Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wan Gateway interference #845

Closed
ai6bx opened this issue May 21, 2023 · 8 comments
Closed

Wan Gateway interference #845

ai6bx opened this issue May 21, 2023 · 8 comments

Comments

@ai6bx
Copy link

ai6bx commented May 21, 2023

This is a challenge I have run into for some time and, depending on the connections, have found a couple ways to manage it. Looking at the Advanced Config section under the WAN section I am wondering if the prevent others on my LAN connections from accessing my WAN will help out.

One of my sites has a WAN link from my QTH providing the bridge for a number of DMR D-Star and Allstar linked repeaters. If I get another WAN gateway that is too close, I start seeing drops and packet loss. With the recent advancements, is there a better way to manage this so repeaters at my site will only use the link to my QTH? I am hosting a few tunnels from my QTH as well. Is it possible that this is contributing?

Thank you,

Keith - AI6BX

@VA2XJM
Copy link
Contributor

VA2XJM commented May 22, 2023

Best way I found to achieve is to setup a VPN server at Internet gateway location and route traffic through an unencrypted VPN over the mesh. This way, the traffic will always goes through the wished gateway. Pretty easy to do using a cheap mikrotik router or a raspberry pi with PiVPN.

@ai6bx
Copy link
Author

ai6bx commented May 22, 2023 via email

@VA2XJM
Copy link
Contributor

VA2XJM commented May 22, 2023

For Ubiquiti device, you will be on your own or someone else will be needed as I have not much knowledge of those devices.

Due to some factor (Pi prices and availability, ease of use...) we switched toward Mikrotitk hardware to host this kind of systems.

The way I do it, is a Pi or Mikrotik hAP device inside the mesh (10...*) at the location where Internet is available. Until recently, I was using a Raspberry Pi that hosted OpenVPN server (search Pi VPN) and added clients for each system needing Internet access. You may need to put some filtering rules to prohibit use of encryption (ex: HTTPS).

Then at each system, I setuped the VPN client and made it default gateway for non-10 address. So mesh traffic goes directly to mesh and Internet traffic will go through VPN-over-mesh.

One interesting thing we were doing was to redirect Yaesu Wires-X ports through the VPN for a FTM-100 node feeding repeaters.

For AllStarLink, what we do is to run a "hub" VM on the mesh boundary. The hub will connect to outside world and mesh systems runing a 1000-1999 node number will connect to boundary server. This way the link is properly done, quite simple and very easy to monitor and troubleshoot.

@ai6bx
Copy link
Author

ai6bx commented May 24, 2023 via email

@ai6bx
Copy link
Author

ai6bx commented May 26, 2023 via email

@ai6bx
Copy link
Author

ai6bx commented May 26, 2023 via email

@VA2XJM
Copy link
Contributor

VA2XJM commented May 26, 2023

You may need to enable IPv4 forward and apply masquerade rules to your firewall (iptables) on the VPN server.

If you are on AREDN Community Slack you can drop me a private message there or an email (call @ gmail.com). I'll give you more help toward that without flooding everyone in here.

@ai6bx
Copy link
Author

ai6bx commented May 26, 2023 via email

@ai6bx ai6bx closed this as completed Jun 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants