Remote-access Guide

edgerouter lite remote access

by Prof. Daryl Lind PhD Published 2 years ago Updated 2 years ago
image

How do I get Started with the edgerouter Lite?

Get started at www.unms.com Static IP Address 1. Connect an Ethernet cable from the Ethernet port of your computer to the port labeled eth0on the EdgeRouter Lite. 2. Configure the Ethernet adapter on your host system with a static IP address on the 192.168.1.x subnet.

Why do I need a VPN server on my edgerouter Lite?

By connecting to my VPN server I have always a secure connection and can access my home network from every location with an internet connection. Creating a VPN server on an Ubiquiti EdgeRouter Lite running EdgeOS is easy!

How to configure edgerouter to work with IPsec?

The VPN users should also get an IP from the EdgeRouter. IPsec requires a pre-shared key for authentication. Replace <password> with your pre-shared key secret. Configure the outside address and next hop address to enable routing to the internet from a VPN connection. Replace <IP address> with the external IP address received by your ISP.

What knowledge is required to use edgerouter L2TP?

Knowledge of the Command Line Interface (CLI) and basic networking knowledge is required. The EdgeRouter L2TP server provides VPN access to the LAN (192.168.1.0/24) for authenticated L2TP clients.

image

How do I log into EdgeRouter Lite?

Type 192.168. 1.1 (the default IP to access the admin interface) in the address bar of your internet browser to access the router's web-based user interface. You should see 2 text fields where you can enter a username and a password. The default username for your Ubiquiti Networks EdgeRouter LITE is ubnt.

What does EdgeRouter Lite do?

Green EdgeRouter Lite is powered on. The EdgeRouter is a router that provides a variety of features, including routing, security, Virtual Private Networking (VPN), monitoring and management services, and Quality of Service (QoS).

How do I access my ubiquiti EdgeRouter?

Establishing Initial ConnectivityConnect an Ethernet cable from a computer to the eth0 interface on the EdgeRouter.Configure a static IP address on your computer in the 192.168. ... Open a Web Browser and enter https://192.168.1.1 in the address bar.Log into the router using the default credentials.More items...

Does EdgeRouter Lite have PoE?

Advanced Routing Technology for the Masses EdgeRouters combine carrier-class reliability with enterprise-level features in a compact and affordable unit. The EdgeRouter PoE and EdgeRouter Lite models are the world's first economical router capable of routing up to 1 million packets per second.

What is EdgeOS?

EdgeOS is a powerful, sophisticated operating system that manages your EdgeRouter. It offers both a browser‑based interface (EdgeOS Configuration Interface) for easy configuration and a Command Line Interface (CLI) for advanced configuration.

How do I set up EdgeRouter pro?

4:0012:03EdgeRouter Pro Unboxing and Setup - YouTubeYouTubeStart of suggested clipEnd of suggested clipSo the first thing I want to do is run through the wizard. Get myself some internet access and thenMoreSo the first thing I want to do is run through the wizard. Get myself some internet access and then update the firmware of this device to a newer version the latest stable version is 18.5.

How do you use EdgeRouter Lite?

3:189:51UBNT EdgeRouter Lite Setup Guide - YouTubeYouTubeStart of suggested clipEnd of suggested clipConnection. Then I go into the properties of the Internet Protocol version 4. And set a static IPMoreConnection. Then I go into the properties of the Internet Protocol version 4. And set a static IP address of 192 168. 1 100 now go to the browser.

How do I SSH into EdgeRouter?

SSH into a Ubiquiti EdgeMax router using a MacOpen up terminal by clicking on the magnifying glass (top right) and typing terminal terminal.Assuming the default username and password hasn't been changed, enter the command ssh ubnt@192.168.1.1. ... When prompted for the password, enter ubnt.More items...•

How do I access ubiquiti console?

UniFi OS consoles can be accessed remotely at unifi.ui.com.

Is edge router PoE?

The EdgeRouter 6P, PoE, and 12P include configurable PoE ports to power airMAX® products, and the EdgeRouter 12 has a PoE input port and a PoE passthrough port. The EdgeRouter 4 and EdgeRouter 6P provide an SFP port.

What is Unifi EdgeRouter?

Ubiquiti introduces the EdgeRouter™ X, part of the EdgeMAX® platform. The EdgeRouter X combines carrier‑class reliability with excellent price‑to‑performance value in an ultra‑compact form factor. The ER-X, can be powered by an external power adapter or 24V passive PoE input.

How do I reset my EdgeRouter Lite?

Press and hold the Reset button for about 10 seconds until the right LED on port eth2 starts flashing and then becomes solidly lit. After a few seconds, the LED will turn off, and the EdgeRouter Lite will automatically reboot.

How do I Reset my edge Lite router?

Press and hold the Reset button for about 10 seconds until the right LED on port eth2 starts flashing and then becomes solidly lit. After a few seconds, the LED will turn off, and the EdgeRouter Lite will automatically reboot.

How do I Reset my EdgeRouter?

Power-on reset Disconnect power from the EdgeRouter. Press and hold the Reset button while connecting power to the EdgeRouter. The port LEDs will light up in sequential order. Keep holding the Reset button until the LED on the last port starts flashing, and then release the button.

