<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title><![CDATA[EdgeMAX Routing & Switching | Topics | Ubiquiti Community]]></title>
        <description><![CDATA[EdgeMAX Routing & Switching | Topics | Ubiquiti Community]]></description>
        <link>https://community.ui.com</link>
        <image>
            <url>https://community.ui.com/images/og-image.jpg</url>
            <title>EdgeMAX Routing &amp; Switching | Topics | Ubiquiti Community</title>
            <link>https://community.ui.com</link>
        </image>
        <generator>Ubiquiti Community</generator>
        <lastBuildDate>Wed, 30 Sep 2026 21:45:51 GMT</lastBuildDate>
        <atom:link href="https://community.ui.com/rss/topics/edgemax" rel="self" type="application/rss+xml"/>
        <pubDate>Wed, 30 Sep 2026 21:45:51 GMT</pubDate>
        <copyright><![CDATA[© 2026 Ubiquiti Inc. All rights reserved.]]></copyright>
        <item>
            <title><![CDATA[Edgeswitch 802.1X multiple untagged VLANs and broadcast traffic]]></title>
            <description><![CDATA[<p>Hello,</p><p>I have a EdgeSwitch 16 XG, and I'm configuring 802.1X port access control with a FreeRadius server.</p><p>I have 2 VLAN for this setup : VLAN 3 and VLAN 5. I want clients to go either on one or the other based on the authentication.</p><p><br></p><p>On a port I enabled Mac-Based 802.1X Port Access Control. I set up a guest vlan ID (5).</p><p>On the same port I set up the VLAN with untagged VLAN 3 and untagged VLAN 5 with PVID 5.</p><p><br></p><p>On this port if a client connect without any 802.1X security it goes in VLAN 5. If it connects using 802.1X (user configured on FreeRadius with vlan id 3) it goes in VLAN 3. I'm using DHCP on each VLAN with different subnet and getting IP corresponding.</p><p>So in this way the config is working.</p><p><br></p><p>Here is the configuration on the switch :</p><pre class="ql-syntax" spellcheck="false">show running-config interface 0/13

!Current Configuration:
!
interface&nbsp; 0/13
dot1x port-control mac-based
dot1x timeout quiet-period 5
dot1x guest-vlan 5
dot1x timeout guest-vlan-period 5
vlan pvid 5
vlan participation include 3,5
</pre><p><br></p><p>But with this configuration I see a problem : either i'm on guest VLAN 5 or connected and assigned to VLAN 3, i'm receiving the multicast/broadcast traffic of both VLAN (I can see it on Wireshark).</p><p>I think this is because both VLAN 3 and 5 are untagged.</p><p><br></p><p>So I tried the same but assigning VLAN 3 as tagged.</p><p>But with this configuration if I want my clients do go on VLAN 3 I also need to configure tagged VLAN 3 (with 802.1).</p><p><br></p><p>Is this normal ? Is there a way to overcome this issue without tagging interfaces ?</p><p><br></p><p>Thanks</p>]]></description>
            <link>https://community.ui.com/questions/Edgeswitch-802-1X-multiple-untagged-VLANs-and-broadcast-traffic/ae3a6058-96b4-47fd-8ab6-71e7b80ffd40</link>
            <guid isPermaLink="false">ae3a6058-96b4-47fd-8ab6-71e7b80ffd40</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[maximushugus]]></dc:creator>
            <pubDate>Sat, 26 Sep 2026 20:22:41 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[EdgeOS, how to change MTU size for pppoe ?]]></title>
            <description><![CDATA[<p>Hi.</p><p>I am a new owner of a Edgerouter 4. I have updated the firmware to 4 3.0.1.</p><p>I have plugged in the router to my ISP optical fiber adapter, Internet is working fine.</p><p>The configuration is with a pppoe loggin (and Vlan 40 as indicated by EBOX, canadian ISP). I am now trying to optimize MTU size to 1492.</p><p><br></p><p>What I see now configured:&nbsp;&nbsp;</p><p class="ql-indent-1">Interface&nbsp;IP Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;S/L Description&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">---------&nbsp;----------&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;--- -----------&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">eth0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u/u&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">eth0.40&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u/u Internet (PPPoE)&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">eth1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;192.168.1.1/24&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u/u Local&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">eth2&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;192.168.2.1/24&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u/D Local 2&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">eth3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u/D&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;lo&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;127.0.0.1/8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u/u&nbsp;&nbsp;&nbsp;&nbsp;::1/128&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">pppoe0&nbsp;&nbsp;104.163.183.81&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;u/u&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p class="ql-indent-1">ubnt@EdgeRouter-4:~$ show interfaces ethernet eth0.40</p><p class="ql-indent-1">eth0.40@eth0: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 qdisc noqueue state UP&nbsp;</p><p class="ql-indent-1">group default qlen 1000&nbsp;&nbsp;</p><p class="ql-indent-1"><br></p><p>I googled 2 methods to change the MTU to 1492. Both are not working.</p><p>The first thing I try is to use the GUI, but I see no '<strong>action</strong>' button for any interface.</p><p>I then try using the CLI, this command:</p><p class="ql-indent-1"><strong><em>set interfaces pppoe pppoe0 mtu 1492</em></strong></p><p>IT does not work, if you look my currently configure Interface, my guess the name use in my command is wrong ?</p><p>Any help to resolve the situation is appreciated.</p><p><br></p><p>PS: I am not a total noob in networking, but I am new to CLI and EdgeOS.</p><p>Thanks.</p>]]></description>
            <link>https://community.ui.com/questions/EdgeOS-how-to-change-MTU-size-for-pppoe/a33197cd-2ab9-4529-816d-a976e6746f93</link>
            <guid isPermaLink="false">a33197cd-2ab9-4529-816d-a976e6746f93</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[Julie1992]]></dc:creator>
            <pubDate>Wed, 23 Sep 2026 16:14:33 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Edgerouter Edgeswitch Aircube Guest Integration]]></title>
            <description><![CDATA[<p>Dear All,</p><p>I have an EdgeRouter X SFP and 2 aircubes. I want to prepare for deploying some cameras so I bought an Edgeswitch 16 150W.&nbsp;</p><p>As part of the integration, I decided to move everything that I can to the switch, so the router should handle the internet connections only (primary and backup). The switch is connected to the server via SFP. I already moved everything and works fine, except my guest network. On the router I made a logical switch for the ports with name switch0. The guest network operated on switch0.6, used the vlan 6. The firewall rules are fine, I didnt touch them yet. On the switch I made a vlan for the same with 6 vlan id. The switch port, where the AP connects is Untagged on the default vlan and Tagged on the vlan 6.</p><p>I assumed it should work, but the clients can’t receive ip. What would you recommend to check?</p><p>Thanks in advance for any help!</p><p><br></p><p>PS: No vlan-aware used</p>]]></description>
