Ik loop helaas een beestje vast
. Heb gisteren de USG PRO 4 binnen gekregen en dacht die config dat fix ik wel even. Helaas blijft nu de USG op provisioning staat en krijg onderstaande fouten in de logs! Lijkt erop dat de commando's niet ondersteund worden door de USG ? Maar ik krijg er helaas geen duidelijkheid over na uren aan google.
Wat ik gedaan heb
* config.gateway.json file aangemaakt
* Config erin geplakt en het juiste MAC adres ingevuld
* json file naar de juiste map op de Cloud-Key gezet (/srv/unifi/data/sites/default/)
* USG PRO 4 geforceerd laat provisionen
* Na max 2 minuten begint hij met onderstaande fouten naar boven te komen
Ik heb deze config gebruikt van HellStorm666 in "\[Ubiquiti-apparatuur] Ervaringen & Discussie - Deel 2" en aangepast naar mijn ip rang 172.16.0.x. Maar ook de standaart 2.xxx range aangehouden. Dus letterlijk copy/past en alleen mac adres aangepast. Dit op een volledige reset van de USG.
Ik heb letterlijk 3 of 4 uur zitten googlen maar nergens antwoorden kunnen vinden die tot de oplossing lijdt helaas.
Iemand enig idee wat ik hier verkeer heb gedaan ? Zie ik iets over het hoofd ? Of doe ik het helemaal verkeerd ? Dit is namelijk de eerste keer dat ik een USG configureer buiten de web interface om.
USG Lan1 zit mijn lan/switch op aangesloten
USG Wan1 zit naar de FTU van kpn (wordt straks via SFP1 als alles werkt)
Cloud key = 5.6.29
USG Pro 4 = 4.4.18.5052172
Wat ik gedaan heb
* config.gateway.json file aangemaakt
* Config erin geplakt en het juiste MAC adres ingevuld
* json file naar de juiste map op de Cloud-Key gezet (/srv/unifi/data/sites/default/)
* USG PRO 4 geforceerd laat provisionen
* Na max 2 minuten begint hij met onderstaande fouten naar boven te komen
Ik heb deze config gebruikt van HellStorm666 in "\[Ubiquiti-apparatuur] Ervaringen & Discussie - Deel 2" en aangepast naar mijn ip rang 172.16.0.x. Maar ook de standaart 2.xxx range aangehouden. Dus letterlijk copy/past en alleen mac adres aangepast. Dit op een volledige reset van de USG.
Ik heb letterlijk 3 of 4 uur zitten googlen maar nergens antwoorden kunnen vinden die tot de oplossing lijdt helaas.
Iemand enig idee wat ik hier verkeer heb gedaan ? Zie ik iets over het hoofd ? Of doe ik het helemaal verkeerd ? Dit is namelijk de eerste keer dat ik een USG configureer buiten de web interface om.
USG Lan1 zit mijn lan/switch op aangesloten
USG Wan1 zit naar de FTU van kpn (wordt straks via SFP1 als alles werkt)
Cloud key = 5.6.29
USG Pro 4 = 4.4.18.5052172
configuration commit error. Error message: { "DELETE" : { "failure" : "0" , "success" : "1"} , "SESSION_ID" : "af13a4fa439011bcd59f0d31de" , "SET" : { "error" : { "firewall ipv6-name WANv6_IN rule 30 destination address ipv6adres" : "\"ipv6adres\" is not a valid value of type \"ipv6_addr_param\"\n\n\uffff0\nValue validation failed\n" , "firewall ipv6-name WANv6_IN rule 40 destination address ipv6adres" : "\"ipv6adres\" is not a valid value of type \"ipv6_addr_param\"\n\n\uffff0\nValue validation failed\n" , "firewall ipv6-name WANv6_IN rule 50 destination address ipv6adres" : "\"ipv6adres\" is not a valid value of type \"ipv6_addr_param\"\n\n\uffff0\nValue validation failed\n" , "interfaces ethernet eth0 address ipv6adres::1/64" : "Invalid IPv6 address\n\n\uffff0\nValue validation failed\n" , "interfaces ethernet eth0 ipv6 dup-addr-detect-transmits 1" : "\"1\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth0 ipv6 router-advert name-server ipv6adres::254" : "\"ipv6adres::254\" is not a valid value of type \"ipv6\"\nValue validation failed\n" , "interfaces ethernet eth0 ipv6 router-advert other-config-flag false" : "\"false\" is not a valid value of type \"bool\"\nValue validation failed\n" , "interfaces ethernet eth0 ipv6 router-advert reachable-time 0" : "\"0\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth0 ipv6 router-advert send-advert true" : "\"true\" is not a valid value of type \"bool\"\nValue validation failed\n" , "interfaces ethernet eth2 dhcp-options default-route-distance 1" : "\"1\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 mtu 