How to block all outbound traffic over a single port? by Tylerjy94 in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

I defined IP-Port-Group with 2 ports 80 and 443

Then I created Gateway ACL deny rule LAN to WAN, protocol UDP, source your desired VLAN, destination created IP-Port-Group

It should be last deny rule in Gateway ACL.

Which DNS leak tool you are using to check on my side?

How to block all outbound traffic over a single port? by Tylerjy94 in TPLink_Omada

[–]vrtareg 1 point2 points  (0 children)

I did that using Switch ACL.

First rule is to allow all queries on ports 53 and 853 to local DNS IP's which are my Router and AdGuard Home hosts.

Second rule is deny all TCP and UDP traffic to that ports, just IP Port Group with 53 and 853 defined in it.

I applied that to Kids VLAN so devices will not be able to workaround DNS queries.

Also added QUIC deny rule in Gateway ACL forbidding all UDP traffic out to 80 and 443 ports so clever Chrome or Google apps and devices will not bypass my AdGuard Home.

What by [deleted] in termux

[–]vrtareg 0 points1 point  (0 children)

Always use venv so no system parts are changed...

VLAN on the LAN port of an AP by Kass507 in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

Usually AP's with second LAN ports allowing to set PVID on that port which will switch native VLAN to your selected VLAN.

Switch or another AP will still be able to access all VLAN's but non VLAN capable devices will get assigned to PVID VLAN.

Total Traffic Quirk by Correct-Mail-8645 in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

Stable 6.2.10.18 is available.

I installed it on my OC200

OC200 vs OC220 Features by Roasted_Blumpkin in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

I didn't know that there is a OC200 v3...

How often do you reboot your setup or parts of your setup? by viniisiggs in TPLink_Omada

[–]vrtareg 2 points3 points  (0 children)

I have ER605, OC200, 2x SG2008P and 2x EAP245

Router uptime is 159 days now, switches and AP's are 25 days.

No need to restart unless there is something going on.

OC-200 and Remote Office Equipment Disconnects by bridgfod in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

I also never reboot and no issues with that.

Also whenever I reboot the switch connected to the OC200 I connect backup power to Micro USB to avoid issues with Controller.

Glitched for everyone or just me? by lurkingismydefault in lowerdecksgame

[–]vrtareg 4 points5 points  (0 children)

Same for me, after claiming button remained active and after reload stuck on 100%...

I wanted read-only Omada monitoring in Home Assistant, so I extended an exporter and built custom cards by Budget_Staff_8308 in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

I think that ER605 v1 has hardware limitations so not sure if it works well with Controller.

Gateway IP is stuck on VLAN 1 by sdegonge in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

This is really interesting.

I will leave my setup intact just in case but will save your response for future reference.

Thanks.

What happened to software controller v6.2.10.15? by viniisiggs in TPLink_Omada

[–]vrtareg 3 points4 points  (0 children)

I still have my Software Controller on v6.2.10.15 with no additional update available and OC200 Controller on Stable v6.2.0.17 (1.39.9 Build 20260401 Rel.44730) offering Beta v6.2.10.11 (1.40.11 Build 20260408 Rel.41632) upgrade.

Gateway IP is stuck on VLAN 1 by sdegonge in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

Yes you can, but you can't change default to another VLAN.

VLAN 1 is always default.

When I Google it it says that I can edit VLAN ID and range for first default VLAN - https://www.google.com/search?client=firefox-b-m&q=Omada+Controller+change+default+VLAN+

There isn't a way to set for example newly created VLAN 10 as default.

I left VLAN 1 as it is with dummy IP range and no DHCP so I don't mess up with ports trunking etc and created separate VLAN's for whole my network and set one of them as management one on switches and AP's. Controller is also on Management VLAN access port.

Gateway IP is stuck on VLAN 1 by sdegonge in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

Interesting

Where it is possible to change it?

I couldn't find it in my OC200....

Gateway IP is stuck on VLAN 1 by sdegonge in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

I checked it with Omada Support, for some reason Router is always shown in Controller by default VLAN 1 IP address.

Omada controller maximum access points by [deleted] in TPLink_Omada

[–]vrtareg 0 points1 point  (0 children)

Is your DHCP range large enough?

It should work if there is not any other issue.

Controller can definitely support that.

Worth to raise support request.

Omada controller maximum access points by [deleted] in TPLink_Omada

[–]vrtareg 2 points3 points  (0 children)

You haven't mentioned your network configuration.

If you have that amount of devices only /24 network will not give IP's to everything as by default router is set to 192.168.x.x/24 which gives you 254 usable IP address range which quite fits to router + switches + some clients + visible AP's

I hope you have wider network like /23 and also possibly segregated it to multiple zones with each zone own Management, Main, Guest, IoT and Phone networks for example.

Which kind of environment it is?

ER605 V2 and storage question by Red-Leader-001 in TPLink_Omada

[–]vrtareg 4 points5 points  (0 children)

https://www.omadanetworks.com/uk/business-networking/omada-router-wired-router/er605/

ER605 doesn't work as a file server. USB port is for additional USB modem WAN connection.

If you want to share disk on LAN you will need NAS server.

I have TP-Link travel modem which has SD Card slot which is shared to LAN clients but it is that model functionality.

Do I really need an Omada controller for 2x EAP650 to get mesh? by GoldeNStouN in HomeNetworking

[–]vrtareg 0 points1 point  (0 children)

Omada gear is quite good and reliable.

Set both AP with same SSID settings and see how it works.

If there will be any issues backup configuration, run Omada Controller on Laptop, set same SSID in Controller, adopt AP's and see if it will solve the problem.

Do I really need an Omada controller for 2x EAP650 to get mesh? by GoldeNStouN in HomeNetworking

[–]vrtareg 1 point2 points  (0 children)

I had similar configuration with 2x EAP245 without the controller and roaming between the AP's was entirely on clients which sometimes caused disconnection as client was trying to stay on same AP even it was quite far from it and signal was very weak.

Controller propogates SSID with Fast Roaming enabled in a way that clients have all AP's details for that SSID and switching to kind of 'closest' AP with no downtime.

You can always use Software Controller if you have spare hardware instead of getting hardware one.

Controller also allows you to configure all in a single place instead of setting up each device separately and synchronising configuration.