            <link>https://community.ui.com/questions/Edgerouter-Edgeswitch-Aircube-Guest-Integration/7c0e7866-0fc6-4bd0-92cd-c63c83a2c676</link>
            <guid isPermaLink="false">7c0e7866-0fc6-4bd0-92cd-c63c83a2c676</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[ImreKovacs]]></dc:creator>
            <pubDate>Sat, 19 Sep 2026 01:11:18 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[EdgeRouter failover WAN group (eth1) and related firewall rule(s)]]></title>
            <description><![CDATA[<p>RE: My EdgeRouter-X was set-up with the default Load Balancing wizard. So, it has default configuration choices baked in.</p><p><br></p><p>The ER is currently set to failover to eth1, with the entire set of LAN IPs having access to both eth0 and eth1.</p><p>My goal is simple: create an address-group comprised of a sub-set of the group that accesses eth0, i.e. I don't want all LAN devices to be able to access the failover ISP (bandwidth considerations).</p><p><br></p><p>Creating an address-group or network group is easy. But I need to know how to tie this into existing configuration and firewall rules, relative to failover to eth1.</p><p><br></p><p>Should point out that there is already a firewall &gt; modify &gt; balance &gt; rule 1, so if there needs to be another firewall rule prior to this one, this one will need to be moved.</p><p><br></p><p>Thanks for any pointers. Am comfortable with CLI, GUI, config tree... simple configuration command sequence preferred.</p>]]></description>
            <link>https://community.ui.com/questions/EdgeRouter-failover-WAN-group-eth1-and-related-firewall-rules/acfea591-7683-474e-9233-d2e8f0500a3a</link>
            <guid isPermaLink="false">acfea591-7683-474e-9233-d2e8f0500a3a</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[2wander4]]></dc:creator>
            <pubDate>Mon, 07 Sep 2026 03:39:41 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[(Copied from UniFi) Edgerouter (ER-X):  Need to run script on router restart.]]></title>
            <description><![CDATA[<p>After upgrading to firmware 3.0.1, I've noticed the router will "crash" from time to time, unresponsive in all manners available (no UI, no ping response, no routing). <span class="mention" data-id="1814fd48-e64f-441e-9bf8-735b64ce0d25" data-value="UI-Team" data-denotation-char="@"><span contenteditable="false"><span class="ql-mention-denotation-char">@</span>UI-Team</span></span>I'm unsure if there is any way to record what happens (the TTY could be plugged into a nearby PC and monitored for data if it posts anything). Also not sure if there is any current issues with 3.0.1 that would cause it to crash.</p><p><br></p><p>I have an automation that will reboot the router, but what I need to do is to have the router run the script to re-allow (Geo-IP table) outside IP ranges to a specific IP table that is used in routing rules to allow those outside IP ranges into services, without that table, all services are unavailable.</p><p><br></p><p><code>ls -al /config/scripts/post-config.d</code></p><p><code>total 3</code></p><p><code>drwxrwsr-x&nbsp;1 root&nbsp;&nbsp;vyattacf&nbsp;&nbsp;224 Sep 4 14:18 .</code></p><p><code>drwxrwsr-x&nbsp;1 root&nbsp;&nbsp;vyattacf&nbsp;&nbsp;232 Mar 5 2020 ..</code></p><p><code>-rwxr-xr-x&nbsp;1 root&nbsp;&nbsp;vyattacf&nbsp;&nbsp;40 Sep 4 14:18 geo.sh</code></p><p><br></p><p>I have the geo.sh which calls the script I have, but it seems to not work:</p><p><br></p><p><code>sudo sh /config/zonefiles/country-load</code></p><p><br></p><p>I did a sudo reboot in PuTTY on the router and when it comes back up, it fails to run that script, as I know, because I'm sending log information to /var/log/countryload and there is no such file on reboot and all the services are offline from allowed Geo-IP table. I know the script works as I did an sh /config/scripts/post-config.d/geo.sh and it ran, the log file showed up and services came back.</p><p><br></p><p>What is missing to get this script setup to work properly?</p>]]></description>
            <link>https://community.ui.com/questions/Copied-from-UniFi-Edgerouter-ER-X-Need-to-run-script-on-router-restart/8460ed0d-e5c3-4156-9210-8156039fbec5</link>
            <guid isPermaLink="false">8460ed0d-e5c3-4156-9210-8156039fbec5</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[GuruSR]]></dc:creator>
            <pubDate>Fri, 04 Sep 2026 19:53:54 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Documentation for /sbin/switch on ER-X]]></title>
            <description><![CDATA[<p>I want hardware-accelerated port mirroring on my ER-X, so I tested and created documentation for the not-officially-supported /sbin/switch utility.</p><p><br></p><p>Repo: https://github.com/bengoerz/erx-mt7530-switch-docs</p><p><br></p><p>Because this exposes the port mirroring built into the switch silicon, it <strong><em>should</em></strong> support a full 1Gbps port mirror. I plan to test the performance in my homelab soon.</p><p><br></p><p>Credit to gojimmypi's post https://gojimmypi.github.io/Edgerouter-Port-Monitor/ for sparking my curiosity.</p><p><br></p><p>I'd love to hear from anyone who has achieved full 1Gbps port mirroring on an ER-X already.</p>]]></description>
            <link>https://community.ui.com/questions/Documentation-for-sbin-switch-on-ER-X/fd6800d0-ad88-454f-b2b0-3c412b47238a</link>
            <guid isPermaLink="false">fd6800d0-ad88-454f-b2b0-3c412b47238a</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[bengoerz]]></dc:creator>
            <pubDate>Thu, 03 Sep 2026 17:49:39 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Port Forwarding 8080?]]></title>
            <description><![CDATA[<p>Am I doing something wrong to simply add 8080?</p><p>Yes, I found <a href="https://help.uisp.com/hc/en-us/articles/22591049434903-EdgeRouter-Port-Forwarding" rel="noopener noreferrer" target="_blank">https://help.uisp.com/hc/en-us/articles/22591049434903-EdgeRouter-Port-Forwarding</a></p><p>Hints and tips sincerely appreciated!</p><p><br></p><pre class="ql-syntax" spellcheck="false"># open port for httpd forwarding
set firewall name WAN_IN rule 22 action accept
set firewall name WAN_IN rule 22 description httpd
set firewall name WAN_IN rule 22 destination address 192.168.httpd apache server
set firewall name WAN_IN rule 22 destination port 8080
set firewall name WAN_IN rule 22 log disable
set firewall name WAN_IN rule 22 protocol tcp
# set firewall name WAN_IN rule 22 source port 8080 #- tried with and without this

# port-forward configuartion for httpd
set port-forward rule 3 description httpd
set port-forward rule 3 forward-to address 192.168.httpd apache server
set port-forward rule 3 forward-to port 8080
set port-forward rule 3 original-port 8080
set port-forward rule 3 protocol tcp

$ show configuration | no-more
firewall {
&nbsp; &nbsp; all-ping enable
&nbsp; &nbsp; broadcast-ping disable
&nbsp; &nbsp; group {
&nbsp; &nbsp; &nbsp; &nbsp; address-group ExtIP {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address my Pub IP address
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Public IP (eth0)"
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; address-group PBX {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 34.210.91.112/28
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 34.226.36.32/28
