terenie dosc zabudowanym - oczywiscie nie zamierzam lamac prawa PIR - ale czasami do celow czysto naukowych by sie przydalo potestowac wiecej dBm :-)

PS.

Widze ze jestes tu na tym temacie aktywny - zerknij prosze na moj problem z openvpn - skontaktowalem sie z autorem mwan3 i okazalo sie ze w wersji 1.2.-18 jest bug autor zaleca wersje 1.2-20 w Twoim repozytorium jest 1.2.18 z bugiem - po wgraniu w zasadzie 1 skryptu od hotplug.d 15-xxxxx wszystko zaczelo mi dzialac na mwan3 - prosba do Ciebie o rozwiniecie troche tematu mwan3 - strasznie dlugo trzeba rozkminiac co autor mwan3 mial na mysli pomijajac ustawienia poczatkowe przypisania interfejsu do konkretnego WAN/WAN2/WAN3 itd


ACTION=ifup DEVICE=eth0.2 INTERFACE=wan /sbin/hotplug-call iface

pozdrawiam,

Witam,

Mam prosbe o pomoc, mam 2 WANy na routerze WAN i WAN2. Chcialbym polaczyc mozliwosc dostepu do zasobow lokalnych routera
LAN tego routera to 192.168.100.0/255.255.255.0 tam wchodzi WAN 10.0.0.155 ale tez WAN2 192.168.200.100 GW 192.168.200.1.

WAN2 jest wpiety poprzez router posredniczacy, do ktorego mozna sie polaczyc po wifi LAN 192.168.200.0. W sieci routera LAN
(na ktory wchodzi WAN2 - 192.168.200.100) 192.168.100.0 mam drukarke pod adresem 192.168.100.109.

Chcialbym aby po podlaczeniu do wifi do routera z siecia LAN 192.168.200.0 byly widoczne zasoby z routera gdzie wchodzi WAN2 o adresie sieci
192.168.100.0. Resumujac siec 192.168.200.0 jest WAN2 w routerze z LAN 192.168.100.0 i ni jak po konfiguracji firewala na routerze z siecia
192.168.100.0 oraz robienia forwardow WAN2 > LAN nie jest to widoczne.

http://fotoo.pl/show.php?img=630668_roz … d.jpg.html

patrzac na powyzszy rysunek po podlaczeniu sie do wifi routera xx chcialbym widziec zasoby LAN routera yy. W 2 strone to dziala czyli jak jestem na routerze yy to moge dostac sie do zasobow LAN routera xx.

ok,

tzn ze ma mozliwosci fizyczne czy nie ma te radio w tym modelu 500 mW ? Czy ogranicza to CRDA softwerowo (chyba nie, bo czy mam pakiet CRDA czy nie zachowanie jest takie samo). Dlaczego wiec pokazuje sterownik 500 Mw, mam Alfe - gdzie standardowo jest 20 , przestawia sie txpower i ma 27 dBm - ta karta ma 500 mW. Nie znalazlem mocy nadajnika nigdzie do 1043.
Podsumowujac ma 27 dBm czy nie ?

839

(80 odpowiedzi, napisanych Oprogramowanie / Software)

Witam,

root@router_glowny_extroot:~# ip route list table 1018
default  metric 1
        nexthop via 192.168.200.1  dev eth0.3 weight 2
        nexthop via 10.0.0.1  dev eth0.2 weight 8


okazalo sie wman3 w repo Cezarego jest przestarzaly - mam buga dlatego mialem problemy i z mwan3  skontaktowalem sie z autorem i to jego odpowiedz w sprawie niedzialajacego loadbalancu

"Which version of mwan3 are you using? The reason i ask is because there was a bug in earlier versions. The bug was that when an interface is named "wan", it would not work. So please update to version 1.2-20 or rename your "wan" interface to "wan1".
Jeroen."

Cezary mozesz zaktualizowac swoje repo do wersji 1.2-20 - po wgraniu nowej wersji - bez zmiany wan na wan1 wszystko zaczelo dzialac
z balancingiem routing openvpn do zasobow lokalnych po polaczeniu z serwerem openvpn dziala - fakt ze jak chodzi wan to na wan2 na openvpn sie nie podlaczy ale jak wan wraca to przelaczyc sie mozna bez problemu niestety nie trzyma konekcji na wan2 tylko sie zacina.


przelaczenie wan > wan2 >wan3 dziala niemal bez zauwazenia ze sie cos przelaczylo.


Warto jednak by opisac cos wiecej o mwan3 na stronkach eko - totalna czarna magia - i dzien zajmuje aby zrozumiec co autor mwan3 mial na mysli.

Witam,

z autorem sie skontaktowalem i dal mi rozwiazanie ale generalnie update trzeba zrobic do mwan3

"Which version of mwan3 are you using? The reason i ask is because there was a bug in earlier versions. The bug was that when an interface is named "wan", it would not work. So please update to version 1.2-20 or rename your "wan" interface to "wan1


Jeroen."

Czesc,

to dlaczego tyle sie pokazuje ?

Witam

iwconfig pokazuje mi
wlan0     IEEE 802.11bgn  Mode:Master  Tx-Power=23 dBm   
          RTS thr=2347 B   Fragment thr=2346 B   
          Power Management:off
         

choc powinien 27 dBm

ustawienbia wifi

cat /etc/config/wireless 

config wifi-device 'radio0'
        option type 'mac80211'
        option hwmode '11ng'
        option macaddr 'f8:d1:11:b7:41:56'
        option noscan '1'
        list ht_capab 'HT40- HT40+'
        list ht_capab 'DSSS_CCK-40'
        list ht_capab 'RX HT40 SGI'
        list ht_capab 'SHORT-GI-40'
        list ht_capab 'DSSS/CCK HT40'
        option short_preamble '1'
        option country 'US'
        option distance '2000'
        option frag '2346'
        option rts '2347'
        option htmode 'HT40+'
        option txpower '27'
        option channel '7'
        option beacon_int '40'

config wifi-iface 'ap_g'
        option device 'radio0'
        option mode 'ap'

po wykonaniu komendy wifi

ustawia sie na 27 dBm

co za ciortrt - dodalem w rc.local dodatkowo komende wifi ale nie pomaga

dopiero jak wejde na konsole przez ssh zmienie country na BO np i po  wykonam wifi to sie przestawia,

wlan0     IEEE 802.11bgn  Mode:Master  Tx-Power=27 dBm   
          RTS thr=2347 B   Fragment thr=2346 B   
          Power Management:off

co to moze byc ?

