Temat: Failover mwan3 Aero2
Witam wszystkich.
Posiadam następującą konfigurację sprzętową
Ruter WDR4300 LEDE z LuCI - r3876-efb6ca1
Modem E3372h-153 (Hi-Link) z kartą Aero2
Konfigurację wykonałem według poniższej instrukcji:
http://pliki.linuxiarz.pl/11-2013/PORAD … 3%20v1.pdf\
Niestety w żaden sposób nie jestem w stanie ustawić aby ruch przełączył się na wan2
Interfejs wan2 jest offline po przełączeniu się na wan2 (gdy wan jest offline) a następnie gdy nastąpi powrót do głównego interfejsu wan.
Gdy ruter przełączy się na wan2 nie pingują się żadne serwery DNS ani jakikolwiek publiczny adres IP.
Działa jedynie dostęp do adresu IP 192.168.8.1 modemu gdy ruch przełączy się na wan2
Status mwan3.
Interface status:
interface wan is online and tracking is active
interface wan2 is offline and tracking is active
Current ipv4 policies:
failover:
wan (100%)
Current ipv6 policies:
failover:
unreachable
Directly connected ipv4 networks:
192.168.8.100
127.0.0.1
224.0.0.0/3
10.0.100.1
192.168.100.1
172.16.100.0/30
192.168.100.31
192.168.125.19
172.16.100.3
127.0.0.0
127.0.0.0/8
172.16.200.3
192.168.8.0/24
10.0.100.0/29
192.168.100.0/27
192.168.125.63
192.168.8.255
172.16.100.0
192.168.125.0/26
192.168.8.0
192.168.100.0
172.16.200.1
192.168.8.1
172.16.200.0/30
10.0.100.7
192.168.125.1
192.168.125.0
127.255.255.255
172.16.200.0
172.16.100.1
10.0.100.0
Directly connected ipv6 networks:
fe80::/64
fd6a:3de3:2021::/64
Active ipv4 user rules:
47 2541 - failover all -- * * 0.0.0.0/0 0.0.0.0/0
Active ipv6 user rules:
20 10780 - failover all * * ::/0 ::/0/etc/config/mwan3
config interface 'wan'
option enabled '1'
option reliability '2'
option count '1'
option timeout '2'
option interval '5'
option down '3'
option up '8'
option reroute '0'
list track_ip '8.8.8.8'
list track_ip '208.67.222.222'
config interface 'wan2'
option reliability '1'
option count '1'
option timeout '10'
option interval '20'
option down '10'
option up '5'
option enabled '1'
option reroute '0'
list track_ip '8.8.8.8'
list track_ip '208.67.222.222'
config member 'wan_m1_w3'
option interface 'wan'
option metric '1'
option weight '1'
config member 'wan2_m2_w2'
option interface 'wan2'
option metric '2'
option weight '2'
config policy 'failover'
list use_member 'wan_m1_w3'
list use_member 'wan2_m2_w2'
config rule 'default_rule'
option dest_ip '0.0.0.0/0'
option proto 'all'
option sticky '0'
option use_policy 'failover'/etc/config/network
config interface 'loopback'
option ifname 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fd6a:3de3:2021::/48'
config interface 'lan'
option type 'bridge'
option ifname 'eth0.1'
option proto 'static'
option ip6assign '60'
option ipaddr '192.168.100.1'
option netmask '255.255.255.224'
config interface 'wan'
option ifname 'eth0.2'
option proto 'dhcp'
option metric '10'
option peerdns '0'
option metric '1'
option dns '8.8.8.8 208.67.222.222'
config interface 'wan6'
option ifname 'eth0.2'
option proto 'dhcpv6'
config switch
option name 'switch0'
option reset '1'
option enable_vlan '1'
config switch_vlan
option device 'switch0'
option vlan '1'
option ports '4 5 0t'
config switch_vlan
option device 'switch0'
option vlan '2'
option ports '1 0t'
config switch_vlan
option device 'switch0'
option vlan '3'
option ports '2 0t'
config switch_vlan
option device 'switch0'
option vlan '4'
option ports '3 0t'
config interface 'wan2'
option proto 'dhcp'
option ifname 'eth1'
option metric '20'
option peerdns '0'
option metric '2'
option dns '8.8.8.8 208.67.222.222'
config interface 'lan2'
option ifname 'eth0.3'
option proto 'static'
option ipaddr '172.16.100.1'
option netmask '255.255.255.252'
config interface 'lan3'
option ifname 'eth0.4'
option proto 'static'
option ipaddr '172.16.200.1'
option netmask '255.255.255.252'
config interface 'guest'
option type 'bridge'
option proto 'static'
option ipaddr '10.0.100.1'
option netmask '255.255.255.248'/etc/config/firewall
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
config zone
option name 'lan'
list network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'wan'
list network 'wan'
list network 'wan6'
list network 'wan2'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fc00::/6'
option dest_ip 'fc00::/6'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config include
option path '/etc/firewall.user'
config zone
option name 'lan2'
list network 'lan2'
option output 'ACCEPT'
option input 'REJECT'
option forward 'REJECT'
config forwarding
option src 'lan2'
option dest 'wan'
config rule
option src 'lan2'
option proto 'udp'
option src_port '67-68'
option dest_port '67-68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option src 'lan2'
option dest_port '53'
option target 'ACCEPT'
option family 'ipv4'
option proto 'tcpudp'
config zone
option name 'lan3'
list network 'lan3'
option output 'ACCEPT'
option input 'REJECT'
option forward 'REJECT'
config forwarding
option src 'lan3'
option dest 'wan'
config rule
option src 'lan3'
option proto 'udp'
option src_port '67-68'
option dest_port '67-68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option src 'lan3'
option dest_port '53'
option target 'ACCEPT'
option family 'ipv4'
option proto 'tcpudp'
config zone
option name 'guest'
list network 'guest'
option output 'ACCEPT'
option input 'REJECT'
option forward 'REJECT'
config forwarding
option src 'guest'
option dest 'wan'
config rule
option src 'guest'
option proto 'udp'
option src_port '67-68'
option dest_port '67-68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option src 'guest'
option dest_port '53'
option target 'ACCEPT'
option family 'ipv4'
option proto 'tcpudp'| WDR4300 @ OpenWrt 21.02 / LuCI -> extroot, sieć gościnna, WINS serwer
| MR3020 @ MiFi 17.01 -> E3372 HiLink
| WR842ND v2 @ Gargoyle PL 1.13.0 -> testy