Follow along with the video below to see how to install our site as a web app on your home screen.
Opmerking: This feature may not be available in some browsers.
Ik zal dit nogmaal doen zodra er een "maintenance windows" beschikbaar is. Ik heb dit reeds meermaals gedaan (wellicht nu meer geluk). Ik laat het resultaat weten.Wat je zou kunne proberen is de USG "vergeten", resetten naar default en opnieuw adopteren.
Ik neem aan dat dit hetzelfde is als "trigger Provision"?Je kunt ook vanuit de controller nog een ‘ full provision’ doen en dan in server.log kijken welke fouten je krijgt.
Er gaat iets in ieder geval niet goed met het koppelen van interfaces aan de juiste firewall regels, je WAN_IN en WAN_LOCAL zijn inactive.volgens de scan:
Echter heb ik wel UPnP "aan"staan. IK heb deze "aan" staan vanwege 2x XBOX (gaming kids)
Show firewall:
Code:-------------------------------------------------------------------------------- IPv4 Firewall "AUTHORIZED_GUESTS": Inactive - Not applied to any interfaces, zones or for content-inspection. rule action proto packets bytes ---- ------ ----- ------- ----- 10000 drop all 0 0 -------------------------------------------------------------------------------- IPv4 Firewall "GUEST_IN": Inactive - Not applied to any interfaces, zones or for content-inspection. rule action proto packets bytes ---- ------ ----- ------- ----- 3001 accept tcp_udp 0 0 condition - tcp dpt:domain 3002 accept all 0 0 condition - match-DST-ADDR-GROUP guest_portal_address match-set guest_portal_p orts dst 3003 accept tcp 0 0 condition - tcp dpt:https match-set captive_portal_subnets dst 3004 accept all 0 0 condition - match-set guest_pre_allow dst 3005 drop all 0 0 condition - match-set guest_restricted dst 3006 drop all 0 0 condition - match-set corporate_network dst 3007 drop all 0 0 condition - match-set remote_user_vpn_network dst 3008 drop all 0 0 10000 accept all 0 0 -------------------------------------------------------------------------------- IPv4 Firewall "GUEST_LOCAL": Inactive - Not applied to any interfaces, zones or for content-inspection. rule action proto packets bytes ---- ------ ----- ------- ----- 3001 accept tcp_udp 0 0 condition - tcp dpt:domain 3002 accept icmp 0 0 [CODE]IPv4 Firewall "WAN_IN": Active on (eth0,IN) rule action proto packets bytes ---- ------ ----- ------- ----- 3001 accept all 448917 43221679 condition - state RELATED,ESTABLISHED 3002 drop all 34 1504 condition - state INVALID 10000 drop all 2725 157333 -------------------------------------------------------------------------------- IPv4 Firewall "WAN_LOCAL": Active on (eth0,LOCAL) rule action proto packets bytes ---- ------ ----- ------- ----- 3001 accept all 206098 18022064 condition - state RELATED,ESTABLISHED 3002 drop all 7182 342031 condition - state INVALID 10000 drop all 301920 15809529
3003 accept udp 0 0
condition - udp spt:bootpc dpt:bootps
3004 accept tcp 0 0
condition - match-set guest_portal_redirector_ports dst
10000 drop all 0 0
--------------------------------------------------------------------------------
IPv4 Firewall "GUEST_OUT":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 0 0
--------------------------------------------------------------------------------
IPv4 Firewall "LAN_IN":
Active on (eth1,IN)
rule action proto packets bytes
---- ------ ----- ------- -----
6001 accept all 41876050 9506489838
condition - saddr 192.168.1.0/24
10000 accept all 0 0
--------------------------------------------------------------------------------
IPv4 Firewall "LAN_LOCAL":
Active on (eth1,LOCAL)
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 695799 78364327
--------------------------------------------------------------------------------
IPv4 Firewall "LAN_OUT":
Active on (eth1,OUT)
rule action proto packets bytes
---- ------ ----- ------- -----
6001 accept all 56460551 73125520931
condition - daddr 192.168.1.0/24
10000 accept all 0 0
--------------------------------------------------------------------------------
IPv4 Firewall "WAN_IN":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept all 4512 639641
condition - state RELATED,ESTABLISHED
3002 drop all 0 0
condition - state INVALID
3003 accept tcp 0 0
condition - daddr 192.168.1.11 tcp dpt:8123
10000 drop all 0 0
--------------------------------------------------------------------------------
IPv4 Firewall "WAN_LOCAL":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept all 286 28701
condition - state RELATED,ESTABLISHED
3002 drop all 23 2018
condition - state INVALID
10000 drop all 447 29333
--------------------------------------------------------------------------------
IPv4 Firewall "WAN_OUT":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 8498 1465125
--------------------------------------------------------------------------------
IPv6 Firewall "AUTHORIZED_GUESTSv6":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