Pozdr

843

(80 odpowiedzi, napisanych Oprogramowanie / Software)

Dodatkowo nie widzi zasobow lokalnych openvpn jesli polacze sie na wan2 cos nie przestawia rutingu po zmianie w /etc/openvpn/server/route_data z 192.168.100.0 255.255.255.0 10.8.0.0 na 192.168.0.0 255.255.255.0 10.8.0.0 widzi zasoby lokalne - co z tego jak po restarcie mi to zniknie.

Jak jest podniesiony wan i wan2 to do openvpn moge sie podlaczyc tylko na wan po polozeniu wan moge polkaczyc sie na wan2

Load balancing tez mi nie dziala na multiwanie dzialal - tu idzie wan nie idzie przez wan i wan2


dodatkowo po polozeniu wan czy wan2 interfejsy nie podnosza sie same

moj nowy config - od rana walcze z mwan3 - i jest kicha

cat /etc/config/mwan3 
# This is a mwan3 example config. For mwan3 to work you will need at least:
#
# - 2 interfaces
# - 2 members
# - 1 policy
# - 1 rule
#
# First define all your wan interfaces. Interface name must match with the
# name used in your network configuration:

config 'interface' 'wan'
        option 'enabled' '1'
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '8.8.8.8'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '3'
        option 'count' '1'
        option 'timeout' '2'
        option 'interval' '5'
        option 'down' '3'
        option 'up' '5'
        option 'reroute' '0'

config 'interface' 'wan2'
        option 'enabled' '1'
        list 'track_ip' '8.8.8.8'
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '1'
        option 'count' '1'
        option 'timeout' '2'
        option 'interval' '5'
        option 'down' '3'
        option 'up' '5'
        option 'reroute' '0'


config 'interface' 'wan3'               
        option 'enabled' '1'            
        list 'track_ip' '8.8.8.8'       
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '3'        
        option 'count' '1'              
        option 'timeout' '5'            
        option 'interval' '60'           
        option 'down' '4'               
        option 'up' '8'                 
        option 'reroute' '0'  


# Next define a member and configure metric and weight values for this member.
# Each interface can have multiple member definitions. Give each member a correct
# name (A-Z, a-z, 0-9, "_" and no spaces).

config member 'wan_m1_w1'
       option metric '1'
       option weight '5'
       option interface 'wan'
            
config member 'wan_m2_w2'
       option metric '2'
       option weight '5'
       option interface 'wan'     
              
config member 'wan2_m1_w1'
       option interface 'wan2'
       option metric '1'
       option weight '3'

config member 'wan2_m2_w2'
       option interface 'wan2'
       option metric '2'
       option weight '3'

   
# After that create a routing policy. A routing policy consist of one or more
# members. Give each policy a correct name (A-Z, a-z, 0-9, "_" and no spaces). You 
# can create multiple policies, so that it is possible for different traffic to
# have different primary and/or backup interfaces.

config policy 'wan_only'
        list use_member 'wan_m1_w1'

config policy 'wan2_only'
        list use_member 'wan2_m1_w1'
            
config 'policy' 'wan_wan2_loadbalanced'
    list 'use_member' 'wan1_m1_w1'
    list 'use_member' 'wan2_m2_w2'

config policy 'wan_pri_wan2_sec'
       list 'use_member' 'wan1_m1_w1'
       list 'use_member' 'wan2_m2_w2'

config policy 'wan2_pri_wan_sec'
       list 'use_member' 'wan2_m1_w1'
       list 'use_member' 'wan_m2_w2'
                              
# And to finish the config define your traffic rules. Rules are matched in top to
# bottom order. If you define a rule and it matches, all following rules are ignored.
#
# If the option equalize is set, mwan3 will load-balance each new session to the same
# host. If not set, it will load-balance based on destination.


#config 'rule'
#    option 'dest_ip' '192.168.0.0/24'
#    option 'proto' 'tcp'

#    option 'use_policy' 'default'

config 'rule'

    option 'dest_ip' '0.0.0.0/0'
    option proto 'all'
    option 'use_policy' 'wan_wan2_loadbalanced'
     option equalize '1'



  - naprawde jest cos nie tak albo z openvpn i mwan3 - trzeba miec naprawde mocne doswiadczenie w tym zeby to skonfigurowac od podstaw sie nie da

Witam,

Czy mozecie zerknac na ten wontek

http://eko.one.pl/forum/viewtopic.php?pid=88071#p88071

nie umiem skonfigurowac mwana3

845

(80 odpowiedzi, napisanych Oprogramowanie / Software)

Prosze o pomoc - bo niedlugo wywale wszystkie routery z domu i bede bebnami nadawal


zainstalowalem mwan3 - i pojawiaja sie problemy

Same schody

zaczynamy po instalacji i konfigu mwana3

# This is a mwan3 example config. For mwan3 to work you will need at least:
#
# - 2 interfaces
# - 2 members
# - 1 policy
# - 1 rule
#
# First define all your wan interfaces. Interface name must match with the
# name used in your network configuration:

config 'interface' 'wan'
        option 'enabled' '1'
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '8.8.8.8'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '3'
        option 'count' '1'
        option 'timeout' '2'
        option 'interval' '5'
        option 'down' '3'
        option 'up' '5'
        option 'reroute' '0'

config 'interface' 'wan2'
        option 'enabled' '1'
        list 'track_ip' '8.8.8.8'
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '1'
        option 'count' '1'
        option 'timeout' '2'
        option 'interval' '5'
        option 'down' '3'
        option 'up' '5'
        option 'reroute' '0'


config 'interface' 'wan3'               
        option 'enabled' '1'            
        list 'track_ip' '8.8.8.8'       
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '3'        
        option 'count' '1'              
        option 'timeout' '5'            
        option 'interval' '10'           
        option 'down' '3'               
        option 'up' '8'                 
        option 'reroute' '0'  


# Next define a member and configure metric and weight values for this member.
# Each interface can have multiple member definitions. Give each member a correct
# name (A-Z, a-z, 0-9, "_" and no spaces).

config member 'wan_m1_w2'
       option metric '1'
       option weight '2'
       option interface 'wan'
            
config member 'wan_m2_w2'
       option metric '2'
       option weight '2'
       option interface 'wan'
                        
config member 'wan2_m1_w2'
       option interface 'wan2'
       option metric '1'
       option weight '2'
                                    
config member 'wan2_m2_w2'
       option interface 'wan2'
       option metric '2'
       option weight '2'
                                                
config member 'wan3_m1_w1'
       option interface 'wan3'
       option metric '1'
       option weight '2'
                                                            
config member 'wan3_m2_w1'
       option interface 'wan3'
       option metric '2'
       option weight '2'

# After that create a routing policy. A routing policy consist of one or more
# members. Give each policy a correct name (A-Z, a-z, 0-9, "_" and no spaces). You 
# can create multiple policies, so that it is possible for different traffic to
# have different primary and/or backup interfaces.

config policy 'wan_only'
       list use_member 'wan_m1_w2'
    
config policy 'wan2_only'
       list use_member 'wan2_m1_w2'
        
config policy 'wan3_only'
       list use_member 'wan3_m1_w1'
            
config 'policy' 'wan1_wan2_loadbalanced'
    list 'use_member' 'wan1_m1_w2'
    list 'use_member' 'wan2_m1_w2'

                        
config policy 'wan_pri_wan2_sec'
       list use_member 'wan_m1_w2'
       list use_member 'wan2_m2_w2'
                                
config policy 'wan2_pri_wan_sec'
       list use_member 'wan_m2_w2'
       list use_member 'wan2_m1_w2'
                                        



# And to finish the config define your traffic rules. Rules are matched in top to
# bottom order. If you define a rule and it matches, all following rules are ignored.
#
# If the option equalize is set, mwan3 will load-balance each new session to the same
# host. If not set, it will load-balance based on destination.

config 'rule'
    option 'dest_ip' '192.168.0.0/24'
    option 'proto' 'tcp'
    option 'use_policy' 'default'

config 'rule'

    option 'dest_ip' '0.0.0.0/0'
    option 'equalize' '1'
    option 'use_policy' 'wan1_wan2_loadbalanced'

/etc/init.d/mwan3 restart  - trwa strasznie dlugo


no i errory

uci: Entry not found
sh: wan: unknown operand
ERROR: No valid dynamic DNS service configurations defined  <<< to jest known error - ale nie wiadomo czy ma wplyw na cos nie mam ddns
(Did you specify correct configuration file path?)
uci: Entry not found
sh: wan2: unknown operand
uci: Entry not found
sh: wan3: unknown operand

/etc/init.d/mwan3 start

uci: Entry not found
sh: wan: unknown operand
ERROR: No valid dynamic DNS service configurations defined
(Did you specify correct configuration file path?)
uci: Entry not found
sh: wan3: unknown operand
uci: Entry not found
sh: wan2: unknown operand
uci: Entry not found
sh: wan3: unknown operand

route

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
default         10.0.0.1        0.0.0.0         UG    10     0        0 eth0.2
default         192.168.200.1   0.0.0.0         UG    20     0        0 eth0.3
default         10.64.64.64     0.0.0.0         UG    30     0        0 3g-wan3
10.0.0.0        *               255.255.255.0   U     10     0        0 eth0.2
10.8.0.0        *               255.255.255.0   U     0      0        0 tun0
10.64.64.64     *               255.255.255.255 UH    0      0        0 3g-wan3
192.168.100.0   *               255.255.255.0   U     0      0        0 br-lan
192.168.200.0   *               255.255.255.0   U     20     0        0 eth0.3

route -n

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         10.0.0.1        0.0.0.0         UG    10     0        0 eth0.2
0.0.0.0         192.168.200.1   0.0.0.0         UG    20     0        0 eth0.3
0.0.0.0         10.64.64.64     0.0.0.0         UG    30     0        0 3g-wan3
10.0.0.0        0.0.0.0         255.255.255.0   U     10     0        0 eth0.2
10.8.0.0        0.0.0.0         255.255.255.0   U     0      0        0 tun0
10.64.64.64     0.0.0.0         255.255.255.255 UH    0      0        0 3g-wan3
192.168.100.0   0.0.0.0         255.255.255.0   U     0      0        0 br-lan
192.168.200.0   0.0.0.0         255.255.255.0   U     20     0        0 eth0.3

ifconfig


3g-wan3   Link encap:Point-to-Point Protocol  
          inet addr:151.248.32.209  P-t-P:10.64.64.64  Mask:255.255.255.255
          UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1
          RX packets:1407 errors:0 dropped:0 overruns:0 frame:0
          TX packets:1426 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:3 
          RX bytes:117552 (114.7 KiB)  TX bytes:119178 (116.3 KiB)

br-lan    Link encap:Ethernet  HWaddr F8:D1:11:B7:41:56  
          inet addr:192.168.100.100  Bcast:192.168.100.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:14363 errors:0 dropped:5 overruns:0 frame:0
          TX packets:13081 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 
          RX bytes:1744978 (1.6 MiB)  TX bytes:6250600 (5.9 MiB)

eth0      Link encap:Ethernet  HWaddr F8:D1:11:B7:41:56  
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:103076 errors:0 dropped:0 overruns:59886 frame:0
          TX packets:45745 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000 
          RX bytes:17012323 (16.2 MiB)  TX bytes:7567712 (7.2 MiB)
          Interrupt:4 

eth0.1    Link encap:Ethernet  HWaddr F8:D1:11:B7:41:56  
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:7027 errors:0 dropped:0 overruns:0 frame:0
          TX packets:7858 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 
          RX bytes:988553 (965.3 KiB)  TX bytes:2866322 (2.7 MiB)

eth0.2    Link encap:Ethernet  HWaddr F8:D1:11:B7:41:56  
          inet addr:10.0.0.155  Bcast:10.0.0.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:9544 errors:0 dropped:2 overruns:0 frame:0
          TX packets:3163 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 
          RX bytes:772292 (754.1 KiB)  TX bytes:370705 (362.0 KiB)