1512" : "\"1512\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 4 address dhcp" : "\"4\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 4 description eth2.4 - IPTV" : "\"4\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 4 dhcp-options client-option request subnet-mask, routers, rfc3442-classless-static-routes;" : "\"4\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 4 dhcp-options client-option send vendor-class-identifier "IPTV_RG";" : "\"4\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 4 dhcp-options default-route no-update" : "\"4\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 4 dhcp-options default-route-distance 210" : "\"4\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 4 dhcp-options name-server update" : "\"4\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 description eth2.6 - Internet" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 mtu 1508" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 default-route auto" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 dhcpv6-pd no-dns" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 dhcpv6-pd pd 0 interface eth0" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 dhcpv6-pd pd 0 prefix-length /48" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 dhcpv6-pd rapid-commit disable" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 firewall in ipv6-name WANv6_IN" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 firewall in name WAN_IN" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 firewall local ipv6-name WANv6_LOCAL" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 firewall local name WAN_LOCAL" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 idle-timeout 180" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 ipv6 address autoconf" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 ipv6 dup-addr-detect-transmits 1" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 ipv6 enable" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 mtu 1500" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 name-server auto" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 password kpn" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "interfaces ethernet eth2 vif 6 pppoe 2 user-id f0-9f-c2-ce-41-ea@internet" : "\"6\" is not a valid value of type \"u32\"\nValue validation failed\n" , "port-forward rule 3001 description 1" : "\"3001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "port-forward rule 3001 forward-to address 172.16.1.99" : "\"3001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "port-forward rule 3001 original-port 1" : "\"3001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "port-forward rule 3001 protocol tcp_udp" : "\"3001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service dhcp-server disabled false" : "\"false\" is not a valid value of type \"bool\"\nValue validation failed\n" , "service dhcp-server shared-network-name net_LAN_172.16.0.0-24 subnet 172.16.0.0/24 default-router 172.16.0.1" : "\"172.16.0.0/24\" is not a valid value of type \"ipv4net\"\nValue validation failed\n" , "service dhcp-server shared-network-name net_LAN_172.16.0.0-24 subnet 172.16.0.0/24 dns-server 172.16.0.1" : "\"172.16.0.0/24\" is not a valid value of type \"ipv4net\"\nValue validation failed\n" , "service dhcp-server shared-network-name net_LAN_172.16.0.0-24 subnet 172.16.0.0/24 domain-name localdomain" : "\"172.16.0.0/24\" is not a valid value of type \"ipv4net\"\nValue validation failed\n" , "service dhcp-server shared-network-name net_LAN_172.16.0.0-24 subnet 172.16.0.0/24 lease 86400" : "\"172.16.0.0/24\" is not a valid value of type \"ipv4net\"\nValue validation failed\n" , "service dhcp-server shared-network-name net_LAN_172.16.0.0-24 subnet 172.16.0.0/24 start 172.16.0.40 stop 172.16.0.254" : "\"172.16.0.0/24\" is not a valid value of type \"ipv4net\"\nValue validation failed\n" , "service dhcp-server shared-network-name net_LAN_172.16.0.0-24 subnet 172.16.0.0/24 static-mapping 00-12-a3-01-2d-3f ip-address 172.16.0.23" : "\"172.16.0.0/24\" is not a valid value of type \"ipv4net\"\nValue validation failed\n" , "service