Configuring the L2TP Server

The EdgeRouter L2TP server provides VPN access to the LAN (192.168.1.0/24) for authenticated L2TP clients.

Setting up the L2TP Client

The next step is to configure the L2TP VPN settings on the client (s). Make sure to match the credentials on the client and server (EdgeRouter).

My setup

To understand the configuration you should first know my setup. I have an Ubiquiti EdgeRouter Lite with 3 ports. The port configuration:

Enable IPsec on pppoe0

First, configure the allowed networks and enable NAT traversal on the pppoe0 interface.

Enable L2TP remote access with local authentication

I use the local authentication of the EdgeRouter but you can also use RADIUS.

IPsec shared key

IPsec requires a pre-shared key for authentication. Replace <password> with your pre-shared key secret.

L2TP routing

Configure the outside address and next hop address to enable routing to the internet from a VPN connection. Replace <IP address> with the external IP address received by your ISP.

MTU tuning

You can set an MTU to avoid fragmentation and reassembly in the L2TP switching path.

Firewall

To allow VPN users to connect to your VPN server you have to open some ports in the firewall.

How to mount Edgerouter Lite?

To mount the EdgeRouter Lite on a wall, you will need a drill, a 6 mm drill bit, and a Phillips screwdriver. 1. Use a 6 mm drill bit to drill two holes 100 mm apart. 2. Insert the Screw Anchorsinto the holes.

What is the IP address of EdgeOS?

By default, eth1 is set up as a DHCP client, while eth0 is assigned a static IP address of 192.168.1.1. To configure the EdgeRouter, proceed to the appropriate section: DHCP or “Static IP Address”.

What is required to connect to a different power source than those specified?

1. Compliance is required with respect to voltage, frequency, and current requirements indicated on the manufacturer’s label. Connection to a different power source than those specified may result in improper operation, damage to the equipment or pose a fire hazard if the limitations are not followed. 2.

Why does my router reboot from port 0 to port 1?

When the reboot starts, move your computer from port 0 to port 1. This is because both configurations change the LAN connection from port 0 to port 1. Connect your modem or internet connection device to port 0 . Wait about a minute for the router to reboot.

How to reset a USB port 2?

Press and hold the Reset button while connecting the Power Adapter to the Power port. Keep holding the button until the right LED on port 2 starts flashing and then stops after a few seconds. Make sure you press the reset button until the port 2 light stops flashing and goes out.

Can I transfer files to ERL?

You can transfer files to the ERL using WinSCP and other SSH based programs. But note that most files are owned by root, so you can't just overwrite them. You will have to rename the config.boot file first, then upload your modified version and then reboot the ERL to have the new configuration used.

Is Ubiquiti EdgeRouter Lite a NAT router?

In my review of Ubiquiti's EdgeRouter Lite (ERL), I promised some help with getting the router from its out-of-box raw state that doesn't function as a basic NAT router into something that actually works as a NAT router!

Firewall rules

The next step is to create the Firewall rules, to allow the VPN tunnel establishment and the VPN traffic to go through the Router. Copy and paste the following commands, note that you may need to change the rule names, depending on the rules that you already have in place.

Configure the authentication

Then we are going to configure the authentication, here you need to replace the pre-shared-secret key with some strong password.

Create a user

Now, we will create a user, repeat this steps several times if you have more users.

Assign the IP range

Now, we are going to assign the IP range for the SNAT Pool. This is a range of IP addresses on your network that will be used for DHCP to assign internal IP addresses to the users. As an example we will use 192.168.2.30-192.168.2.130, which means we have enough IP addresses for 100 users.

Select the interface

We will select the interface where will allow the VPN Tunnel to be established, this is your Internet facing interface. In our example eth2

Windows 10 setting

Following these steps the VPN tunnel should be established without issues. If your Windows 10 users are having connection fails, make sure you enable MSCHAPv2 on the VPN adapter as this is required for L2TP tunnels with Ubiquiti EdgeRouter to work as shown below:

image

Table of Contents

Establishing Initial Connectivity

  • In the factory default state, the EdgeRouter is accessible on the 192.168.1.1IP address on the eth0 interface. Refer to the sections below for more information on how access the EdgeRouter using either the Web UI, CLI or Console connection on different operating systems. 1. Connect an Ethernet cable from a computer to the eth0interface on the EdgeRouter. 2. Configure a static IP …
See more on help.ui.com

Accessing The EdgeRouter Using The Discovery Tool

  • The Ubiquiti Device Discovery Toolautomatically discovers nearby EdgeRouters (and other Ubiquiti products) on the local network. The tool allows you to conveniently open the Web UI of the EdgeRouter and also provides recovery features such as the Rescue Web UI and SSH Recovery service. 1. Download the Ubiquiti Device Discovery Toolfrom the official Download sec…
See more on help.ui.com

Accessing The EdgeRouter on Macos

  • Back to Top There are three options to access the EdgeRouter from a macOS computer: 1. Use the Ubiquiti Device Discovery Tool in the section aboveto automatically open a session to the Web UI. 2. Access the Web UI manually by navigating to https://192.168.1.1using your favorite browser. 3. Access the EdgeRouter's Command Line Interface (CLI) using either SSH or the Console port. …
See more on help.ui.com

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 1 2 3 4 5 6 7 8 9