eth0.3    Link encap:Ethernet  HWaddr C8:3A:35:4E:4F:CD  
          inet addr:192.168.200.100  Bcast:192.168.200.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:2444 errors:0 dropped:0 overruns:0 frame:0
          TX packets:2139 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 
          RX bytes:239013 (233.4 KiB)  TX bytes:216762 (211.6 KiB)

lo        Link encap:Local Loopback  
          inet addr:127.0.0.1  Mask:255.0.0.0
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:5475 errors:0 dropped:0 overruns:0 frame:0
          TX packets:5475 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0 
          RX bytes:519493 (507.3 KiB)  TX bytes:519493 (507.3 KiB)

tun0      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00  
          inet addr:10.8.0.1  P-t-P:10.8.0.1  Mask:255.255.255.0
          UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100 
          RX bytes:0 (0.0 B)  TX bytes:0 (0.0 B)

wlan0     Link encap:Ethernet  HWaddr F8:D1:11:B7:41:56  
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:10276 errors:0 dropped:0 overruns:0 frame:0
          TX packets:12354 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000 
          RX bytes:1328027 (1.2 MiB)  TX bytes:6165903 (5.8 MiB)

ip rule

0:      from all lookup local 
1001:   from all fwmark 0x100/0xff00 lookup 1001 
1002:   from all fwmark 0x200/0xff00 lookup 1002 
1003:   from all fwmark 0x300/0xff00 lookup 1003 
1016:   from all fwmark 0x1000/0xff00 lookup 1016 
1017:   from all fwmark 0x1100/0xff00 lookup 1017 
1018:   from all fwmark 0x1200/0xff00 lookup 1018 
1019:   from all fwmark 0x1300/0xff00 lookup 1019 
1020:   from all fwmark 0x1400/0xff00 lookup 1020 
1021:   from all fwmark 0x1500/0xff00 lookup 1021 
32766:  from all lookup main 
32767:  from all lookup default 

Po zrobieniu ifdown pokoleii wan > wan2

przelacza sie


ale wywalaja sie bledy nastepne


ifdown wan
root@router_glowny_extroot:~# ifdown wan2
root@router_glowny_extroot:~# Cannot find device "eth0.2"
Cannot find device "eth0.3"


cat /etc/config/network

config interface 'loopback'
        option ifname 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config interface 'lan'
        option ifname 'eth0.1'
        option type 'bridge'
        option proto 'static'
        option netmask '255.255.255.0'
        option ipaddr '192.168.100.100'
        option dns '208.67.222.222 208.67.220.220'

config interface 'wan'
        option auto '1'
        option ifname 'eth0.2'
        option proto 'static'
        option ipaddr '10.0.0.155'
        option netmask '255.255.255.0'
        option gateway '10.0.0.1'
        option dns '208.67.222.222 208.67.220.220'
        option metric '10'
        option peerdns '0'

config interface 'wan2'
        option auto '1'
        option ifname 'eth0.3'
        option macaddr 'C8:3A:35:4E:4F:CD'
        option proto 'dhcp'
        option peerdns '1'
        option dns '208.67.220.220 208.67.222.222'
        option defaultroute '1'
        option metric '20'

config interface 'wan3'
        option auto '1'
        option proto '3g'
        option device '/dev/ttyUSB0'
        option apn 'darmowy'
        option service 'umts'
        option mobile_isp 'Polska - Aero2'
        option peerdns '0'
        option dns '208.67.220.220 208.67.222.222'
        option defaultroute '1'
        option metric '30'

config switch
        option enable '1'
        option name 'rtl8366rb'
        option reset '1'
        option enable_vlan '1'
        option blinkrate '2'

config switch_vlan
        option device 'rtl8366rb'
        option vlan '1'
        option ports '2 3 4 5t'

config switch_vlan
        option device 'rtl8366rb'
        option vlan '2'
        option ports '0 5t'

config switch_vlan
        option device 'rtl8366rb'
        option vlan '3'
        option ports '1 5t'

config interface 'vpn'
        option ifname 'tun0'
        option proto 'none'
        option defaultroute '0'
        option peerdns '0'

Nie bardzo wiem co autor mial na mysli mowiac o zmianie parametrow i gdzie je zmienic nie napisal


ACTION=ifup DEVICE=eth0.1 INTERFACE=wan1 /sbin/hotplug-call iface


czy mam wydac taka komende tylko czy gdzies dopisac

ACTION=ifup DEVICE=eth0.2 INTERFACE=wan /sbin/hotplug-call iface

O CO TU CHODZI ?
po wydaniu komendy mam nastepny blad

ACTION=ifup DEVICE=eth0.2 INTERFACE=wan /sbin/hotplug-call iface
Cannot find device "eth0.2"


ACTION=ifup DEVICE=eth0.3 INTERFACE=wan2 /sbin/hotplug-call iface
uci: Entry not found
sh: wan2: unknown operand


root@router_glowny_extroot:~# ACTION=ifup DEVICE=3g INTERFACE=wan3 /sbin/hotplug-call iface
Cannot find device "3g"


oprocz tego interfejsy sie same klada pozostaje albo 1 albo 2 a widac je dopiero jak recznie sie podniesie ifup wan wan2 wan3



Co ja robie nie tak zgodnie z moimi zalozeniami chcialbym aby jakos to dzialalo - multiwan nie dziala prawidlowo a mwan3 to jakis kosmos z konfiguracja nie wiadomo o co chodzi


Nie wiem o co chodzi w  rolach ip

# ip rule show
0:      from all lookup local 
1001:   from all fwmark 0x100/0xff00 lookup 1001 
1002:   from all fwmark 0x200/0xff00 lookup 1002 
1003:   from all fwmark 0x300/0xff00 lookup 1003 
1016:   from all fwmark 0x1000/0xff00 lookup 1016 
1017:   from all fwmark 0x1100/0xff00 lookup 1017 
1018:   from all fwmark 0x1200/0xff00 lookup 1018 
1019:   from all fwmark 0x1300/0xff00 lookup 1019 
1020:   from all fwmark 0x1400/0xff00 lookup 1020 
1021:   from all fwmark 0x1500/0xff00 lookup 1021 
32766:  from all lookup main 
32767:  from all lookup default 
root@router_glowny_extroot:~# ip route list table 1001
default via 10.0.0.1 dev eth0.2 
root@router_glowny_extroot:~# ip route list table 1002
default via 192.168.200.1 dev eth0.3 
root@router_glowny_extroot:~# ip route list table 1016
default via 10.0.0.1 dev eth0.2  metric 1 
root@router_glowny_extroot:~# ip route list table 1017
default via 192.168.200.1 dev eth0.3  metric 1 
root@router_glowny_extroot:~# ip route list table 1018
default via 10.64.64.64 dev 3g-wan3  metric 1 
root@router_glowny_extroot:~# ip route list table 1019
default via 192.168.200.1 dev eth0.3  metric 1 
root@router_glowny_extroot:~# ip route list table 1020
default via 10.0.0.1 dev eth0.2  metric 1 
default via 192.168.200.1 dev eth0.3  metric 2 
root@router_glowny_extroot:~# ip route list table 1021
default via 192.168.200.1 dev eth0.3  metric 1 
default via 10.0.0.1 dev eth0.2  metric 2 
root@router_glowny_extroot:~# ip route list table 1003
default via 10.64.64.64 dev 3g-wan3 
root@router_glowny_extroot:~# 

Nie mam  nigdzie weight

Dodatkowo nie wiem czy to dobrze pokazuje

iptables -L mwan3_pre -t mangle -v -n



Chain mwan3_pre (2 references)
 pkts bytes target     prot opt in     out     source               destination         
31734 4117K CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0           CONNMARK restore mask 0xff00 
 1547  116K MARK       all  --  eth0.2 *       0.0.0.0/0            0.0.0.0/0           MARK xset 0x8100/0xff00 
 1402  193K MARK       all  --  eth0.3 *       0.0.0.0/0            0.0.0.0/0           MARK xset 0x8200/0xff00 
  281 23604 MARK       all  --  3g-wan3 *       0.0.0.0/0            0.0.0.0/0           MARK xset 0x8300/0xff00 
 5463  429K mwan3_default  all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 
 3722  302K mwan3_interfaces  all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 
  284 20490 mwan3_rules  all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 

ptables -L mwan3_post -t mangle -v -n


Chain mwan3_post (2 references)
 pkts bytes target     prot opt in     out     source               destination         
 1383  109K MARK       all  --  *      eth0.2  0.0.0.0/0            0.0.0.0/0           mark match !0x7f00/0xff00 MARK xset 0x100/0xff00 
 1439  210K MARK       all  --  *      eth0.3  0.0.0.0/0            0.0.0.0/0           mark match !0x7f00/0xff00 MARK xset 0x200/0xff00 
  317 26628 MARK       all  --  *      3g-wan3  0.0.0.0/0            0.0.0.0/0           mark match !0x7f00/0xff00 MARK xset 0x300/0xff00 
10659 1288K MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x8000/0x8000 MARK and 0xffff7fff 
30488 4097K CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0           CONNMARK save mask 0xff00 


ptables -L mwan3_default -t mangle -v -n


Chain mwan3_default (1 references)
 pkts bytes target     prot opt in     out     source               destination         
  162 10313 MARK       all  --  *      *       0.0.0.0/0            224.0.0.0/3         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            127.0.0.0/8         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            10.0.0.0/24         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            10.8.0.0/24         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            10.64.64.64         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    6   361 MARK       all  --  *      *       0.0.0.0/0            192.168.100.0/24    mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            192.168.200.0/24    mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 


iptables -L mwan3_rules -t mangle -v -n


Chain mwan3_rules (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       tcp  --  *      *       0.0.0.0/0            192.168.0.0/24      multiport sports 0:65535 multiport dports 0:65535 mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
   29  2052 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 MARK xset 0x1300/0xff00 


wogole nie ma TUNa


czy nie moze to byc prostrze - nie jestem w stanie zrozumiec tego - za glupi jestem, moze ktos pomoze

Na koniec zestaw komen, ktore moze pomoga rozwiklac tajemnice


ip rule
route -n
iptables -L -t mangle -v -n
cat /etc/config/mwan3
cat /etc/config/network
ip route list table 1001
ip route list table 1002
cat /etc/config/firewall

root@router_glowny_extroot:~# ip rule
0:      from all lookup local 
1001:   from all fwmark 0x100/0xff00 lookup 1001 
1002:   from all fwmark 0x200/0xff00 lookup 1002 
1003:   from all fwmark 0x300/0xff00 lookup 1003 
1016:   from all fwmark 0x1000/0xff00 lookup 1016 
1017:   from all fwmark 0x1100/0xff00 lookup 1017 
1018:   from all fwmark 0x1200/0xff00 lookup 1018 
1019:   from all fwmark 0x1300/0xff00 lookup 1019 
1020:   from all fwmark 0x1400/0xff00 lookup 1020 
1021:   from all fwmark 0x1500/0xff00 lookup 1021 
32766:  from all lookup main 
32767:  from all lookup default 
root@router_glowny_extroot:~# route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         10.0.0.1        0.0.0.0         UG    10     0        0 eth0.2
0.0.0.0         192.168.200.1   0.0.0.0         UG    20     0        0 eth0.3
0.0.0.0         10.64.64.64     0.0.0.0         UG    30     0        0 3g-wan3
10.0.0.0        0.0.0.0         255.255.255.0   U     10     0        0 eth0.2
10.8.0.0        0.0.0.0         255.255.255.0   U     0      0        0 tun0
10.64.64.64     0.0.0.0         255.255.255.255 UH    0      0        0 3g-wan3
192.168.100.0   0.0.0.0         255.255.255.0   U     0      0        0 br-lan
192.168.200.0   0.0.0.0         255.255.255.0   U     20     0        0 eth0.3
root@router_glowny_extroot:~# iptables -L -t mangle -v -n
Chain PREROUTING (policy ACCEPT 8382 packets, 822K bytes)
 pkts bytes target     prot opt in     out     source               destination         
26226 3209K mwan3_pre  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 8382  822K fwmark     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain INPUT (policy ACCEPT 4771 packets, 404K bytes)
 pkts bytes target     prot opt in     out     source               destination         
  252 28983 openvpn_down_bw  udp  --  eth0.2 *       0.0.0.0/0            0.0.0.0/0           udp dpt:8086 
16065 1372K mwan3_post  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain FORWARD (policy ACCEPT 1517 packets, 286K bytes)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 openvpn_up_bw  all  --  tun0   eth0.2  0.0.0.0/0            0.0.0.0/0           
    0     0 openvpn_down_bw  all  --  eth0.2 tun0    0.0.0.0/0            0.0.0.0/0           
 1517  286K mssfix     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain OUTPUT (policy ACCEPT 4628 packets, 589K bytes)
 pkts bytes target     prot opt in     out     source               destination         
  835 78696 openvpn_up_bw  udp  --  *      eth0.2  0.0.0.0/0            0.0.0.0/0           udp spt:8086 
15602 2014K mwan3_pre  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain POSTROUTING (policy ACCEPT 6147 packets, 876K bytes)
 pkts bytes target     prot opt in     out     source               destination         
21549 3586K mwan3_post  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 3148  261K bw_egress  all  --  *      eth0.2  0.0.0.0/0            0.0.0.0/0           

