I have this router set up with OpenWrt 22.03.5 running as a switch and access point in the basement.
OpenWrt 23.05.0-rc3 needs a complete reconfiguration because the config can not be ported automatically.
When I started into OpenWRT two years ago, I had no idea how many options this OS offers.
I followed some guide and managed to set up the device. It's been running ever since but the firmware update made me revisit the settings I made back then.
Although it is running, I think there are some issues in the config.
At least I have some gaps in my understanding of how it works (most likely forgotten).
In addition to that, I have to set up another site with OpenWRT and would like to fully understand what I'm doing.
I would like to start with a review of the config of this device and maybe get an answer on this or that question.
I will post what I think to be the relevant LuCI screens.
Here is the switch config:
All ports are part of VLAN1 so I can use all as regular switched ports.
Q1: Is there a reason why the eh0 should be "tagged"?
Q2: It looks like VLAN2 is not really used here?
The devices:
br-lan is bridging VLAN1 (eth0.1)
It seems the physical WAN port is not on an extra network device (eth1).
Q3: There should be no need of VLAN1. Switching all ports should work without.
Q4: Not even the br-lan should be necessary to brigde eth0 alone. But the bridge will be set up when the wifi radios are added.
Here are the interfaces:
The lan interface has a fixed IP and DHCP is disabled. The main router will take care of IPs.
Q5: Given, how wan is switched, this interface can be deleted?
The br-GAST is bridging the guest wifi networks.
Setting up the Wifi is quite straight forward. No questions on that side.
But I don't understand how this bridge is connected to the switch/lan.
Properties of br-GAST:
I figure it is related to the firewall settings. But where is the (virtual) wire between the interfaces?
Q6: If the wan interface i not used, the firewall rules set are also obsolete?
When inspecting the first rule (lan-->wan), I see this:
The second (wan-->reject) looks like this:
The last (GAST --> lan) is this:
I feel I have to read up on firewall settings next.
Anyway, If someone could review this config and maybe answer one or the other question raised so far, I would be really glad. Improvements and corrections are very welcome.
Here is the config in nerd style
config interface 'loopback'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
option device 'lo'
config globals 'globals'
option ula_prefix 'fdcut by me'
config interface 'lan'
option proto 'static'
option netmask '255.255.255.0'
option delegate '0'
option ipaddr '192.168.158.14'
option gateway '192.168.158.1'
list dns '192.168.158.7'
list dns '192.168.158.1'
option device 'br-lan'
config interface 'wan'
option _orig_ifname 'eth0.2'
option _orig_bridge 'false'
option proto 'dhcp'
option delegate '0'
option device 'eth0.2'
config switch
option name 'switch0'
option reset '1'
option enable_vlan '1'
config switch_vlan
option device 'switch0'
option vlan '1'
option ports '0t 1 2 3 4 5'
option vid '1'
config switch_vlan
option device 'switch0'
option vlan '2'
option ports '0t'
option vid '2'
config interface 'GAST'
option type 'bridge'
option proto 'static'
list ipaddr '192.168.178.14/24'
option delegate '0'
option force_link '0'
config device
option name 'br-lan'
option type 'bridge'
list ports 'eth0.1'
option macaddr 'f8:cut by me'
option ipv6 '0'