Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
495 Pages « < 200 201 202 203 204 > » Bottom

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadband Thread V42, READ 1ST PAGE FOR RELEVANT WIFI INFO!

views
     
kwss
post Jul 28 2024, 07:25 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(kerolzarmyfanboy @ Jul 28 2024, 07:09 PM)
no no it starts from PADI. the logs sequence starts from bottom to top per the timestamp on the left. i guess the way i copy paste it is confusing to read.

2024-07-28 15:15:05 PPP INFO [22432] ppp receive LCP ACK
2024-07-28 15:15:05 PPP INFO [22432] ppp send LCP Request options(mru=1480;magic=0x72f5ad01;)
2024-07-28 15:15:05 PPP INFO [22432] pppoe receive PADS sess-id(9466)
2024-07-28 15:15:05 PPP INFO [22432] pppoe send PADR Host-Uniq(57a0)
2024-07-28 15:15:05 PPP INFO [22432] pppoe receive PADO form AC-MAC(00:00:5e:00:01:bb)
2024-07-28 15:15:05 PPP INFO [22432] pppoe receive PADO AC-Name(ibse04.wmu)
2024-07-28 15:15:05 PPP INFO [22432] pppoe send PADI Host-Uniq(57a0)
2024-07-28 15:15:05 PPP INFO [22432] pppoe send PADT due to(resending PADI)
2024-07-28 15:15:04 PPP INFO [21735] ppp send LCP TermReq due to Failed to authenticate ourselves to peer
2024-07-28 15:15:04 PPP WARNING [21735] ppp receive PAP AuthNak Access number is exceed

so there were a few earlier attempts that were unsuccessful, hence there's that access number exceed & failed to authenticate errors and then i believe that made the router dropped that session & try build another new PPoE session with TM by sending another PADI, redo the negotiation again.

really standard home internet setup, not running more than one PPP client.
my internet works now, but yea it's not stable this past week. fairly confident it's going to disconnect again in a few hours or minutes even. already on my fourth disconnect just for today. the logs were from my third one.  sweat.gif
*
Okay this looks correct.
Things you can observe:
Did the LOS light on ONU turn red when it disconnect? It tells you the fiber is cut off. With Nokia ONU it will bring down the Ethernet port too so that should show up in your log.

Can you increase the ppp client log level? I suspect there is missing LCP-Echo Request and LCP-Echo Reply. Maybe I miss it in your log
kerolzarmyfanboy
post Jul 28 2024, 07:49 PM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
QUOTE(kwss @ Jul 28 2024, 07:25 PM)
Okay this looks correct.
Things you can observe:
Did the LOS light on ONU turn red when it disconnect? It tells you the fiber is cut off. With Nokia ONU it will bring down the Ethernet port too so that should show up in your log.

Can you increase the ppp client log level? I suspect there is missing LCP-Echo Request and LCP-Echo Reply. Maybe I miss it in your log
*
the ONU didn't turn red when it happened.
I don't see LCP-Echo Request and LCP-Echo Reply specifically, but i think maybe different naming in mine, is it the LCP Request & LCP ACK in my log below?

2024-07-28 15:16:05 PPP INFO [26525] ppp send LCP TermReq due to Failed to authenticate ourselves to peer
2024-07-28 15:16:05 PPP WARNING [26525] ppp receive PAP AuthNak Access number is exceed
2024-07-28 15:16:05 PPP INFO [26525] ppp send PAP AuthReq user=(kerolz94@unifi)
2024-07-28 15:16:05 PPP INFO [26525] ppp send LCP ACK
2024-07-28 15:16:05 PPP INFO [26525] ppp receive LCP Request options(mru=1492;authtype=PPP_PAP;magic=0xbcc967e0;)
2024-07-28 15:16:05 PPP INFO [26525] ppp receive LCP ACK
2024-07-28 15:16:05 PPP INFO [26525] ppp send LCP Request options(mru=1480;magic=0x3770669d;)
2024-07-28 15:16:02 PPP INFO [26525] ppp receive LCP ACK
2024-07-28 15:16:02 PPP INFO [26525] ppp send LCP Request options(mru=1480;magic=0x3770669d;)
2024-07-28 15:16:01 PPP INFO [26525] pppoe receive PADS sess-id(14958)
2024-07-28 15:16:01 PPP INFO [26525] pppoe send PADR Host-Uniq(679d)
2024-07-28 15:16:01 PPP INFO [26525] pppoe receive PADO form AC-MAC(00:00:5e:00:01:bb)
2024-07-28 15:16:01 PPP INFO [26525] pppoe receive PADO AC-Name(ibse04.wmu)
2024-07-28 15:16:01 PPP INFO [26525] pppoe send PADI Host-Uniq(679d)
2024-07-28 15:16:01 PPP INFO [26525] pppoe send PADT due to(resending PADI)
kwss
post Jul 28 2024, 08:00 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(kerolzarmyfanboy @ Jul 28 2024, 07:49 PM)
the ONU didn't turn red when it happened.
I don't see LCP-Echo Request and LCP-Echo Reply specifically, but i think maybe different naming in mine, is it the LCP Request & LCP ACK in my log below?

2024-07-28 15:16:05 PPP INFO [26525] ppp send LCP TermReq due to Failed to authenticate ourselves to peer
2024-07-28 15:16:05 PPP WARNING [26525] ppp receive PAP AuthNak Access number is exceed
2024-07-28 15:16:05 PPP INFO [26525] ppp send PAP AuthReq user=(kerolz94@unifi)
2024-07-28 15:16:05 PPP INFO [26525] ppp send LCP ACK
2024-07-28 15:16:05 PPP INFO [26525] ppp receive LCP Request options(mru=1492;authtype=PPP_PAP;magic=0xbcc967e0;)
2024-07-28 15:16:05 PPP INFO [26525] ppp receive LCP ACK
2024-07-28 15:16:05 PPP INFO [26525] ppp send LCP Request options(mru=1480;magic=0x3770669d;)
2024-07-28 15:16:02 PPP INFO [26525] ppp receive LCP ACK
2024-07-28 15:16:02 PPP INFO [26525] ppp send LCP Request options(mru=1480;magic=0x3770669d;)
2024-07-28 15:16:01 PPP INFO [26525] pppoe receive PADS sess-id(14958)
2024-07-28 15:16:01 PPP INFO [26525] pppoe send PADR Host-Uniq(679d)
2024-07-28 15:16:01 PPP INFO [26525] pppoe receive PADO form AC-MAC(00:00:5e:00:01:bb)
2024-07-28 15:16:01 PPP INFO [26525] pppoe receive PADO AC-Name(ibse04.wmu)
2024-07-28 15:16:01 PPP INFO [26525] pppoe send PADI Host-Uniq(679d)
2024-07-28 15:16:01 PPP INFO [26525] pppoe send PADT due to(resending PADI)
*
No that's not it.
LCP-Echo happen periodically in a session to detect if the season is still alive. You need to explicitly log it.

If you have access to the ONU, can you login and keep an eye on the operational status? Not sure if your ONU can enable logging, Any changes from O5 means there's a momentary disconnect between the ONU and OLT.

However, the disconnect need to last long enough for the ppp season to timeout so you should be able to catch it.

Oh hey, we live nearby each other.
Anime4000
post Jul 28 2024, 10:33 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


I make a complain to MCMC about Unifi IPv6 which disallow Home to having subnetting IPv6 even request /60 prefix,

Just in case... had to resort using NPTv6/NAT66, Unifi also disallow it!!!
user posted image

I tested both TIME and Maxis, they can allow NAT, but not Unifi...
kwss
post Jul 28 2024, 10:44 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(Anime4000 @ Jul 28 2024, 10:33 PM)
I make a complain to MCMC about Unifi IPv6 which disallow Home to having subnetting IPv6 even request /60 prefix,

Just in case... had to resort using NPTv6/NAT66, Unifi also disallow it!!!
user posted image

I tested both TIME and Maxis, they can allow NAT, but not Unifi...
*
TM don't allow this for as long as I remember.
So you can only have 1 IPv6 subnet on TM.
On other ISP you can have 2 with your little hack.
Anime4000
post Jul 28 2024, 10:49 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


QUOTE(kwss @ Jul 28 2024, 10:44 PM)
TM don't allow this for as long as I remember.
So you can only have 1 IPv6 subnet on TM.
On other ISP you can have 2 with your little hack.
*
This is stupid, not having Subnetting IPv6, even not allow NPTv6/NAT66 due to Router lacks of IP Address

No wonder same Maxis configuration not working, I even replicate on TIME, and it works...

I wonder Why TM do this? aren't IPv6 has very huge address??
kwss
post Jul 28 2024, 10:52 PM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(Anime4000 @ Jul 28 2024, 10:49 PM)
This is stupid, not having Subnetting IPv6, even not allow NPTv6/NAT66 due to Router lacks of IP Address

No wonder same Maxis configuration not working, I even replicate on TIME, and it works...

I wonder Why TM do this? aren't IPv6 has very huge address??
*
Their appetite to save IPv6 address is remarkable. They can just submit a plan to APNIC and get a new block for free. Yet they pull this kind of stunt.
My conspiracy theory is they try to make the network broken for Unifi customer so that you move to TM One
Leroi2x
post Jul 28 2024, 11:18 PM

Enthusiast
*****
Junior Member
701 posts

Joined: Oct 2009
QUOTE(YoungMan @ Jun 21 2024, 09:53 PM)
Ini you kena try tanya di Tmpoint. Tapi Rm79 untuk 100mbps free 6 bulan memang ada.
*
Hi, is this rm79 + free 6 month must bundle with unifi mobile rm39 for at least 2 month?
That's what the guy in tmpoint tell me
Im doubt on this
kcl2006ch
post Jul 28 2024, 11:28 PM

Getting Started
**
Junior Member
288 posts

Joined: Sep 2020


QUOTE(Leroi2x @ Jul 28 2024, 11:18 PM)
Hi, is this rm79 + free 6 month must bundle with unifi mobile rm39 for at least 2 month?
That's what the guy in tmpoint tell me
Im doubt on this
*
all SWU package need bundle with unifi mobile sim card, minimum RM39 , the sim card can be terminate after the ONR replacement
zellleonhart
post Jul 29 2024, 01:42 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


Can anyone check if you can access this website https://tailscale.com? I can't access it on unifi, even with my own DNS, but all good with Digi or under VPN. Pinging it 76.76.21.21 returns 100% packet loss.

I happen to want to read a blogpost there but turns out I can't access. This is not the first time I randomly encounter a common/popular site that is not accessible via unifi.
kwss
post Jul 29 2024, 02:04 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(zellleonhart @ Jul 29 2024, 01:42 AM)
Can anyone check if you can access this website https://tailscale.com? I can't access it on unifi, even with my own DNS, but all good with Digi or under VPN. Pinging it 76.76.21.21 returns 100% packet loss.

I happen to want to read a blogpost there but turns out I can't access. This is not the first time I randomly encounter a common/popular site that is not accessible via unifi.
*
UPDATE: Not MITM after checking with my laptop

Wow wow wow.... Because on IPv4, TM redirect it to Vercel hosting. The 308 redirect to https:///nice%20ports%2C/Tri%6Eity.txt%2ebak
For port 443 Vercel return X-Vercel-Error: DEPLOYMENT_NOT_FOUND because it's invalid.

IPv6 remains working because it go to the actual server.

I am outside now and SSH back to test for you. Without access to my machine with all the tooling I am limited to what I can do on the phone.

I'm not making shit up, I collected nmap log. Will post....

This post has been edited by kwss: Jul 29 2024, 06:21 AM
countingcrows
post Jul 29 2024, 02:23 AM

Getting Started
**
Junior Member
258 posts

Joined: Feb 2023
QUOTE(zellleonhart @ Jul 29 2024, 01:42 AM)
Can anyone check if you can access this website https://tailscale.com?
Can.

user posted image

kwss
post Jul 29 2024, 02:31 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(countingcrows @ Jul 29 2024, 02:23 AM)
Can.

user posted image
*
You must be using IPv6. Checked again the MITM is still on going
countingcrows
post Jul 29 2024, 02:37 AM

Getting Started
**
Junior Member
258 posts

Joined: Feb 2023
QUOTE(kwss @ Jul 29 2024, 02:31 AM)
You must be using IPv6. Checked again the MITM is still on going
*
Yup using IPv6.

Can ping 76.76.21.21 too, if it helps.
kwss
post Jul 29 2024, 02:39 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
QUOTE(countingcrows @ Jul 29 2024, 02:37 AM)
Yup using IPv6.