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 136.57.136.147
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 24.163.114.98
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; ipv6-name WANv6_IN {
&nbsp; &nbsp; &nbsp; &nbsp; default-action drop
&nbsp; &nbsp; &nbsp; &nbsp; description "WAN inbound traffic forwarded to LAN"
&nbsp; &nbsp; &nbsp; &nbsp; enable-default-log
&nbsp; &nbsp; &nbsp; &nbsp; rule 10 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Allow established/related sessions"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; established enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; related enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 20 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action drop
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Drop invalid state"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; invalid enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; ipv6-name WANv6_LOCAL {
&nbsp; &nbsp; &nbsp; &nbsp; default-action drop
&nbsp; &nbsp; &nbsp; &nbsp; description "WAN inbound traffic to the router"
&nbsp; &nbsp; &nbsp; &nbsp; enable-default-log
&nbsp; &nbsp; &nbsp; &nbsp; rule 10 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Allow established/related sessions"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; established enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; related enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 20 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action drop
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Drop invalid state"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; invalid enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 30 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Allow IPv6 icmp"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; protocol ipv6-icmp
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 40 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "allow dhcpv6"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; destination {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 546
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; protocol udp
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; source {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 547
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; ipv6-receive-redirects disable
&nbsp; &nbsp; ipv6-src-route disable
&nbsp; &nbsp; ip-src-route disable
&nbsp; &nbsp; log-martians enable
&nbsp; &nbsp; name WAN_IN {
&nbsp; &nbsp; &nbsp; &nbsp; default-action drop
&nbsp; &nbsp; &nbsp; &nbsp; description "WAN to internal"
&nbsp; &nbsp; &nbsp; &nbsp; rule 10 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Allow established/related"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; established enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; related enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 20 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description RTP
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; destination {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 192.168PBX box IP
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 10000-25000
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; log disable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; protocol udp
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 21 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Asterisk 5060"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; destination {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 192.168PBX box IP
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 5060
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; log disable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; protocol udp
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; source {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; group {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address-group PBX
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 5060
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 22 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description httpd
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; destination {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 192.168.httpd apache server
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 8080
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; log disable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; protocol tcp
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 50 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action drop
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Drop invalid state"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; invalid enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; name WAN_LOCAL {
&nbsp; &nbsp; &nbsp; &nbsp; default-action drop
&nbsp; &nbsp; &nbsp; &nbsp; description "WAN to router"
&nbsp; &nbsp; &nbsp; &nbsp; rule 10 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action accept
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Allow established/related"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; established enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; related enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; rule 20 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; action drop
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "Drop invalid state"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; state {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; invalid enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; receive-redirects disable
&nbsp; &nbsp; send-redirects enable
&nbsp; &nbsp; source-validation disable
&nbsp; &nbsp; syn-cookies enable
}
interfaces {
&nbsp; &nbsp; ethernet eth0 {
&nbsp; &nbsp; &nbsp; &nbsp; address dhcp
&nbsp; &nbsp; &nbsp; &nbsp; description Internet
&nbsp; &nbsp; &nbsp; &nbsp; duplex auto
&nbsp; &nbsp; &nbsp; &nbsp; firewall {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; in {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ipv6-name WANv6_IN
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; name WAN_IN
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; local {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ipv6-name WANv6_LOCAL
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; name WAN_LOCAL
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; speed auto
&nbsp; &nbsp; }
&nbsp; &nbsp; ethernet eth1 {
&nbsp; &nbsp; &nbsp; &nbsp; description Local
&nbsp; &nbsp; &nbsp; &nbsp; duplex auto
&nbsp; &nbsp; &nbsp; &nbsp; speed auto
&nbsp; &nbsp; }
&nbsp; &nbsp; ethernet eth2 {
&nbsp; &nbsp; &nbsp; &nbsp; description Local
&nbsp; &nbsp; &nbsp; &nbsp; duplex auto
&nbsp; &nbsp; &nbsp; &nbsp; speed auto
&nbsp; &nbsp; }
&nbsp; &nbsp; ethernet eth3 {
&nbsp; &nbsp; &nbsp; &nbsp; description Local
&nbsp; &nbsp; &nbsp; &nbsp; duplex auto
&nbsp; &nbsp; &nbsp; &nbsp; speed auto
&nbsp; &nbsp; }
&nbsp; &nbsp; ethernet eth4 {
&nbsp; &nbsp; &nbsp; &nbsp; description Local
&nbsp; &nbsp; &nbsp; &nbsp; duplex auto
&nbsp; &nbsp; &nbsp; &nbsp; poe {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; output off
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; speed auto
&nbsp; &nbsp; }
&nbsp; &nbsp; loopback lo {
&nbsp; &nbsp; }
&nbsp; &nbsp; switch switch0 {
