Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - prutz0r

#1
Quote from: nero355 on September 26, 2026, 02:38:14 PMBut I was thinking...

Any chance that there is some kind of alternative firmware available for these things ?!
Slapping OpenWRT on them for example would solve the whole issue pretty easily! :)
Great idea. But then I searched for the model numbers and openwrt and no result unfortunately.
#2
Quote from: nero355 on September 25, 2026, 10:19:07 PM
Quote from: prutz0r on September 25, 2026, 09:32:34 PMBecause my whole network goes down or I need to run a cable directly between the MR and MS
I am guessing your Netgear Switch is blocking some kind of protocol that those things use to communicate...
Reason I am saying this is that I have read something similar once, but I can't remember anymore what the exact issue was :(

Can't you just DISABLE MESH functionality and configure all the units like a simple Accesspoint ?!

Another possible issue :
Not having a proper (R)STP setup on your Switches combined with the Mesh functionality of those things can indeed cause serious issues!
I read about loop prevention being able to cause all kinds of trouble so that's disabled. I really think the WAN and LAN interface are bridged in AP mode thus causing lot's of issues when connecting both to a switch on the same subnet. I think it's looping. That theory does fit my observations so far. Assuming mesh means using a wireless connection as backhaul and automatically finding the best path and considering roaming a seperate feature, mesh is disabled automatically when connecting the satellite, MS, wired to the MR. However the MR interfaces still seem bridged. To stop the loop I think I can solve the puzzle by isolating the connection between the MS and MR as networking is taken care of by the bridge. The MS have their own web interface but there is almost nothing you can configure. Rebooting, perhaps syncing for wireless mesh and that's about it. They really depend on the MR.

QuoteNow to answer your question about VLANs partially :
- When your OPNsense Interface is just the Default LAN for example you need to transport it as UNTAGGED to a Switch or Accesspoint.
That would be the situation without VLANs that I have right now I think?

Quote- When your OPNsense Interface has VLANs assigned to it you need to transport them as TAGGED to a Switch or Accesspoint.
My default LAN will be VLAN 10 so that would mean connection from router to switch is tagged?

Quote- VLANs between Switches usually go TAGGED too unless you are doing something special for whatever reason.
I have only one switch.

Quote- VLANs from Switches to Accesspoints go TAGGED too unless you are doing something special for whatever reason.

Simple common example of "Something special" :
Some equipment needs to have it's Management Network transported as UNTAGGED instead of TAGGED.
Since your MESH units probably don't know what to do with VLANs on the "Switch side" you will need to do something like this, because both the regular traffic and management traffic will go via the same connection/network :)
This system is completely unaware of VLANs, it's not like Ubiquity where you apply a VLAN to an SSID so I would think the traffic is untagged anyway to the MR interface that connects the access points to the rest of the network and the internet? And then apply a fixed PVID to the relevant switch port?

QuoteHeel veel succes alvast! ;)
Bedankt, interessante puzzel, alleen wil ik niet voor iedereen in het huis dagen lang het netwerk uit de lucht hebben ;)
#3
Quote from: klinebau on September 25, 2026, 09:04:54 PMI don't understand why you wouldn't connect the mesh router to the switch.  This is the correct location and it should be setup in AP mode.  There is no reason for VLANs just to connect a mesh system.  You might want VLANS for other purposes, but it is not needed to connect a mesh system.
Because my whole network goes down or I need to run a cable directly between the MR and MS, while also running a cable between the router and the MR, essentially creating a 1gbps bottleneck between my router, having to run around 30 meters of extra cabling and also I see no reason why all network traffic needs to go through this device. I tried to describe this in the observations, but perhaps you can let me know why they're unclear. I can add more information.
#4
I have this Netgear mesh system that I want to use a wired backhaul (essentially making it non mesh roaming AP's). After some research it seems the main AP (the MR) needs to sit between router and network switch. I have a Protectli with OpnSense and I see no use to put this in between the router and my 16p Netgear smart switch. The MR has one other port, a LAN port, that the satellite (MS) needs to be connected to either directly or through a switch. Connecting them both to the 16p switch doesn´t work. My observations:
  • Connecting the MR and MS to the 16p switch causes the whole network to go down. I connected the MR WAN and LAN port both to the switch as the manual states it needs the LAN port for connecting to the other satellite and the WAN port for network traffic. Kind of weird I would think, but connecting the WAN port to my LAN makes it see all kinds of devices.
  • Connecting the MR with WAN port to the 16p switch and the MS directly to the MR works. Weird thing is, the MS get it's ip from the main network, that the MR connects to through the WAN port. Together with the previous observation I'm led to believe that while this system is in AP-only mode the WAN and LAN interface are bridged, which would also explain the network going down because of infinite loops.
  • Putting the MR between my router with WAN port to router and LAN port to the switch, and the MS directly connected to the switch, works.

I do not want the MR in between the router and switch as their location is very mediocre for an access point ánd I'm fundamentally against having devices handle traffic for no reason - wired-only traffic should pass that device. So I though that this might something a VLAN might solve. Put my whole LAN in VLAN10 and the MR LAN interface and MS in VLAN20. Then seperate them by blocking all traffic between 10 and 20 as the MR bridges these networks anyway. I have questions about doing this. I know about the theory but have no experience in practice and only one network to test this on, being my own house network. So I want to try and get things as right as possible from the start. I found this tutorial:
Dutch - https://privacygear.nl/guides/opnsense-vlan-gids/
English (automtically translated) - https://privacygear-nl.translate.goog/guides/opnsense-vlan-gids/?_x_tr_sl=nl&_x_tr_tl=en&_x_tr_hl=nl&_x_tr_pto=wapp

  • Am I correct in thinking that I can skip step 3 for VLAN 20 as device in VLAN 20 will get the ip address through the bridging function of the MR?
  • Is there anything missing from that tutorial?
  • I currently have a network running on 192.168.1.1/24. I´d like to keep it that way so DHCP for VLAN 10 will need that same range. However, it seems I cannot yet configure this right now as the subnet is already used? Is there any kind of shortcut that makes it easier?
  • Can I migrate my static leases to the DHCP service of the VLAN? I didn´t see anything that would suggest this is possible.