Can ping 76.76.21.21 too, if it helps.
*
I do not have access to my Wireshark but I suspect TM rewrite the destination address on egress.
So yea you can ping because you are actually pinging Vercel.
cklove96
post Jul 29 2024, 04:08 AM

hehe
*****
Junior Member
705 posts

Joined: Feb 2017

QUOTE(zellleonhart @ Jul 29 2024, 02:42 AM)
Can anyone check if you can access this website https://tailscale.com? I can't access it on unifi, even with my own DNS, but all good with Digi or under VPN. Pinging it 76.76.21.21 returns 100% packet loss.

I happen to want to read a blogpost there but turns out I can't access. This is not the first time I randomly encounter a common/popular site that is not accessible via unifi.
*
can access (ipv6 enabled)
kwss
post Jul 29 2024, 06:55 AM

Regular
******
Senior Member
1,207 posts

Joined: Aug 2018
A bit of update after checking with laptop.
It seems nothing is wrong...

I ran the same nmap scan using my Amazon EC2 instance in Oregon, US.
Same result.

curl on TM:
CODE

curl -v -4 http://tailscale.com
* Host tailscale.com:80 was resolved.
* IPv6: (none)
* IPv4: 76.76.21.21
*   Trying 76.76.21.21:80...
* Connected to tailscale.com (76.76.21.21) port 80
> GET / HTTP/1.1
> Host: tailscale.com
> User-Agent: curl/8.6.0
> Accept: */*
>
* HTTP 1.0, assume close after body
< HTTP/1.0 308 Permanent Redirect
< Content-Type: text/plain
< Location: https://tailscale.com/
< Refresh: 0;url=https://tailscale.com/
< server: Vercel
<
* Closing connection
Redirecting...


curl on AWS:
CODE

curl -v -4 http://tailscale.com
* Host tailscale.com:80 was resolved.
* IPv6: (none)
* IPv4: 76.76.21.21
*   Trying 76.76.21.21:80...
* Connected to tailscale.com (76.76.21.21) port 80
> GET / HTTP/1.1
> Host: tailscale.com
> User-Agent: curl/8.5.0
> Accept: */*
>
* HTTP 1.0, assume close after body
< HTTP/1.0 308 Permanent Redirect
< Content-Type: text/plain
< Location: https://tailscale.com/
< Refresh: 0;url=https://tailscale.com/
< server: Vercel
<
* Closing connection


For transparency purpose here is the IPv4 nmap
» Click to show Spoiler - click again to hide... «


Here is the IPv6 nmap
» Click to show Spoiler - click again to hide... «


I even scan the whole subnet on TM and AWS. Attached here for record keeping purpose.


Attached File(s)
Attached File  subnet_scan_aws.txt ( 214.87k ) Number of downloads: 2
Attached File  subnet_scan_tm.txt ( 215.27k ) Number of downloads: 2
nik91
post Jul 29 2024, 10:31 AM

Getting Started
**
Junior Member
96 posts

Joined: Aug 2011


Now UniFi has fixed high ping connection to certain Taiwan areas, just not long before, there's high ping issue in Philippines and was quickly fixed. Joining friend server in Taiwan now with normal ping instead of 250+ ms. Just for info...

Anyone know where I can see full info about network problem from Malaysia to the rest of country?
zellleonhart
post Jul 29 2024, 11:35 AM

Stars stars stars
*******
Senior Member
5,075 posts

Joined: Oct 2008


QUOTE(kwss @ Jul 29 2024, 06:55 AM)
A bit of update after checking with laptop.
It seems nothing is wrong...

I ran the same nmap scan using my Amazon EC2 instance in Oregon, US.
Same result.

...
*
Hmm sorry I am not technical enough to understand - so there's no issue actually? Just tried again and still can't access/ping on IPv4... Can't afford to get a new public IP now since I am outside, but will see if a new IP range works.

Tried your command and it's loading forever:

CODE

curl -v -4 http://tailscale.com
*   Trying 76.76.21.21:80...


This post has been edited by zellleonhart: Jul 29 2024, 11:39 AM
Anime4000
post Jul 29 2024, 12:43 PM

Look at all my stars!!
*******
Senior Member
2,399 posts

Joined: Jul 2009
From: /dev/null


kwss seem Unifi IPv6 has broken IX or potential MITM attack?

My Mikrotik cannot join my friend BGP bangwall.gif
user posted image

Bogon IX?
user posted image
https://bgpview.io/ip/2001:8f8:0:10:0:21:58:2a

495 Pages « < 200 201 202 203 204 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0218sec    0.65    6 queries    GZIP Disabled
Time is now: 4th December 2025 - 11:15 AM