&nbsp; &nbsp; &nbsp; &nbsp; address 192.168.1.1/24
&nbsp; &nbsp; &nbsp; &nbsp; description Local
&nbsp; &nbsp; &nbsp; &nbsp; mtu 1500
&nbsp; &nbsp; &nbsp; &nbsp; switch-port {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; interface eth1 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; interface eth2 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; interface eth3 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; interface eth4 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; vlan-aware disable
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
}
port-forward {
&nbsp; &nbsp; auto-firewall enable
&nbsp; &nbsp; hairpin-nat enable
&nbsp; &nbsp; lan-interface eth1
&nbsp; &nbsp; rule 1 {
&nbsp; &nbsp; &nbsp; &nbsp; description RTP
&nbsp; &nbsp; &nbsp; &nbsp; forward-to {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 192.168PBX box IP
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 10000-25000
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; original-port 10000-25000
&nbsp; &nbsp; &nbsp; &nbsp; protocol udp
&nbsp; &nbsp; }
&nbsp; &nbsp; rule 2 {
&nbsp; &nbsp; &nbsp; &nbsp; description "Asterisk 5060"
&nbsp; &nbsp; &nbsp; &nbsp; forward-to {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 192.168PBX box IP
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 5060
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; original-port 5060
&nbsp; &nbsp; &nbsp; &nbsp; protocol udp
&nbsp; &nbsp; }
&nbsp; &nbsp; rule 3 {
&nbsp; &nbsp; &nbsp; &nbsp; description httpd
&nbsp; &nbsp; &nbsp; &nbsp; forward-to {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; address 192.168.httpd apache server
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; port 8080
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; original-port 8080
&nbsp; &nbsp; &nbsp; &nbsp; protocol tcp
&nbsp; &nbsp; }
&nbsp; &nbsp; wan-interface eth0
}
service {
&nbsp; &nbsp; dhcp-server {
&nbsp; &nbsp; &nbsp; &nbsp; disabled false
&nbsp; &nbsp; &nbsp; &nbsp; hostfile-update disable
&nbsp; &nbsp; &nbsp; &nbsp; shared-network-name LAN {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; authoritative enable
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; subnet 192.168.1.0/24 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; default-router 192.168.1.1
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; dns-server 192.168.1.1
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; lease 86400
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; start 192.168.1.38 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; stop 192.168.1.243
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; static-mapping Asterisk {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip-address 192.168PBX box IP
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; mac-address xx:xx:xx:xx:xx:xx
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; static-mapping FreeNAS {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ip-address 192.168.fileserver
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; mac-address xx:xx:xx:xx:xx:xx
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; static-arp disable
&nbsp; &nbsp; &nbsp; &nbsp; use-dnsmasq disable
&nbsp; &nbsp; }
&nbsp; &nbsp; dns {
&nbsp; &nbsp; &nbsp; &nbsp; forwarding {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; cache-size 150
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; listen-on switch0
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; gui {
&nbsp; &nbsp; &nbsp; &nbsp; http-port 80
&nbsp; &nbsp; &nbsp; &nbsp; https-port 443
&nbsp; &nbsp; &nbsp; &nbsp; older-ciphers enable
&nbsp; &nbsp; }
&nbsp; &nbsp; nat {
&nbsp; &nbsp; &nbsp; &nbsp; rule 5010 {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description "masquerade for WAN"
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; outbound-interface eth0
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; type masquerade
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; ssh {
&nbsp; &nbsp; &nbsp; &nbsp; port 22
&nbsp; &nbsp; &nbsp; &nbsp; protocol-version v2
&nbsp; &nbsp; }
&nbsp; &nbsp; unms {
&nbsp; &nbsp; }
}
system {
&nbsp; &nbsp; analytics-handler {
&nbsp; &nbsp; &nbsp; &nbsp; send-analytics-report false
&nbsp; &nbsp; }
&nbsp; &nbsp; conntrack {
&nbsp; &nbsp; &nbsp; &nbsp; timeout {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; udp {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; other 60
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; stream 360
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; crash-handler {
&nbsp; &nbsp; &nbsp; &nbsp; send-crash-report false
&nbsp; &nbsp; }
&nbsp; &nbsp; host-name EdgeRouter-X-5-Port
&nbsp; &nbsp; login {
&nbsp; &nbsp; &nbsp; &nbsp; user guest {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; authentication {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; encrypted-password ****************
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; plaintext-password ****************
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; public-keys guest@tatooine {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; key ****************
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; type ssh-rsa
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; level admin
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; ntp {
&nbsp; &nbsp; &nbsp; &nbsp; server 0.ubnt.pool.ntp.org {
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; server 1.ubnt.pool.ntp.org {
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; server 2.ubnt.pool.ntp.org {
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; server 3.ubnt.pool.ntp.org {
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; offload {
&nbsp; &nbsp; &nbsp; &nbsp; hwnat enable
&nbsp; &nbsp; }
&nbsp; &nbsp; syslog {
&nbsp; &nbsp; &nbsp; &nbsp; global {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; facility all {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; level notice
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; facility protocols {
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; level debug
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; &nbsp; &nbsp; }
&nbsp; &nbsp; }
&nbsp; &nbsp; time-zone UTC
}


</pre>]]></description>
            <link>https://community.ui.com/questions/Port-Forwarding-8080/c260954b-a811-4caa-b79e-92c227529bd4</link>
            <guid isPermaLink="false">c260954b-a811-4caa-b79e-92c227529bd4</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[ThePowerTool]]></dc:creator>
            <pubDate>Wed, 02 Sep 2026 13:30:00 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[EF-Core + ER-8-XG]]></title>
            <description><![CDATA[<img src="https://img.community.ui.com/8ce9e05f-6e74-47ad-afb6-e21a04df1cfb/questions/f39d6d2a-399f-4000-b2c5-4787d146d26c/dccc9bf5-215b-4730-b7ab-3bf311611a78" style="width: 100%;object-fit: cover;height: 205px" /><p>HI</p><p><br></p><p>Has anyone tried using an EF Core and an EdgeRouter for a WISP?</p><p>I'm trying or I want to use a EF Core as a firewall and let the EdgeRouter handle all the routing, since the UDM or UniFi has problems with routing and the EdgeRouter is more advanced.</p><p>...or any better suggestions you might have?</p><p>I'm all ears.</p>]]></description>
            <link>https://community.ui.com/questions/EF-Core-ER-8-XG/f39d6d2a-399f-4000-b2c5-4787d146d26c</link>