dhcp-server shared-network-name net_LAN_172.16.0.0-24 subnet 172.16.0.0/24 static-mapping 00-12-a3-01-2d-3f mac-address 00:12:a3:01:2d:3f" : "\"172.16.0.0/24\" is not a valid value of type \"ipv4net\"\nValue validation failed\n" , "service dns forwarding cache-size 10000" : "\"10000\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service gui https-port 443" : "\"443\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5000 description IPTV" : "\"5000\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5000 destination address 213.75.112.0/21" : "\"5000\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5000 log disable" : "\"5000\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5000 outbound-interface eth2.4" : "\"5000\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5000 protocol all" : "\"5000\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5000 type masquerade" : "\"5000\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5010 description KPN Internet" : "\"5010\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5010 log disable" : "\"5010\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5010 outbound-interface pppoe2" : "\"5010\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5010 protocol all" : "\"5010\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 5010 type masquerade" : "\"5010\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6001 description MASQ corporate_network to WAN" : "\"6001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6001 disable" : "\"6001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6001 log disable" : "\"6001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6001 outbound-interface eth2" : "\"6001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6001 protocol all" : "\"6001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6001 source group network-group corporate_network" : "\"6001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6001 type masquerade" : "\"6001\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6002 description MASQ remote_user_vpn_network to WAN" : "\"6002\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6002 disable" : "\"6002\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6002 log disable" : "\"6002\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6002 outbound-interface eth2" : "\"6002\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6002 protocol all" : "\"6002\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6002 source group network-group remote_user_vpn_network" : "\"6002\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6002 type masquerade" : "\"6002\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6003 description MASQ guest_network to WAN" : "\"6003\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6003 disable" : "\"6003\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6003 log disable" : "\"6003\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6003 outbound-interface eth2" : "\"6003\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6003 protocol all" : "\"6003\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6003 source group network-group guest_network" : "\"6003\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6003 type masquerade" : "\"6003\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service nat rule 6004 disable" : "\"6004\" is not a valid value of type \"u32\"\nValue validation failed\n" , "service ssh port 22" : "\"22\" is not a valid value of type \"u32\"\nValue validation failed\n"} , "failure" : "1" , "success" : "1"}}
{
"firewall": {
"ipv6-name": {
"WANv6_IN": {
"default-action": "drop",
"description": "WAN inbound traffic forwarded to LAN",
"rule": {
"10": {
"action": "accept",
"description": "Allow established/related sessions",
"state": {
"established": "enable",
"related": "enable"
}
},
"20": {
"action": "drop",
"description": "Drop invalid state",
"state": {
"invalid": "enable"
}
},
"30": {
"action": "accept",
"description": "Sonarr",
"destination": {
"port": "8989",
"address": "ipv6adres"
},
"protocol": "tcp"
},
"40": {
"action": "accept",