10000 drop all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "GUESTv6_IN":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
3001 drop all 0 0
condition - match-set corporate_networkv6 dst
10000 accept all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "GUESTv6_LOCAL":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept udp 0 0
condition - udp dpt:domain
3002 accept icmp 0 0
10000 drop all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "GUESTv6_OUT":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "LANv6_IN":
Active on (eth1,IN)
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "LANv6_LOCAL":
Active on (eth1,LOCAL)
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 10851 2082999
--------------------------------------------------------------------------------
IPv6 Firewall "LANv6_OUT":
Active on (eth1,OUT)
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "WANv6_IN":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept all 0 0
condition - state RELATED,ESTABLISHED
3002 drop all 0 0
condition - state INVALID
10000 drop all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "WANv6_LOCAL":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept ipv6-icmp 0 0
condition - ipv6-icmp neighbour-advertisement
3002 accept ipv6-icmp 0 0
condition - ipv6-icmp neighbour-solicitation
3003 accept all 0 0
condition - state RELATED,ESTABLISHED
3004 drop all 0 0
condition - state INVALID
10000 drop all 0 0
--------------------------------------------------------------------------------
IPv6 Firewall "WANv6_OUT":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
10000 accept all 0 0
[/CODE]
--------------------------------------------------------------------------------
IPv4 Firewall "WAN_IN":
Active on (eth0,IN)
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept all 448917 43221679
condition - state RELATED,ESTABLISHED
3002 drop all 34 1504
condition - state INVALID
10000 drop all 2725 157333
--------------------------------------------------------------------------------
IPv4 Firewall "WAN_LOCAL":
Active on (eth0,LOCAL)
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept all 206098 18022064
condition - state RELATED,ESTABLISHED
3002 drop all 7182 342031
condition - state INVALID
10000 drop all 301920 15809529
--------------------------------------------------------------------------------
Volgens mij is de "classic" GUI er niet meer sinds v7.023 (ik zie iig niet meer de switch om om te schakelen..Ook meen ik me te herinneren dat er een issue is met het configureren van de WAN VLAN ID in de nieuwe GUI van de controller I.c.m. een USG, voor de USG moet je die configureren vanuit de classic interface.
Hi, dat ben ik helemaal met je eens. Ik had (stiekem) gehoopt dat provisioning zou werken na de update.Nogmaals: Het niet provisionen is je probleem, het heeft geen zin met firewall regels te experimenteren zolang dat niet normaal werkt. Want je firewall is inactief en doet dus helemaal niets, welke regel je ook toevoegt.
Welk commando kan ik hiervoor het beste gebruiken? (of waar moet ik naar zoeken in de config.json)Je moet weer via ssh in de USG kijken of de firewall op WAN IN actief is.
--------------------------------------------------------------------------------
IPv4 Firewall "WAN_IN":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
2000 drop all 779 105213
condition - match-SRC-PORT-GROUP 6242c9b7e9d2910144e88d97 match-set NETv4_eth1
dst
3001 accept all 4438 694681
condition - state RELATED,ESTABLISHED
3002 drop all 0 0
condition - state INVALID
3003 accept tcp 0 0
condition - daddr 192.168.1.11 tcp dpt:8123
10000 drop all 0 0
--------------------------------------------------------------------------------
IPv4 Firewall "WAN_LOCAL":
Inactive - Not applied to any interfaces, zones or for content-inspection.
rule action proto packets bytes
---- ------ ----- ------- -----
3001 accept all 402 39715
condition - state RELATED,ESTABLISHED
3002 drop all 165 13158
condition - state INVALID
10000 drop all 939 86287
--------------------------------------------------------------------------------

Het Nederlandse Unifi Forum is het onofficiële forum voor UniFi liefhebbers. Sinds de start op 4 januari 2018 bieden we een fris en overzichtelijk platform met handige functies, een responsief design voor mobiel gebruik, tutorials en handleidingen.
Ons forum is gebaseerd op XenForo-software en bevat een Resources sectie waar gebruikers content kunnen delen en beoordelen. Op UniFi Forum blijf je altijd op de hoogte van het laatste UniFi nieuws, aankondigingen en productveiligheidsupdates. We voegen regelmatig nuttige functies toe, terwijl het forum overzichtelijk en goed gemodereerd blijft.
Disclaimer:
Dit forum is op geen enkele manier verbonden met Ubiquiti of het merk UniFi. Alle vermeldingen van producten of merken zijn uitsluitend bedoeld voor discussie en informatieve doeleinden.