            <guid isPermaLink="false">f39d6d2a-399f-4000-b2c5-4787d146d26c</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[AnYeLoWAW]]></dc:creator>
            <pubDate>Mon, 31 Aug 2026 00:09:12 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[EdgeRouter 12 with Bouygues Telecom (French ISP) - VLAN + IGMP for IPTV, any experience?]]></title>
            <description><![CDATA[<p>Hi everyone,</p><p><br></p><p>I'm setting up a home automation project (Home Assistant + VLAN to isolate my IoT devices) and I'm planning to switch to Bouygues Telecom (a French ISP) with an external ONT, so I can plug my own router directly into the fiber.</p><p><br></p><p>I found a used EdgeRouter 12 (ER-12) for about 60€ and I'm wondering if it's a good fit for my use case, specifically:</p><p><br></p><p>1) VLAN tagging (VLAN ID 100) + PPPoE for the internet connection</p><p>2) Keeping the Bouygues TV set-top box working (requires VLAN + IGMP Proxy for multicast IPTV)</p><p><br></p><p>I've found confirmation that a UniFi Dream Machine works fine for this exact setup with Bouygues (Internet + Phone + TV all working), but I haven't found anything specific to the EdgeRouter line with this ISP.</p><p><br></p><p>On the technical side, I came across a guide for a UK ISP (BT/EE) using an EdgeRouter X, where the author had to manually assign an IP address to the underlying Ethernet interface (in addition to the PPPoE interface) for the IGMP Proxy to start correctly. Has anyone run into a similar issue, or does the ER-12 handle VLAN + PPPoE + IGMP Proxy smoothly out of the box?</p><p><br></p><p>Any experience, tips, or gotchas would be greatly appreciated. Thanks in advance!</p>]]></description>
            <link>https://community.ui.com/questions/EdgeRouter-12-with-Bouygues-Telecom-French-ISP-VLAN-IGMP-for-IPTV-any-experience/ee1f58e2-2e4c-40d7-83c4-d85931d89917</link>
            <guid isPermaLink="false">ee1f58e2-2e4c-40d7-83c4-d85931d89917</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[Queuedepie]]></dc:creator>
            <pubDate>Sat, 29 Aug 2026 19:28:59 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Give client an specific WAN on a multi WAN environment.]]></title>
            <description><![CDATA[<p><br></p><p>Hi, I'm using Edgerouter to manage several clients and I'm balancing 6 different ISPs.</p><p>I'm trying to give a client to a specific WAN (always the same).</p><p><br></p><p>Right now I have identified this client and added to a static MAC/ IP mapping.</p><p>But don't know how exactly send him through always the same ETH port through CLI commands.</p><p><br></p><p>Thanks in advance.</p><p><br></p><p><span class="mention" data-id="1814fd48-e64f-441e-9bf8-735b64ce0d25" data-value="UI-Team" data-denotation-char="@"><span contenteditable="false"><span class="ql-mention-denotation-char">@</span>UI-Team</span></span> </p>]]></description>
            <link>https://community.ui.com/questions/Give-client-an-specific-WAN-on-a-multi-WAN-environment/d25a0236-34bb-4b02-b49d-c5ea8fe0b352</link>
            <guid isPermaLink="false">d25a0236-34bb-4b02-b49d-c5ea8fe0b352</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[acasber]]></dc:creator>
            <pubDate>Thu, 27 Aug 2026 17:44:51 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[EP-54V-150W]]></title>
            <description><![CDATA[<p>How/where to hook up the battery to this device?</p>]]></description>
            <link>https://community.ui.com/questions/EP-54V-150W/459b9860-fb80-4764-bd71-c80e82ae8a4c</link>
            <guid isPermaLink="false">459b9860-fb80-4764-bd71-c80e82ae8a4c</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[WS386]]></dc:creator>
            <pubDate>Fri, 21 Aug 2026 21:33:38 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[DESCARGAR KMZ]]></title>
            <description><![CDATA[<p>al crear un enlace punto a punto, guardo el proyecto, pero al quedar exportar el KMZ la pagina indica un error pide refrescar, vuelve al punto de origen y no se puede exportar el proyecto a KMZ</p>]]></description>
            <link>https://community.ui.com/questions/DESCARGAR-KMZ/be95d5cc-d2e9-449d-bf55-c39b883d8aa3</link>
            <guid isPermaLink="false">be95d5cc-d2e9-449d-bf55-c39b883d8aa3</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[jose barraza]]></dc:creator>
            <pubDate>Mon, 10 Aug 2026 15:23:57 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Edgerouter ER-8-XG:  is it possible to bridge VLANS (vifs) between interfaces on the same router?]]></title>
            <description><![CDATA[<p>If I have VIFs defined under a bond0 and the same VIFs defined under eth4, is there a way on the ER-8-XG to bridge them in order to pass traffic through?</p><p><br></p><p><br></p><p>In the other Edgerouters I believe we can use the switch0 to accomplish this bridging, but is this possible in the ER-8-XG somehow? I don't believe the switch0 is available in this model.</p><p><br></p><p><br></p><p><br></p><p><br></p>]]></description>
            <link>https://community.ui.com/questions/Edgerouter-ER-8-XG-is-it-possible-to-bridge-VLANS-vifs-between-interfaces-on-the-same-router/724bddb7-747a-47ae-bb6b-8ab8553983be</link>
            <guid isPermaLink="false">724bddb7-747a-47ae-bb6b-8ab8553983be</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[sean-north83]]></dc:creator>
            <pubDate>Mon, 10 Aug 2026 14:22:02 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Bug report: SNMP settings not being restored after reboot]]></title>
            <description><![CDATA[<p><br></p><p>When I reboot my EdgeRouter, the snmp service section is not restored at all.</p><p>Here is the output of <em>show configuration commands</em>, when it's working (pre-reboot).</p><p><br></p><pre class="ql-syntax" spellcheck="false">set service snmp v3 engineid ''
set service snmp v3 group readonly mode ro
set service snmp v3 group readonly seclevel priv
set service snmp v3 group readonly view DefaultRead
set service snmp v3 user &lt;secret hidden&gt; auth encrypted-key &lt;secret hidden&gt;
set service snmp v3 user &lt;secret hidden&gt; auth plaintext-key &lt;secret hidden&gt;
set service snmp v3 user &lt;secret hidden&gt; auth type sha
set service snmp v3 user &lt;secret hidden&gt; engineid ''
set service snmp v3 user &lt;secret hidden&gt; group readonly
set service snmp v3 user &lt;secret hidden&gt; mode ro
set service snmp v3 user &lt;secret hidden&gt; privacy encrypted-key &lt;secret hidden&gt;
set service snmp v3 user &lt;secret hidden&gt; privacy plaintext-key &lt;secret hidden&gt;
set service snmp v3 user &lt;secret hidden&gt; privacy type aes
set service snmp v3 view DefaultRead oid 1
</pre><p>It turns out `set service snmp v3 group readonly view DefaultRead` must be done AFTER `set service snmp v3 view DefaultRead oid 1`. I suppose that's what prevent the restore from working at reboot ?</p><pre class="ql-syntax" spellcheck="false">You must create "DefaultRead" view first

Value validation failed
Set failed
</pre><p>Version: 2.0.9-hotfix7 (will upgrade to 3.0.1 soon, but I haven't seen any bugfix related to snmp in the 3.x.x changelogs).</p><p><br></p><p>Also, there is a chown error:</p><pre class="ql-syntax" spellcheck="false">commit;save
[ service snmp v3 ]
chown: unknown user snmp

Saving configuration to '/config/config.boot'...