I have a Netgear smart switch. I'm thinking of how I should configure this to work with OpnSense. Would I have to configure it like this?
  • 802.1Q VLANs
  • Port 1 to OpnSense (trunk) - untagged VLAN 10, 20
  • Port 2 and 3 to MR LAN and MS - tagged VLAN 20
  • The rest, including to MR WAN - tagged vlan 10
  • Tagged means assigning membership of the port and not using PVID?

Thanks a lot.
#5
It worked but not 100% reliably. Sometimes connections just didn't work. So I'll be looking for different hardware. Thanks for your support all.
#6
Ok, it's a complete mystery to me, but I have just reinstalled OPNsense. No errors at boot, no problems logging into local shell and GUI is responsive....later on I will try routing. Hope it works, then I got myself a 20 dollar J3455 OPNsense box. Realtek and not Intel but worth a shot for the money.
#7
Quote from: cookiemonster on April 14, 2024, 10:39:58 PM
It would be useful if not done yet, to run the checksums on the downloaded files. It checks not only that the images haven't been tampered with (unlikely but all serious projects do it to protect their users), but also checks for a corrupted download. Only takes a few minutes.
Additionally this:
QuoteLogging into the console is impossible. Doesn't matter if I use a custom password or the stock opnsense on after a new install. Also created a new user with sh as login shell and added to admin group but no result. Done 2 installs now just to be sure.
What happens, do you get a login prompt?
Checksums checks out ;) Also, pfSense works flawlessly, also providing an internet connection. Next step: install OpnSense again and see what it does.
#8
Quote from: cookiemonster on April 14, 2024, 10:39:58 PM
It would be useful if not done yet, to run the checksums on the downloaded files. It checks not only that the images haven't been tampered with (unlikely but all serious projects do it to protect their users), but also checks for a corrupted download. Only takes a few minutes.
Thanks, good tip. Will do that.
Quote
Additionally this:
What happens, do you get a login prompt?
Yes I do. But I keep getting wrong username/password error.
#9
Quote from: cookiemonster on April 14, 2024, 10:00:35 PM
problem could be storage or another hardware like memory.
Those errors and failure to login could suggest a broken installation, which in turn could be memory or storage.
You could try running ubench or stress (these are freebsd packages) but I find those tend to just max out the hardware to a crash, so without understanding what is happening, it could lead to misdiagnostics.
Run memtest from a usb stick first if you can.
Try to validate the storage. You could do that from this vanilla freebd.  Some heavy use of disk like large file transfers, etc.
Look for clues in dmesg.
Thanks a lot. Tonight I took a different route and if this doesn't work out I'll try yours.



    • I did memtest - passed.
    • Installed Lubuntu, worked without problems.
    • Installed pfSense, no errors and boots quick enough. I also get into the shell main menu.

    It must be said that before I ran the before mentioned, I changed 1 S4/S5 power option in the bios. Tommorow I will check how the pfSense web gui runs and if the devices routes without a problem. If so I'll give OpnSense another install and try and let you guys know how it works out. And if it still doesn't work I can try what you suggested.
#10
Quote from: Patrick M. Hausen on April 07, 2024, 01:59:33 PM
Signal 6, random weird crashes - hardware problem. Either a defect of some sort or an incompatibility of your platform with the FreeBSD 13 kernel.

Things to try:

Reset BIOS settings to manufacturer defaults.
BIOS update available?
Power saving states - disable them all at first.
Run memtest.
Does some Linux distro run?
Does a stock FreeBSD 13.3 run?

HTH,
Patrick
Thanks for your input. I installed stock FreeBSD 13.3 and I can boot and login. It's booting alright. I'm not at all familiar with FreeBSD, somewhat with Linux and it's command line. Is there anything I can do at the command line of FreeBSD 13.3 (there is no GUI booting up) to test if there are any problems?
#11
I'm slowly going crazy here. I use a AOpen DE3450( J3455, 4gb RAM, 64gb SSD). Starting after the install it's just one big mess:

  • Booting takes up to 8 minutes.
  • Auto boot countdown doesn't run and work - no boot without user input
  • Logging into the console is impossible. Doesn't matter if I use a custom password or the stock opnsense on after a new install. Also created a new user with sh as login shell and added to admin group but no result. Done 2 installs now just to be sure.
  • Webinterface differs in speed between pages from "ok-ish" to not usable; no logs load. No boot log either, that I was hoping to find for trouble shooting. No access in console either as I mentioned...

A load of error messages at boot.

DHCPv4/DHCPd client exits at signal 6.

Error in start script 25-syslog
Fatal python error: init_interp_main: can't initialize time (might the cause be the absence of an active internet connection? WAN is not hooked up)
Following: OverflowError: timestamp too large to convert to C _PyTime_t

Error in early script 90-carp
Fatal python error: init_interp_main: can't initialize time (might the cause be the absence of an active internet connection? WAN is not hooked up)
Following: OverflowError: timestamp too large to convert to C _PyTime_t

And many more. All these errors, no access to console, 8 minute boot time and half functioning GUI (tried on a Windows machine and Linux, both with differing browsers) and therefor no access to logs makes me about to give up. I hope any of you guys have an idea of what's going on.