Chain bw_egress (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id total1-upload-2-449 --type combined --current_bandwidth 0 --reset_interval 2 --reset_time 2 --intervals_to_save 449 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           match-set local_addr_set src bandwidth --id bdist1-upload-minute-15 --type individual_src --reset_interval minute --intervals_to_save 15 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id total2-upload-minute-359 --type combined --current_bandwidth 0 --reset_interval minute --intervals_to_save 359 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           match-set local_addr_set src bandwidth --id bdist2-upload-900-24 --type individual_src --reset_interval 900 --reset_time 900 --intervals_to_save 24 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id total3-upload-180-479 --type combined --current_bandwidth 0 --reset_interval 180 --reset_time 180 --intervals_to_save 479 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           match-set local_addr_set src bandwidth --id bdist3-upload-hour-24 --type individual_src --reset_interval hour --intervals_to_save 24 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id total4-upload-7200-359 --type combined --current_bandwidth 0 --reset_interval 7200 --reset_time 7200 --intervals_to_save 359 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           match-set local_addr_set src bandwidth --id bdist4-upload-day-31 --type individual_src --reset_interval day --intervals_to_save 31 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id total5-upload-day-365 --type combined --current_bandwidth 0 --reset_interval day --intervals_to_save 365 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           match-set local_addr_set src bandwidth --id bdist5-upload-month-12 --type individual_src --reset_interval month --intervals_to_save 12 

Chain fwmark (1 references)
 pkts bytes target     prot opt in     out     source               destination         

Chain mssfix (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 TCPMSS     tcp  --  *      eth0.2  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 /* wan (mtu_fix) */ TCPMSS clamp to PMTU 
   22  1320 TCPMSS     tcp  --  *      eth0.3  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 /* wan (mtu_fix) */ TCPMSS clamp to PMTU 
    0     0 TCPMSS     tcp  --  *      3g-wan3  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 /* wan (mtu_fix) */ TCPMSS clamp to PMTU 
   22  1320 TCPMSS     tcp  --  *      eth0.3  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 /* wan2 (mtu_fix) */ TCPMSS clamp to PMTU 
    0     0 TCPMSS     tcp  --  *      3g-wan3  0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 /* wan3 (mtu_fix) */ TCPMSS clamp to PMTU 
    0     0 TCPMSS     tcp  --  *      tun0    0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 /* vpn (mtu_fix) */ TCPMSS clamp to PMTU 

Chain mwan3_default (1 references)
 pkts bytes target     prot opt in     out     source               destination         
  395 23568 MARK       all  --  *      *       0.0.0.0/0            224.0.0.0/3         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            127.0.0.0/8         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            10.0.0.0/24         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            10.8.0.0/24         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            10.64.64.64         mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
   11   864 MARK       all  --  *      *       0.0.0.0/0            192.168.100.0/24    mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
    0     0 MARK       all  --  *      *       0.0.0.0/0            192.168.200.0/24    mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 

Chain mwan3_interfaces (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 3575  294K mwan3_wan3  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 3235  267K mwan3_wan2  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 2197  181K mwan3_wan  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain mwan3_post (2 references)
 pkts bytes target     prot opt in     out     source               destination         
 3428  284K MARK       all  --  *      eth0.2  0.0.0.0/0            0.0.0.0/0           mark match !0x7f00/0xff00 MARK xset 0x100/0xff00 
 2357  346K MARK       all  --  *      eth0.3  0.0.0.0/0            0.0.0.0/0           mark match !0x7f00/0xff00 MARK xset 0x200/0xff00 
  493 41412 MARK       all  --  *      3g-wan3  0.0.0.0/0            0.0.0.0/0           mark match !0x7f00/0xff00 MARK xset 0x300/0xff00 
13997 1618K MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x8000/0x8000 MARK and 0xffff7fff 
37614 4958K CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0           CONNMARK save mask 0xff00 

Chain mwan3_pre (2 references)
 pkts bytes target     prot opt in     out     source               destination         
41828 5222K CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0           CONNMARK restore mask 0xff00 
 5588  429K MARK       all  --  eth0.2 *       0.0.0.0/0            0.0.0.0/0           MARK xset 0x8100/0xff00 
 2635  346K MARK       all  --  eth0.3 *       0.0.0.0/0            0.0.0.0/0           MARK xset 0x8200/0xff00 
  491 41244 MARK       all  --  3g-wan3 *       0.0.0.0/0            0.0.0.0/0           MARK xset 0x8300/0xff00 
 7240  569K mwan3_default  all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 
 5193  424K mwan3_interfaces  all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 
  318 22866 mwan3_rules  all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 

Chain mwan3_rules (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       tcp  --  *      *       0.0.0.0/0            192.168.0.0/24      multiport sports 0:65535 multiport dports 0:65535 mark match 0x0/0xff00 MARK xset 0x7f00/0xff00 
   56  3936 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff00 MARK xset 0x1300/0xff00 

Chain mwan3_wan (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 1011 82378 MARK       all  --  *      *       10.0.0.155           0.0.0.0/0           MARK xset 0x100/0xff00 