</pre><p><br></p><p>Best regards</p>]]></description>
            <link>https://community.ui.com/questions/Bug-report-SNMP-settings-not-being-restored-after-reboot/cc0dd4c0-a398-447d-88d0-ad206da43aca</link>
            <guid isPermaLink="false">cc0dd4c0-a398-447d-88d0-ad206da43aca</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[elliptical123]]></dc:creator>
            <pubDate>Mon, 03 Aug 2026 10:57:58 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Feature request: an official, paid, per-device EdgeSwitch → UniFi firmware conversion]]></title>
            <description><![CDATA[<p><span class="mention" data-id="1814fd48-e64f-441e-9bf8-735b64ce0d25" data-value="UI-Team" data-denotation-char="@"><span contenteditable="false"><span class="ql-mention-denotation-char">@</span>UI-Team</span></span></p><p><br></p><p>I run an IT company and, like a lot of people here, I have a decent number of EdgeSwitches in the field. They work perfectly. They're not broken, they're not slow, and for the sites they sit in nobody needs 2.5G or PoE++. The only thing wrong with them is that they live in a different management world than everything else we deploy today.</p><p><br></p><p>That's the problem I'd like to put forward — and I'm clearly not the first, which is part of the point.</p><p><br></p><p><strong>This question keeps coming back</strong></p><p><br></p><p>A few of the existing threads on this community:</p><p><br></p><ul><li>Install UniFi Switch firmware on Edge Switch — <a href="https://community.ui.com/questions/Install-UniFi-Switch-firmware-on-Edge-Switch/a81b0ac6-faca-474c-a6b1-100d6095928a" rel="noopener noreferrer" target="_blank">https://community.ui.com/questions/Install-UniFi-Switch-firmware-on-Edge-Switch/a81b0ac6-faca-474c-a6b1-100d6095928a</a></li><li>Unifi Switch Firmware on EdgeSwitch? — <a href="https://community.ui.com/questions/dd9a405d-3699-46ea-a9b3-7c7cb26e6ac2" rel="noopener noreferrer" target="_blank">https://community.ui.com/questions/dd9a405d-3699-46ea-a9b3-7c7cb26e6ac2</a></li><li>can you convert an edge switch to a unifi switch? — <a href="https://community.ui.com/questions/can-you-convert-an-edge-switch-to-a-unifi-switch/65e2ffe7-2376-4d97-8f1c-992c88aba0d2" rel="noopener noreferrer" target="_blank">https://community.ui.com/questions/can-you-convert-an-edge-switch-to-a-unifi-switch/65e2ffe7-2376-4d97-8f1c-992c88aba0d2</a></li></ul><p><br></p><p>The same question, asked independently, more than once, never with a resolution. That's usually a signal of unmet demand rather than a handful of people being awkward.</p><p><br></p><p><strong>What changed</strong></p><p><br></p><p>We now standardise on UniFi OS consoles. New sites are UniFi end to end, and the single pane of glass is genuinely one of the strongest reasons to keep buying Ubiquiti. But every site with a legacy EdgeSwitch forces us to either run UISP alongside UniFi just for one or two devices, or accept a blind spot in the topology view — a switch that carries real traffic but shows up as an unmanaged black box. Neither is great, and the blind spot is the one that costs us time on every support call.</p><p><br></p><p><strong>What I'm asking for</strong></p><p><br></p><p>Not a free unlock, and not an unsupported hack. Something official and paid:</p><p><br></p><ul><li>A conversion request tied to a specific device — MAC address and serial number.</li><li>Ubiquiti validates that the model has a supported UniFi equivalent, then generates a signed firmware image bound to that one device.</li><li>A small per-device fee. Speaking for myself, a handful of dollars per switch is an easy yes, and I suspect I'm not alone.</li><li>One-way, clearly documented: converted device is sold as-is, no RMA, support scope limited to what a comparable UniFi switch gets.</li></ul><p>Restricting it to the model pairs that already share hardware would keep the scope small. Nobody's asking for every EdgeSwitch ever made.</p><p>In our case these will be the models that also reside on the UniFi Line; ES-24-Lite - ES-24-PoE-250W - ES-48-Lite - ES-48-500W - ES-48-750W - ES-8-150W - ES-16-150W - ES-16-XG</p><p><br></p><p><strong>Why this is good for Ubiquiti, not just for us</strong></p><p><br></p><ul><li>It's revenue on hardware that was already sold and is currently generating none.</li><li>It keeps us in the ecosystem. The alternative path for a lot of people isn't buying replacement USWs — it's leaving the switch in place, staying half-managed, and slowly getting comfortable with looking at other vendors.</li><li>It sells more UniFi OS consoles and pulls whole sites onto UniFi that are currently stuck in between.</li><li>It's a straightforward sustainability win: working hardware stays in service instead of being replaced for a management-layer reason.</li></ul><p><br></p><p><strong>On the DIY route</strong></p><p><br></p><p>People have tried, and it doesn't work. The most thorough attempt I've seen is documented outside this community (Level1Techs, "Help convert Ubiquiti Edgeswitch to Unifi?"), on a hardware pair that is identical down to the bootloader build and CPU. The UniFi image boots, but the switch driver and the network interface never come up, because the board identity doesn't resolve to a known UniFi profile.</p><p><br></p><p>That's not something the community can or should engineer around. It's exactly the kind of thing only Ubiquiti can do properly, safely, and with a signed image — which is why I'd rather pay for it than watch people keep bricking switches attempting it.</p><p><br></p><p>Would be very interested to hear from others running mixed EdgeSwitch / UniFi estates, and from anyone at Ubiquiti on whether this has ever been considered.</p>]]></description>
            <link>https://community.ui.com/questions/Feature-request-an-official-paid-per-device-EdgeSwitch-UniFi-firmware-conversion/5429ed77-8fa2-4bf2-a08e-873de3ff87ce</link>
            <guid isPermaLink="false">5429ed77-8fa2-4bf2-a08e-873de3ff87ce</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[kayvanaarssen]]></dc:creator>
            <pubDate>Thu, 30 Jul 2026 09:23:54 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[[EdgeRouter] Traffic being dropped although allowed by firewall]]></title>
            <description><![CDATA[<p>Hello,</p><p><br></p><ul><li>Hardware: EdgeRouter Infinity</li><li>Firmware: 2.0.9 hotfix 7</li></ul><p>I noticed kerberos was being dropped, confirmed by reading the logs.</p><p><br></p><pre class="ql-syntax" spellcheck="false">warning kernel: [dmz2it-default-D]IN=eth1.18 OUT=eth1.21 MAC=74:ac:b9:e1:ab:07:2a:f8:b3:5c:65:04:08:00:45:00:00:34 SRC=10.168.191.100 DST=10.168.11.19 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=5241 DF PROTO=TCP SPT=65101 DPT=88 WINDOW=65535 RES=0x00 SYN URGP=0 
warning kernel: [dmz2it-default-D]IN=eth1.18 OUT=eth1.21 MAC=74:ac:b9:e1:ab:07:2a:f8:b3:5c:65:04:08:00:45:00:00:34 SRC=10.168.191.100 DST=10.168.11.19 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=5243 DF PROTO=TCP SPT=65102 DPT=88 WINDOW=65535 RES=0x00 SYN URGP=0 
warning kernel: [dmz2it-default-D]IN=eth1.18 OUT=eth1.21 MAC=74:ac:b9:e1:ab:07:2a:f8:b3:5c:65:04:08:00:45:00:00:34 SRC=10.168.191.100 DST=10.168.11.19 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=5254 DF PROTO=TCP SPT=65103 DPT=88 WINDOW=65535 RES=0x00 SYN URGP=0 