"description": "Radarr",
"destination": {
"port": "7878",
"address": "ipv6adres"
},
"protocol": "tcp"
},
"50": {
"action": "accept",
"description": "NZBGet",
"destination": {
"port": "6791",
"address": "ipv6adres"
},
"protocol": "tcp"
}
}
},
"WANv6_LOCAL": {
"default-action": "drop",
"description": "WAN inbound traffic to the router",
"rule": {
"10": {
"action": "accept",
"description": "Allow established/related sessions",
"state": {
"established": "enable",
"related": "enable"
}
},
"20": {
"action": "drop",
"description": "Drop invalid state",
"state": {
"invalid": "enable"
}
},
"30": {
"action": "accept",
"description": "Allow IPv6 icmp",
"protocol": "ipv6-icmp"
},
"40": {
"action": "accept",
"description": "allow dhcpv6",
"destination": {
"port": "546"
},
"protocol": "udp",
"source": {
"port": "547"
}
}
}
}
},
"ipv6-receive-redirects": "disable",
"ipv6-src-route": "disable",
"ip-src-route": "disable",
"log-martians": "enable",
"source-validation": "disable"
},
"interfaces": {
"ethernet": {
"eth0": {
"address": [
"ipv6adres::1/64",
"172.16.0.1/16"
],
"description": "eth0 - LAN",
"duplex": "auto",
"speed": "auto",
"ipv6": {
"address": {
"autoconf": "''"
},
"dup-addr-detect-transmits": "1",
"router-advert": {
"cur-hop-limit": "64",
"link-mtu": "0",
"managed-flag": "false",
"max-interval": "600",
"name-server": [
"ipv6adres::254"
],
"other-config-flag": "false",
"prefix": {
"::/64": {
"autonomous-flag": "true",
"on-link-flag": "true",
"valid-lifetime": "2592000"
}
},
"radvd-options": [
"RDNSS ipv6adres::254 {};"
],
"reachable-time": "0",
"retrans-timer": "0",
"send-advert": "true"
}
}
},
"eth2": {
"description": "eth2 - FTTH",
"duplex": "auto",
"mtu": "1512",
"speed": "auto",
"vif": {
"4": {
"address": [
"dhcp"
],
"description": "eth2.4 - IPTV",
"dhcp-options": {
"client-option": [
"send vendor-class-identifier "IPTV_RG";",
"request subnet-mask, routers, rfc3442-classless-static-routes;"
],
"default-route": "no-update",
"default-route-distance": "210",
"name-server": "update"
}
},
"6": {
"description": "eth2.6 - Internet",
"mtu": "1508",
"pppoe": {
"2": {
"default-route": "auto",
"idle-timeout": "180",
"dhcpv6-pd": {
"no-dns": "''",
"pd": {
"0": {
"interface": {
"eth0": "''",
},
"prefix-length": "/48"
}
},
"rapid-commit": "disable"
},
"firewall": {
"in": {
"ipv6-name": "WANv6_IN",
"name": "WAN_IN"
},
"local": {
"ipv6-name": "WANv6_LOCAL",
"name": "WAN_LOCAL"
}
},
"ipv6": {
"address": {
"autoconf": "''"
},
"dup-addr-detect-transmits": "1",
"enable": "''"
},
"mtu": "1500",
"name-server": "auto",
"password": "kpn",
"user-id": "XXXXXXXXXX in mijn json file staat juiste max@internet"
}
}
}
}
}
}
},
"port-forward": {
"auto-firewall": "enable",
"wan-interface": "pppoe2"
},
"protocols": {
"igmp-proxy": {
"interface": {
"eth0": {
"role": "disabled",
"threshold": "1"
},
"eth0.5": {
"role": "disabled",
"threshold": "1"
},
"eth0.4": {
"alt-subnet": [
"0.0.0.0/0"
],
"role": "downstream",
"threshold": "1"
},
"eth1": {
"role": "disabled",
"threshold": "1"
},
"eth2": {
"role": "disabled",
"threshold": "1"
},
"eth2.4": {
"alt-subnet": [
"0.0.0.0/0"
],
"role": "upstream",
"threshold": "1"
},
"eth2.6": {
"role": "disabled",
"threshold": "1"
},
"pppoe2": {
"role": "disabled",
"threshold": "1"
},
"eth3": {
"role": "disabled",
"threshold": "1"
},
}
},
"static": {
"interface-route6": {
"::/0": {
"next-hop-interface": {
"pppoe2": "''"
}
}
}
}
},
"service": {
"dhcp-server": {
"hostfile-update": "disable",
"global-parameters": [
"option vendor-class-identifier code 60 = string;",
"option broadcast-address code 28 = ip-address;"
]
},
"nat": {
"rule": {
"5000": {
"description": "IPTV",
"destination": {
"address": "213.75.112.0/21"
},
"log": "disable",
"outbound-interface": "eth2.4",
"protocol": "all",
"type": "masquerade"
},
"5010": {
"description": "KPN Internet",
"log": "disable",
"outbound-interface": "pppoe2",
"protocol": "all",
"type": "masquerade"
},
"6001": {
"disable": "''"
},
"6002": {
"disable": "''"
},
"6003": {
"disable": "''"
},
"6004": {
"disable": "''"
}
}
}
},
"system": {
"name-server": [
"208.67.222.222",
"2620:0:ccc::2",
"2001:4860:4860::8888",
"8.8.8.8"
]
}
}