Joined: 13 Aug 2013 Posts: 6870 Location: Romerike, Norway
Posted: Sun Dec 10, 2017 16:11 Post subject:
It's off for br0, but vlan3 where the set-top box is located is not member of br0.
If my teory is correct, when enabling snooping on the switch the igmpproxy is bypassed and the multicast is sent directly from the wan port to the lan port with the set-top box.
Joined: 13 Aug 2013 Posts: 6870 Location: Romerike, Norway
Posted: Sun Dec 10, 2017 23:27 Post subject:
The cause of the issue is the mix of IGMP v3 and v2.
My ISP uses v3, but their set-top box does not. I also have a Netgear switch that also only supports v2.
When snooping is not turned on on the switch, I see v3 conversation between my router and the upstream router. When enabling, v2 queries go between lan nodes, but no v3 answer goes to the upstream server.
The cause of the issue is the mix of IGMP v3 and v2
Same problem here. When I enable it, IGMPv3 SSM tv-stations don't play anymore and I can see that the communication changes from IGMPv3 to IGMPv2 (which isn't SSM capable).
Wired connection with igmp snooping turned on in /Networking.asp and
swconfig dev switch0 set igmp_snooping 0
swconfig dev switch0 set igmp_v3 0
are doing fine.
But wireless IGMPv3 SSM doesn't work. Do I have to manually create a config file for igmprt?
New to Atheros with the R7800s I have been able to translate my Broadcom R7000 network configuration to the Atheros R7800. The only issue is Multicasting with IGMP to my ISP TVBoxes, both are wired and was working with the R7000. For now I do have ISP Router connected for the TVBoxes to stream correctly til I can get the R7800 working with them.
These TVBoxes are connected on VLAN15 through my switches and I tried many configurations on the R7800 but the stream dies after about 10sec. I had to stop "playing around" since the family wasn't happy with the interruptions. There must be some conflict with the GUI and CLI swconfig. Does anyone have a working configuration I can test?
TIA _________________ Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9
Off Site 1
R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4
Off Site 2
R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531
With build 38840M I was getting boot loops when I enabled IGMP Snooping on br0 under Networking. Also tried enabling IGMP Snooping in the switch and caused IPv6 to stop working.
I updated both R7800s to build 39000M and the same problem enabling IGMP Snooping in the switch caused IPv6 to stop working, I left it disabled. I did set up an Unbridged I/F eth1.15 and enabled IGMP Snooping on br0 under the Network (no boot loop like 38840M). The other problem under DNSMasq I setup DHCP for eth1.15 and devices didn't get an assigned IP addresses, is it a problem with the I/F name eth1.15 which has a "dot" in it? Normally I assign all my I/F to bridges (br1,br2,etc) like I've done with the R7000 Broadcom and use DNSMasq to setup DHCP for bridges (br1,br2,etc) like I currently do with the R7800s. So I tried using DHCPD under Networking and again devices not getting IP Addresses, conflict with DNSmasq? _________________ Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9
Off Site 1
R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4
Off Site 2
R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531
Joined: 24 Feb 2013 Posts: 1634 Location: Belgrade
Posted: Thu Mar 14, 2019 21:45 Post subject:
ssh to your router and type:
Code:
cat /tmp/dnsmasq.conf
do you have some doubled directives?
ddwrt implementation of DNSMasq doesn't have "custom config" anymore, like in old days... Now it's called "Additional Dnsmasq Options"... you can just add "some options" not complete config... Multiple DHCP Server on networking.asp is dnsmasq too...
so if you are not getting IPs on bridge it's either dnsmasq fault or firewall...
I stumbled on similar problem recently that's why I jumped in your post...
I don't understand your commit about DNSMasq and not complete configs?
I don't have conflicts with my DNSMasq config file and it's working fine with br0,br1,b2,b3 & br6 (on Gateway Router). With previous Router R7000 with KONGAC 37985M, IGMP Proxy & Snooping was working but was limited to br0 which was fine.
Currently I have the R7800 (with build 39000M) working with same configuration but without IGMP. Maybe these newer builds broke IGMP.
In anycase I going to leave the ISP Router in for IGMP services to the TVBoxes. It's less of a headache when dealing with ISP Support since they like to "see" their devices online.
I've been working and I succuesfully updated my scripts on my AP router to run 2 openvpn clients and will be monitoring it. _________________ Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9
Off Site 1
R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4
Off Site 2
R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531
I was using the ISP Router for ONLY their IPTV services plus Bridge-Mode enabled to give the R7800 gateway a Public Address.
After having issues with the ISP Router, I removed it. I added a gigabit switch to the ONT Modem (only one port active of 4) to get 2 Pubic Addresses, one to the R7800 for Internet services and the other to the E3000 to handle the IGMP for wired 4K IPTV services. _________________ Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9
Off Site 1
R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4
Off Site 2
R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531
Joined: 16 Nov 2015 Posts: 6447 Location: UK, London, just across the river..
Posted: Sat Oct 05, 2019 19:01 Post subject:
may be im too off topic got this in my R7800 to filter multicast on wi-fi via ebtables...
in start up scipt
insmod ebtables
insmod ebtable_filter
insmod ebt_pkttype
firewall script
ebtables -A FORWARD -o "ath0" --pkttype-type multicast -j DROP
ebtables -A OUTPUT -o "ath0" --pkttype-type multicast -j DROP
i got this long time ago, it was ok i haven't checked R7800 since than... there was a problem with multicast that i fixed with it...
p.s. you could use it for eth or br if so... _________________ Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
Last edited by Alozaros on Sat Oct 05, 2019 20:08; edited 1 time in total
Since I monitor data usage with YAMon3, I prefer to break up data and iptv services. In the past the ISP has reported incorrect data usage. Two months ago they reported nearly 3TB of usage plus the whole family was on vacation for 2 weeks and our normal monthly usage is under 300GB/month. YAMon3 showed only 115GB for that month. Either their router was hacked or they measured iptv as data, either way their router had to go.
ISP Routers more likely have backdoors for tech access and they can push firmware at any time and cause issues with your setup or security, don't like it!! But if I call the ISP for Network issues their Router/Equipment will need to be up and running before I call them (this will only be required til they fix their issue and back to my secure setup). _________________ Home Network on Telus 1Gb PureFibre - 10GbE Copper Backbone
2x R7800 - Gateway & WiFi & 3xWireGuard - DDWRT r53562 Std k4.9
Off Site 1
R7000 - Gateway & WiFi & WireGuard - DDWRT r54517 Std
E3000 - Station Bridge - DDWRT r49626 Mega K4.4
Off Site 2
R7000 - Gateway & WiFi - DDWRT r54517 Std
E2000 - Wired ISP IPTV PVR Blocker - DDWRT r35531