warning kernel: [dmz2it-default-D]IN=eth1.18 OUT=eth1.21 MAC=74:ac:b9:e1:ab:07:2a:f8:b3:5c:65:04:08:00:45:00:00:34 SRC=10.168.191.114 DST=10.168.11.20 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=28951 DF PROTO=TCP SPT=47839 DPT=88 WINDOW=65535 RES=0x00 SYN URGP=0
</pre><p>It turns out I have a rule in dmz2it chain that allows Kerberos.</p><pre class="ql-syntax" spellcheck="false">set firewall name dmz2it rule 19 action accept
set firewall name dmz2it rule 19 description 'Allow AD (kerberos)'
set firewall name dmz2it rule 19 destination group address-group ad-srv
set firewall name dmz2it rule 19 destination group port-group kerberos
set firewall name dmz2it rule 19 protocol tcp_udp
set firewall name dmz2it rule 19 source group address-group vpn-employee-networks

set firewall group port-group kerberos port 88
set firewall group address-group vpn-employee-networks address 10.168.190.0/24
set firewall group address-group vpn-employee-networks address 10.168.191.0/24
set firewall group address-group ad-srv address 10.168.11.19
set firewall group address-group ad-srv address 10.168.11.20
</pre><p>For now I just set the default action of the chain to accept.</p><p><br></p><p>Am I missing something ?</p><p><br></p><p>EDIT: rebooting the router fixed the issue.</p><p>The issue was caused by iptables being "broken". A rule was still referencing a deleted adress-group and a deleted port-group (I don't know how it's possible). Deleting the rule was impossible, even after re-creating the missing address and port groups.</p><p><br></p><p><br></p><p>Thank you,</p>]]></description>
            <link>https://community.ui.com/questions/EdgeRouter-Traffic-being-dropped-although-allowed-by-firewall/1da9c33b-c397-4d2e-be43-ac23a53fbf00</link>
            <guid isPermaLink="false">1da9c33b-c397-4d2e-be43-ac23a53fbf00</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[elliptical123]]></dc:creator>
            <pubDate>Wed, 29 Jul 2026 23:06:54 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[UISP/UNMS Won't Start after FSCK. Application Loading eventually Errors Out.]]></title>
            <description><![CDATA[<p>Will try to be brief but informative.</p><p><br></p><p>I noticed yesterday my UISP self hosted server wasn't responding and when logging into the VM console, I was prompted with the (initramfs) prompt stating that the file system check of root failed requiring a manual fsck.</p><p><br></p><p>I ran FSCK -yf /dev/mapper/&lt;drive name&gt; The results are that various free inodes were fixed with a resulting message that the file system was modified. I exit and let the system finish booting. I went to the login prompt, logged in to the console. So far everything looked good. I did NOT run apt yet so as not to introduce additional variables in.</p><p><br></p><p>I go and load my webpage/domain and it indefinitely sits at "Application Loading - Please wait" until the page errors out.</p><p><br></p><p>I did attempt to upgrade APT files on a previous backup I restored and then reinstalled UNMS, but that resulted in the unms-api docker failing each and every time along with seeing docker mis-match errors relating to docker 29 was found, but Docker 27.5.1 was expected.</p><p><br></p><p>I restored another pure backup and this time did NOT run the UNMS/UISP reinstall and have only FSCK'd the file system. Where should I go from here? The UISP page still errors out after several minutes of Application Loading - Please wait.</p><p><br></p><p>Something caused this that is well outside my 7 day backup window so going to the furthest back backup still had the same errors as backups from 1-2 days ago.</p><p><br></p><p>This is a personal UISP server, not business. I have my own and family/friends UISP devices (about a dozen) in there that I would like to save that data if at ALL possible. Whether fixing the current server or retrieving the backups internally and applying them to a new spun up VM.</p><p><br></p><p>Please help!</p>]]></description>
            <link>https://community.ui.com/questions/UISP-UNMS-Wont-Start-after-FSCK-Application-Loading-eventually-Errors-Out/c4c14d6d-c303-4532-8f4b-732976892e70</link>
            <guid isPermaLink="false">c4c14d6d-c303-4532-8f4b-732976892e70</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[bawalker]]></dc:creator>
            <pubDate>Tue, 14 Jul 2026 20:34:19 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[lb-local-metric-change does not update the RIB on 3.0.1 — locally-generated traffic has no WAN failover (confirmed with output)]]></title>
            <description><![CDATA[<p>**TL;DR:** With a standard dual-WAN WLB failover setup and `lb-local-metric-change enable`, when the primary WAN goes down, `show load-balance` correctly detects it and fails over forwarded/NAT'd traffic — but the main routing table never re-selects the secondary WAN's default route. The most severe impact is that our site-to-site VPN tunnels back to our office do not form correctly over the surviving WAN. I also cannot ping any public IP from the CLI, and my own background monitoring scripts (which run locally on the router) lose all connectivity during the outage. This worked correctly on 1.10.11. Pasting full output below.</p><p><br></p><p>---</p><p><br></p><p>**Environment**</p><p>- Hardware: ERX and ERX-SFP tested</p><p>- Firmware: v3.0.1 (also reproduced on v2.0.9-hotfix.7; worked correctly on v1.10.11)</p><p>- Config: dual-WAN, eth0 = primary (distance 1), eth1 = secondary/failover-only (distance 10), `lb-local enable`, `lb-local-metric-change enable`</p><p><br></p><p>**The obvious error — `show ip route` still selects the dead primary route:**</p><p>```</p><pre class="ql-syntax" spellcheck="false">IP Route Table for VRF "default"
S&nbsp;*&gt; 0.0.0.0/0 [1/0] via 10.10.10.1, eth0
S&nbsp;&nbsp;0.0.0.0/0 [10/0] via 10.20.20.1, eth1
...
Gateway of last resort is not set
</pre><p>```</p><p>Note the `*&gt;` (selected/FIB route) is still on eth0's distance-1 route, even though watchdog/status below confirm eth0 is down and eth1 is the only reachable path.</p><p><br></p><p>**`ip route` (kernel FIB) confirms the same — default still points at the dead interface:**</p><p>```</p><p><code>default via 10.10.10.1 dev eth0 proto zebra</code></p><p>```</p><p><br></p><p>**`<code>show load-balance watchdog</code>` — eth0 is confirmed down, eth1 confirmed reachable:**</p><p>```</p><pre class="ql-syntax" spellcheck="false">Group WAN-LB
&nbsp;eth0
&nbsp;status: Waiting on recovery (0/3)
&nbsp;pings: 155
&nbsp;fails: 155
&nbsp;run fails: 0/5
&nbsp;route drops: 0
&nbsp;ping gateway: 8.8.8.8 - DOWN


&nbsp;eth1
&nbsp;status: OK
&nbsp;pings: 196
&nbsp;fails: 1
&nbsp;run fails: 0/5
&nbsp;route drops: 0
&nbsp;ping gateway: 8.8.8.8 - REACHABLE
</pre><p>```</p><p><br></p><p>**`<code>show load-balance status</code>` — WLB itself has correctly failed over (weight 0% / 100%), but this isn't reflected in the RIB above:**</p><p>```</p><pre class="ql-syntax" spellcheck="false">Group WAN-LB
&nbsp;Balance Local : true
&nbsp;Lock Local DNS : false
&nbsp;Conntrack Flush: true
&nbsp;Sticky Bits&nbsp;: 0x00000000


&nbsp;interface&nbsp;: eth0
&nbsp;reachable&nbsp;: false
&nbsp;status&nbsp;&nbsp;: inactive
