Several SSH Problems

Comments

12 comments

  • Avatar
    Firewalla

    SSH should be a straight forward.  How are you using the gold?  Are you using in the traditional simple mode?  If you are, which ports are doing the spoofing?  For the VLAN ports, how are they connected to your network?  

    0
    Comment actions Permalink
  • Avatar
    Marinna Cole

    My Gold is under "Simple Mode" but I guess in your terminology it is "Advanced Simple Mode" since I use P1~P3 to connect to the VLAN -specific ports on my switch. The logical connection was explained in my original post. I am attaching my screenshot from app for your reference.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    There is a bug in 1.970 sort of related how different segments are talking to each other.   Possible to give that a try?

    Instructions here 

    https://help.firewalla.com/hc/en-us/articles/360052804993-Firewalla-1-971-Early-Access-Multi-WAN-Smart-Queue-Rate-limit-Device-Quarantine

    0
    Comment actions Permalink
  • Avatar
    Marinna Cole

    Thanks for the update. I will wait till this version becomes more stable to test.

    I did a quick test by disabling entirely the monitoring on the device and the connectivity issue is gone. and after I made connection and reenable monitoring the connection is hang immediately. Also I found by disabling device monitoring my iPhone app connection to Gold is significantly faster (15~20 seconds to less 1~2 second). So this is definitely a bug on Gold, whether it is fixed or not. 

    As for the password issue, it still feels this is a hidden issue somewhere. After I disable device monitoring I couldn't login still. So I have to reset it again to make it work. But at the moment I can't definitively describe the step to reproduce this issue.

    If you havn't already reproduce this issue, I would recommend you to test VLAN on this SSH issue to see if you can reproduce it. Would be nice to some assurance that this issue is addressed in the coming 1.971.

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    I am running port 4 as WAN and I am using port 3 for my main network and I am running one VLAN on port 3 also. No problem connecting to ssh.

    0
    Comment actions Permalink
  • Avatar
    Marinna Cole

    James which FW are you using? I wonder if I did something wrong.

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    Gold version 1.970
    Primary network is 192.168.2.0/24
    VLAN 300 is 192.168.58.0/24

    I have a TP-Link AP that tags the “guest” network as VLAN 300 that then goes to the Firewalla for DHCP and Routing. I can access ssh from either network, but I did turn VLAN 300 ssh off since that is my “guest” network.

     

    ive been ssh in all day long with no issues

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    I plan on adding a IoT VLAN on the same port 3, but haven’t yet.... also because I’m not looking forward to going around and re-linking the devices to the new network....

    0
    Comment actions Permalink
  • Avatar
    Marinna Cole

    I log into my Gold trying to find if there is anything fishy in /var/system but I only see a lot of logs of Gold not being able to get DHCPv6 lease, other than that I couldn't find any useful information. I wonder if anyone knows where to find enough log to debug this issue.

    It started to leave my comfort zone when I get into these low level logs.

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    Just wanted to check. You said you have all 3 ports going to a switch, are those ports just tagged or did you set them as untagged ports?

    0
    Comment actions Permalink
  • Avatar
    Marinna Cole

    I was using untagged ports almost exactly the same as instruction from this page. On the switch side I flag each of the port with matching "U" to specific VLAN. 

    Switching "Monitoring" off will directly make my Gold box pingable. I can see why I couldn't see the Gold box P4 IP for the bug they mentioned. But it should still allow me to see the P1 IP it was licensed from VLAN DHCP server.

    0
    Comment actions Permalink
  • Avatar
    James Willhoite

    My old Linksys went out, so I bought the Firewalla Gold and a TP-Link AP. My setup is as
    ISP Modem -> Gold Port 4
    Gold Port 3 -> Netgear Managed switch port 24 (tagged 300)
    Netgear Port 23 (tagged 300) -> TP-Link AP

    The AP has 2 SSID, one for internal, one for guest (VLAN 300)

    The VLAN network that is on Port 3 of the Gold has a rule that blocks access to my LAN network (this way I can access the devices on the guest network, but they cannot access the LAN network)

    I can create a new SSID on the AP with a new VLAN pretty quickly and add a new VLAN on the Gold without having to plug in another network cable.

    My Gold is in Router mode since I don’t have anything else between it and the internet. The main reason for buying the Gold.

    0
    Comment actions Permalink

Please sign in to leave a comment.