Ubiquity EdgeRouter X - Configuring to Isolate Surveillance Networks

abyq

n3wb
Joined
Apr 25, 2020
Messages
6
Reaction score
1
Location
Indonesia
Interesting question and why it doesn't work. There are couple of "schools" on how to implement the firewall on an Edgerouter, either you put it on WAN_OUT, or on the "local"_(vlan)_OUT. I opted for the latter:

Code:
        rule 40 {
            action accept
            description "Allow TCP/2195"
            destination {
                port 2195
            }
            log disable
            protocol tcp
            source {
                group {
                    network-group IPC_catcamstarvlan
                }
            }
        }
If you are unsure what is happening: enable "LOG DEFAULT" in the EdgeMAX web browser, and then "tail -f /var/log/messages", and you'll see which IP/Port/Destination gets "blocked".

Good luck!
CC
I've tried this and its seems still not working, from the apps side, its working if all the OP ruleset disabled. I guess I should try again with different ruleset

update:
its working now if I put in restricted_lan_in at first rule, thanks
 

4isteve

n3wb
Joined
Jun 18, 2020
Messages
2
Reaction score
1
Location
Washington, WA, US
@guykuo First, thank you for writing this up!! It was incredibly helpful. I was able to follow your tutorial to set things up, had to change the camera LAN IP block but managed to fix up everything. I even got the OpenVPN setup work with my iphone client.

I had a ASUS router OpenVPN setup before. I normally VPN back home to check on the cameras and use my home ISP to check Internet contents that are blocked at some part of the world. With your EdgeRouter X OpenVPN setup, I was able to do the same - but with some challenges. Checking my LAN cameras was ok, a bit slower than the ASUS setup. But connecting to outside Internet timed out most of the time, and unreliably slow when it worked. EdgeRouter X CPU was barely 15% busy most of the time. Where would you recommend me to troubleshoot this?
 

4isteve

n3wb
Joined
Jun 18, 2020
Messages
2
Reaction score
1
Location
Washington, WA, US
I think I found a fix. I changed the OpenVPN port (both server and client) from 443 to 1194, per instruction here: EdgeRouter - OpenVPN Server . I guess it has to do with browser on my iphone visiting web sites (https on port 443) and created a conflict. But my VPN knowledge is limited. However everything worked perfectly and very fast after I made the change!
 

GPSeek

n3wb
Joined
Feb 3, 2019
Messages
3
Reaction score
0
Location
DE, 19709
The firmware versioning is very confusing

From the firmware page:

You can see that smaller-numbered version has a most recent update date.
But the higher number version is older. So, which one we go with? any ideas? Thanks!

EdgeRouter ER-X/ER-X-SFP/EP-R6: Firmware v1.10.11Firmware2020-03-11
EdgeRouter ER-X/ER-X-SFP/EP-R6/ER-10X: Firmware v2.0.8-hotfix.1Firmware2020-03-10
 
Top