Chain mwan3_wan2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 1207  101K MARK       all  --  *      *       192.168.200.100      0.0.0.0/0           MARK xset 0x200/0xff00 

Chain mwan3_wan3 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
  493 41412 MARK       all  --  *      *       37.209.128.169       0.0.0.0/0           MARK xset 0x300/0xff00 

Chain openvpn_down_bw (2 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr1-download-2-449 --type combined --current_bandwidth 0 --reset_interval 2 --reset_time 2 --intervals_to_save 449 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr1-download-minute-15 --type combined --current_bandwidth 0 --reset_interval minute --intervals_to_save 15 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr2-download-minute-359 --type combined --current_bandwidth 0 --reset_interval minute --intervals_to_save 359 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr2-download-900-24 --type combined --current_bandwidth 0 --reset_interval 900 --reset_time 900 --intervals_to_save 24 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr3-download-180-479 --type combined --current_bandwidth 0 --reset_interval 180 --reset_time 180 --intervals_to_save 479 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr3-download-hour-24 --type combined --current_bandwidth 0 --reset_interval hour --intervals_to_save 24 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr4-download-7200-359 --type combined --current_bandwidth 0 --reset_interval 7200 --reset_time 7200 --intervals_to_save 359 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr4-download-day-31 --type combined --current_bandwidth 0 --reset_interval day --intervals_to_save 31 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr5-download-day-365 --type combined --current_bandwidth 0 --reset_interval day --intervals_to_save 365 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr5-download-month-12 --type combined --current_bandwidth 0 --reset_interval month --intervals_to_save 12 

Chain openvpn_up_bw (2 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr1-upload-2-449 --type combined --current_bandwidth 0 --reset_interval 2 --reset_time 2 --intervals_to_save 449 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr1-upload-minute-15 --type combined --current_bandwidth 0 --reset_interval minute --intervals_to_save 15 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr2-upload-minute-359 --type combined --current_bandwidth 0 --reset_interval minute --intervals_to_save 359 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr2-upload-900-24 --type combined --current_bandwidth 0 --reset_interval 900 --reset_time 900 --intervals_to_save 24 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr3-upload-180-479 --type combined --current_bandwidth 0 --reset_interval 180 --reset_time 180 --intervals_to_save 479 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr3-upload-hour-24 --type combined --current_bandwidth 0 --reset_interval hour --intervals_to_save 24 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr4-upload-7200-359 --type combined --current_bandwidth 0 --reset_interval 7200 --reset_time 7200 --intervals_to_save 359 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr4-upload-day-31 --type combined --current_bandwidth 0 --reset_interval day --intervals_to_save 31 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-hr5-upload-day-365 --type combined --current_bandwidth 0 --reset_interval day --intervals_to_save 365 
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           bandwidth --id openvpn-lr5-upload-month-12 --type combined --current_bandwidth 0 --reset_interval month --intervals_to_save 12 
root@router_glowny_extroot:~# cat /etc/config/mwan3
# This is a mwan3 example config. For mwan3 to work you will need at least:
#
# - 2 interfaces
# - 2 members
# - 1 policy
# - 1 rule
#
# First define all your wan interfaces. Interface name must match with the
# name used in your network configuration:

config 'interface' 'wan'
        option 'enabled' '1'
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '8.8.8.8'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '3'
        option 'count' '1'
        option 'timeout' '2'
        option 'interval' '5'
        option 'down' '3'
        option 'up' '5'
        option 'reroute' '0'

config 'interface' 'wan2'
        option 'enabled' '1'
        list 'track_ip' '8.8.8.8'
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '1'
        option 'count' '1'
        option 'timeout' '2'
        option 'interval' '5'
        option 'down' '3'
        option 'up' '5'
        option 'reroute' '0'


config 'interface' 'wan3'               
        option 'enabled' '1'            
        list 'track_ip' '8.8.8.8'       
        list 'track_ip' '8.8.4.4'
        list 'track_ip' '208.67.222.222'
        list 'track_ip' '208.67.220.220'
        option 'reliability' '3'        
        option 'count' '1'              
        option 'timeout' '5'            
        option 'interval' '10'           
        option 'down' '3'               
        option 'up' '8'                 
        option 'reroute' '0'  


# Next define a member and configure metric and weight values for this member.
# Each interface can have multiple member definitions. Give each member a correct
# name (A-Z, a-z, 0-9, "_" and no spaces).

config member 'wan_m1_w2'
       option metric '1'
       option weight '2'
       option interface 'wan'
            
config member 'wan_m2_w2'
       option metric '2'
       option weight '2'
       option interface 'wan'
                        
config member 'wan2_m1_w2'
       option interface 'wan2'
       option metric '1'
       option weight '2'
                                    
config member 'wan2_m2_w2'
       option interface 'wan2'
       option metric '2'
       option weight '2'
                                                
config member 'wan3_m1_w1'
       option interface 'wan3'
       option metric '1'
       option weight '2'
                                                            
config member 'wan3_m2_w1'
       option interface 'wan3'
       option metric '2'
       option weight '2'

# After that create a routing policy. A routing policy consist of one or more
# members. Give each policy a correct name (A-Z, a-z, 0-9, "_" and no spaces). You 
# can create multiple policies, so that it is possible for different traffic to
# have different primary and/or backup interfaces.

config policy 'wan_only'
       list use_member 'wan_m1_w2'
    
config policy 'wan2_only'
       list use_member 'wan2_m1_w2'
        
config policy 'wan3_only'
       list use_member 'wan3_m1_w1'
            
config 'policy' 'wan1_wan2_loadbalanced'
    list 'use_member' 'wan1_m1_w2'
    list 'use_member' 'wan2_m1_w2'

                        
config policy 'wan_pri_wan2_sec'
       list use_member 'wan_m1_w2'
       list use_member 'wan2_m2_w2'
                                
config policy 'wan2_pri_wan_sec'
       list use_member 'wan_m2_w2'
       list use_member 'wan2_m1_w2'
                                        



# And to finish the config define your traffic rules. Rules are matched in top to
# bottom order. If you define a rule and it matches, all following rules are ignored.
#
# If the option equalize is set, mwan3 will load-balance each new session to the same
# host. If not set, it will load-balance based on destination.