&nbsp;gateway&nbsp;&nbsp;: 10.10.10.1
&nbsp;route table : 201
&nbsp;weight&nbsp;&nbsp;: 0%
&nbsp;fo_priority : 100
&nbsp;flows
&nbsp;&nbsp;WAN Out&nbsp;: 0
&nbsp;&nbsp;WAN In&nbsp;: 3
&nbsp;&nbsp;Local ICMP: 346
&nbsp;&nbsp;Local DNS : 0
&nbsp;&nbsp;Local Data: 0

&nbsp;interface&nbsp;: eth1
&nbsp;reachable&nbsp;: true
&nbsp;status&nbsp;&nbsp;: active
&nbsp;gateway&nbsp;&nbsp;: 10.20.20.1
&nbsp;route table : 202
&nbsp;weight&nbsp;&nbsp;: 100%
&nbsp;fo_priority : 60
&nbsp;flows
&nbsp;&nbsp;WAN Out&nbsp;: 0
&nbsp;&nbsp;WAN In&nbsp;: 18
&nbsp;&nbsp;Local ICMP: 197
&nbsp;&nbsp;Local DNS : 0
&nbsp;&nbsp;Local Data: 139
</pre><p>```</p><p><br></p><p>**Relevant config:**</p><p>```</p><pre class="ql-syntax" spellcheck="false">&nbsp;group WAN-LB {
&nbsp;&nbsp;interface eth0 {
&nbsp;&nbsp;&nbsp;route-test {
&nbsp;&nbsp;&nbsp;&nbsp;count {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;failure 5
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;success 3
&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;&nbsp;initial-delay 180
&nbsp;&nbsp;&nbsp;&nbsp;interval 5
&nbsp;&nbsp;&nbsp;&nbsp;type {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ping {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;target 8.8.8.8
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;}
&nbsp;&nbsp;interface eth1 {
&nbsp;&nbsp;&nbsp;failover-only
&nbsp;&nbsp;&nbsp;route {
&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;route-test {
&nbsp;&nbsp;&nbsp;&nbsp;count {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;failure 5
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;success 3
&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;&nbsp;initial-delay 120
&nbsp;&nbsp;&nbsp;&nbsp;interval 5
&nbsp;&nbsp;&nbsp;&nbsp;type {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ping {
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;target 8.8.8.8
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;}
&nbsp;&nbsp;lb-local enable
&nbsp;&nbsp;lb-local-metric-change enable
&nbsp;}
</pre><p>```</p><p><br></p><p>**Impact (highest severity first):**</p><p>1. **Site-to-site VPN tunnels back to our office do not form correctly over the surviving WAN** when the primary fails — this is the most serious consequence, since it directly breaks our office connectivity, not just diagnostics.</p><p>2. With eth0 down, I cannot ping any public IP from the CLI on the router itself.</p><p>3. My own connectivity-monitoring scripts running locally on the router lose all reachability for the duration of the outage.</p><p><br></p><p>This is a basic dual-WAN failover use case, not an edge case, and all three of the above worked correctly on 1.10.11.</p><p><br></p><p>**Questions for the <span class="mention" data-id="1814fd48-e64f-441e-9bf8-735b64ce0d25" data-value="UI-Team" data-denotation-char="@"><span contenteditable="false"><span class="ql-mention-denotation-char">@</span>UI-Team</span></span> / community**</p><p><br></p><p>1. Has the internal implementation of `lb-local-metric-change` changed between 1.10.x and 2.0.x/3.0.x? On 3.0.1 it does not appear to alter the main table's route distance at all, despite WLB itself correctly detecting the failure and failing over forwarded traffic.</p><p>2. Does `failover-only` on the secondary interface change how `lb-local-metric-change` is supposed to behave? My config has it set on eth1 (see config above) — wondering if that's interacting with this.</p><p>3. Is there a supported way to get locally-originated traffic (including router-initiated VPN tunnels) to follow WAN failover on 3.0.1 given this doesn't currently work as documented?</p><p>4. Has anyone else reproduced this on 2.x/3.x, or is there a known workaround (e.g. transition-script based) — particularly one that reliably re-homes VPN tunnels onto the surviving WAN?</p><p><br></p><p>Happy to provide additional sanitized output or run specific diagnostics if it helps track this down. This is currently affecting production office connectivity and monitoring, so any guidance is much appreciated.</p>]]></description>
            <link>https://community.ui.com/questions/lb-local-metric-change-does-not-update-the-RIB-on-3-0-1-locally-generated-traffic-has-no-WAN-failov/3fe9fdbb-1ec8-4cc5-b196-b284b790766c</link>
            <guid isPermaLink="false">3fe9fdbb-1ec8-4cc5-b196-b284b790766c</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[xmtbiker]]></dc:creator>
            <pubDate>Thu, 09 Jul 2026 18:05:03 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[EdgeRouter-12 100 down 900 up]]></title>
            <description><![CDATA[<p>I have an apartment building with an ER-12 (and wave PTP backhaul), and I'm maxing out at about 120 down, 900+ upload.  CPU doesn't break a sweat.  IPv4 forwarding and vlan hardware offloading is enabled.  I've replaced the ER-12 and have the same result.  ER-X-SFP goes 800+/800+.  What in the world am I missing?</p>]]></description>
            <link>https://community.ui.com/questions/EdgeRouter-12-100-down-900-up/d6eae725-e75c-49c6-9b7c-1b8c8070cc47</link>
            <guid isPermaLink="false">d6eae725-e75c-49c6-9b7c-1b8c8070cc47</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[I keep getting banned]]></dc:creator>
            <pubDate>Fri, 26 Jun 2026 13:02:22 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Windows 11 Connectivity Issues]]></title>
            <description><![CDATA[<p>For awhile I have had random internet connectivity issues with Windows 11 and I am looking for some suggestions on how to go about narrowing down the culprit. The normal internet connection path is:</p><p><br></p><p>Windows 11 Pro Laptop (24H2) -&gt; IW HD (6.5.1) -&gt; USW Pro 48 PoE (7.5.2) -&gt; ER4 (3.0.1) [DHCP server] -&gt; Motorola cable modem -&gt; Comcast/Xfinity Internet</p><p><br></p><p>There is also a UCK G2 Plus (5.1.15) running Network (10.4.57).</p><p><br></p><p>When the issue starts, the Windows 11 laptop loses internet connectivity. Restarting the laptop does not fix the issue, but randomly it eventually starts to work again which takes minutes to hours.</p><p><br></p><p>During the time of losing the internet connection, the laptop still receives an IP address from the ER4 DHCP, but cannot ping nor access the ER4. The laptop can, though, ping and access any other device on the network, including the switch, AP, the cloud key, a Synology DS716, etc. All network devices are on the same subnet. Another Windows 11 Pro laptop exhibits the same issue. Other devices, including android phones, iPhones and iPads, do not have the issue and connect just fine.</p><p><br></p><p>When the laptop connection is working normally, ping responses and access to the ER4 is normal, including to all the other devices on the network.</p><p><br></p><p>Has anyone come across this or have suggestions on where to begin with the troubleshooting?</p>]]></description>
            <link>https://community.ui.com/questions/Windows-11-Connectivity-Issues/79478f1f-ff7a-4da7-9ee1-7d76d8ab82c7</link>
            <guid isPermaLink="false">79478f1f-ff7a-4da7-9ee1-7d76d8ab82c7</guid>
            <category><![CDATA[edgemax]]></category>
            <dc:creator><![CDATA[jacobs75xx]]></dc:creator>
            <pubDate>Tue, 23 Jun 2026 19:10:53 GMT</pubDate>
        </item>
    </channel>
</rss>