config 'rule'
    option 'dest_ip' '192.168.0.0/24'
    option 'proto' 'tcp'
    option 'use_policy' 'default'

config 'rule'

    option 'dest_ip' '0.0.0.0/0'
    option 'equalize' '1'
    option 'use_policy' 'wan1_wan2_loadbalanced'
root@router_glowny_extroot:~# cat /etc/config/network

config interface 'loopback'
        option ifname 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config interface 'lan'
        option ifname 'eth0.1'
        option type 'bridge'
        option proto 'static'
        option netmask '255.255.255.0'
        option ipaddr '192.168.100.100'
        option dns '208.67.222.222 208.67.220.220'

config interface 'wan'
        option auto '1'
        option ifname 'eth0.2'
        option proto 'static'
        option ipaddr '10.0.0.155'
        option netmask '255.255.255.0'
        option gateway '10.0.0.1'
        option dns '208.67.222.222 208.67.220.220'
        option metric '10'
        option peerdns '0'

config interface 'wan2'
        option auto '1'
        option ifname 'eth0.3'
        option macaddr 'C8:3A:35:4E:4F:CD'
        option proto 'dhcp'
        option peerdns '1'
        option dns '208.67.220.220 208.67.222.222'
        option defaultroute '1'
        option metric '20'

config interface 'wan3'
        option auto '1'
        option proto '3g'
        option device '/dev/ttyUSB0'
        option apn 'darmowy'
        option service 'umts'
        option mobile_isp 'Polska - Aero2'
        option peerdns '0'
        option dns '208.67.220.220 208.67.222.222'
        option defaultroute '1'
        option metric '30'

config switch
        option enable '1'
        option name 'rtl8366rb'
        option reset '1'
        option enable_vlan '1'
        option blinkrate '2'

config switch_vlan
        option device 'rtl8366rb'
        option vlan '1'
        option ports '2 3 4 5t'

config switch_vlan
        option device 'rtl8366rb'
        option vlan '2'
        option ports '0 5t'

config switch_vlan
        option device 'rtl8366rb'
        option vlan '3'
        option ports '1 5t'

config interface 'vpn'
        option ifname 'tun0'
        option proto 'none'
        option defaultroute '0'
        option peerdns '0'

root@router_glowny_extroot:~# ip route list table 1001
default via 10.0.0.1 dev eth0.2 
root@router_glowny_extroot:~# ip route list table 1002
default via 192.168.200.1 dev eth0.3 
root@router_glowny_extroot:~# cat /etc/config/firewall

config defaults
        option syn_flood '1'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'

config zone
        option name 'lan'
        option network 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'
option 'conntrack' '1'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan wan2 wan3'
option 'conntrack' '1'

config forwarding
        option src 'lan'
        option dest 'wan'

config zone
        option name 'wan2'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan2'

option 'conntrack' '1'

config forwarding
        option src 'lan'
        option dest 'wan2'

config zone
        option name 'wan3'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan3'
option 'conntrack' '1'

config forwarding
        option src 'lan'
        option dest 'wan3'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-Ping'
        option src 'wan2'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-Ping'
        option src 'wan3'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option src_ip 'fe80::/10'
        option src_port '547'
        option dest_ip 'fe80::/10'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config include
        option path '/etc/firewall.user'

config include
        option path '/usr/lib/gargoyle_firewall_util/gargoyle_additions.firewall'

config include 'openvpn_include_file'
        option path '/etc/openvpn.firewall'
        option reload '1'

config include 'miniupnpd'
        option type 'script'
        option path '/usr/share/miniupnpd/firewall.include'
        option family 'IPv4'
        option reload '1'

config remote_accept 'ra_443_8085'
        option local_port '443'
        option remote_port '8085'
        option proto 'tcp'
        option zone 'wan'

config zone 'vpn_zone'
        option name 'vpn'
        option network 'vpn'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        option mtu_fix '1'
        option masq '1'

config forwarding 'vpn_lan_forwarding'
        option src 'lan'
        option dest 'vpn'

config remote_accept 'ra_openvpn'
        option zone 'wan'
        option local_port '8086'
        option remote_port '8086'
        option proto 'udp'

config forwarding 'vpn_wan_forwarding'
        option src 'vpn'
        option dest 'wan'

846

(51 odpowiedzi, napisanych Oprogramowanie / Software)

Czesc,

ty zastosowalec mwan3 czy multiwana, bo config pokazales od multiwana - o co chodzi.


Pozdr

Ma ktos gotowa konfiguracje na mwan3 ?

848

(80 odpowiedzi, napisanych Oprogramowanie / Software)

postaram siew cos splodzic, ale zawiodlem sie na multiwanie, bez openvpn jakos to chodzilo, teraz strasznie chrzani kilka razy juz mi system zrestartowal - moze opisac problemy z multiwanem a szerzej opisac mwan3 - tak jak pozostale rozwiazania, nie ma opisu konfiguracji jakiejs prostej ta stronce eko - przydal by sie taki opis prostej konfiguracji.

Pozdr,

849

(80 odpowiedzi, napisanych Oprogramowanie / Software)

To jak to ugrysc na mwan3 na co zwrocic uwage przy tej konfiguracji mojej z openvpn - masz moze jakis config na 3 wany gdzie 1 jest 3g, wraz z loadbalancerem i failoverem. Czytalem ze tam specjalnie trzeba jakos ruting ustawic zeby to chodzilo prawidlowo typu:

#config route
#    option interface 'wan1'
#    option target '192.168.100.0'
#    option netmask '0.0.0.0'
#    option gateway '10.0.0.1'
                
#config route
#    option interface 'wan2'
#    option target '192.168.100.0'
#    option netmask '0.0.0.0'
#    option gateway '192.168.200.1'
                                
#config route
#    option interface 'wan3'
#    option target '192.168.100.0'
#    option netmask '0.0.0.0'
#    option gateway '10.64.64.64'

oraz metryki odpowiednio musza byc ustawione

850

(80 odpowiedzi, napisanych Oprogramowanie / Software)

To co proponujesz uzywac ? mwan3 ? czytalem ze z nim jeszcze wieksze problemy - nie ma na to lekarstwa ?