Introduction Ventilation Holes Power Thank you for purchasing the Ubiquiti EdgeRouter Lite, ™ model ERLite-3. It is part of the EdgeMAX platform. For ™ 12V DC more information, visit www.ubnt.com/edgemax. GROUND The EdgeRouter is a router that provides a variety of...
Mounting Template The recommended mounting orientation is horizontal with the ports facing down. Note: The EdgeRouter Lite can also be mounted in a vertical orientation. Turn this page sideways to mark the holes for vertical placement. 100 mm Ubiquiti Networks, Inc.
• Domain Name • NTP 2. Configure the interfaces on the Dashboard tab; see “Interfaces” on page 11 for more information. 3. Configure OSPF settings on the Routing > OSPF tab; see “OSPF” on page 16 for more information. Ubiquiti Networks, Inc.
Page 7
Here are the typical steps to follow: 1. Configure the appropriate settings on the System tab (see “System” on page 6 for more information): • Host Name • Time Zone • Gateway • Name Server • Domain Name • NTP Ubiquiti Networks, Inc.
The “Services Tab” on page 28 configures DHCP servers and DNS forwarding. • Users The “Users Tab” on page 32 configures user accounts with administrator or operator access. The EdgeOS Configuration Interface will appear, allowing you to customize your settings as needed. Ubiquiti Networks, Inc.
The following network administration and monitoring tools are available: • “Ping” on page 34 • “Trace” on page 35 • “Discover” on page 35 • “Packet Capture” on page 35 • “Log Monitor” on page 36 Ubiquiti Networks, Inc.
Specify the TCP/IP port of the SSH server. The default mappings in its respective DNS database. is 22. System name server Enter the IP address of your DNS server (example: 192.0.2.1 for IPv4 or 2001:db8::1 for IPv6). Click Add New to add additional servers. Ubiquiti Networks, Inc.
Page 11
RADIUS) are stored in plain text. following: • Provides an interface for device monitoring using SNMP • Communicates with SNMP management applications for network provisioning • Allows network administrators to monitor network performance and troubleshoot network problems Ubiquiti Networks, Inc.
Page 12
EdgeRouter from the power supply during the firmware update process as these actions will damage the EdgeRouter! Restart & Shutdown Router Restart Router Restart To turn the EdgeRouter off and back on again, click this option. Ubiquiti Networks, Inc.
Security > NAT tab. Go to “NAT” on page 24 for more information. Firewall The firewall status and numbers of sets and rules are displayed. Click Firewall to display the Security > Firewall Policies tab. Go to “Firewall Policies” on page 19 for more information. Ubiquiti Networks, Inc.
Click the appropriate tab to filter the of transmitted data), and RX (amount of received data). interfaces as needed. • All interfaces are displayed by default. • Ethernet All of the Ethernet interfaces are displayed. • VLAN All VLANs are displayed. Ubiquiti Networks, Inc.
Page 15
Description Enter keywords to describe this interface. • Enable Check the box to enable the interface. All of the interfaces are saved in the system configuration file; however, only the enabled interfaces are active on the device. Ubiquiti Networks, Inc.
• System > Name Server configuration Configuration Interface. (Refer to “Name Server” on page 7.) • Dashboard > VLAN configuration (Refer to “Add VLAN” on page 11.) • Dashboard > Interface configuration (Refer to “Configure the Interface” on page 12.) Ubiquiti Networks, Inc.
(such as static, RIP, or OSPF), the EdgeRouter characters. compares the routes and uses the route with the lowest distance. Enable • Check the box to enable the route. Click Save to apply your changes. Ubiquiti Networks, Inc.
(such as static, RIP, and OSPF), the EdgeRouter compares the routes and uses the route with the lowest distance. • Enable Check the box to enable the route. Click Save to apply your changes. Ubiquiti Networks, Inc.
Designated Router (DR), which distributes updates to the other OSPF routers. Click Save to apply your changes, or click Delete OSPF to remove the Router, Redistribution, and Area settings (Interfaces settings are retained). Ubiquiti Networks, Inc.
Page 20
Each router uses a key. This provides minimal security because the key is transmitted in A table displays the following information about each plain text format. OSPF Area. Click a column heading to sort by that heading. Ubiquiti Networks, Inc.
Page 21
OSPF Interface. Click a column heading to sort by that heading. Interface The name of the interface is displayed. Cost The cost of the interface is displayed. OSPF uses cost as a metric to determine the best route. Ubiquiti Networks, Inc.
2. Click the Firewall Policies tab, and then click Add Control Message Protocol) message is sent saying the Policy. Configure the basic parameters. See the destination is unreachable. Add Policy description in the next column for more information. Accept Packets are allowed through the firewall. Ubiquiti Networks, Inc.
Page 23
To configure the destination options of a • Delete Policy Remove the policy. rule, click Destination. Go to ”Destination” on page Time To configure the time options of a rule, click Time. • Go to ”Time” on page 22. Ubiquiti Networks, Inc.
Page 24
Don’t match on IPsec packets Do not match any IPsec packets. Match inbound IPsec packets Match IPsec packets that are entering the EdgeRouter. Match inbound non-IPsec packets Match non-IPsec packets that are entering the EdgeRouter. Ubiquiti Networks, Inc.
Page 25
Interpret dates and times as UTC Check the box if your network uses UTC. • Address Enter the IP address of the destination. Click Save to apply your changes, or click Cancel. • Port Enter the port number of the destination. Ubiquiti Networks, Inc.
Address All of the address groups are displayed. Packets The number of packets that triggered this rule is • Network All of the network groups are displayed. displayed. • Port All of the port groups are displayed. Ubiquiti Networks, Inc.
The name of this group is displayed. Add Source NAT Rule To create a new rule, click Add Description Enter keywords to describe this group. Source NAT Rule. Go to “Add or Configure a Source NAT Rule” on page 25. Ubiquiti Networks, Inc.
Page 28
Enter a protocol number Enter the port number of the protocol. Match packets of this protocol. • Match all protocols except for this Match packets of all protocols except for the selected protocol. Ubiquiti Networks, Inc.
Page 29
Enter keywords to describe this rule. filtered in real time as soon as you type two or more Enable • Check the box to enable this rule. characters. • Inbound Interface Select the interface through which the incoming packets enter the EdgeRouter. Ubiquiti Networks, Inc.
(example: 192.0.2.0/24). • Dest. Port Enter the port name or number of the destination. You can also enter a range of port numbers; one of them will be used. Click Save to apply your changes, or click Cancel. Ubiquiti Networks, Inc.
The Create DHCP Server screen appears. Search Allows you to search for specific text. Begin typing; there is no need to press enter. The results are filtered in real time as soon as you type two or more characters. Ubiquiti Networks, Inc.
The Enabled/Disabled status of the DHCP server is displayed. • Search Allows you to search for specific text. Begin typing; there is no need to press enter. The results are filtered in real time as soon as you type two or more characters. Ubiquiti Networks, Inc.
Page 33
At the bottom of the screen, you can click Delete to delete the DHCP server and its configuration. • Available The number of available IP addresses is displayed. • Subnet The IP address and subnet mask of the DHCP server are displayed in slash notation. Ubiquiti Networks, Inc.
The rest of the Details tab displays the following: • DHCP Name The name of the DHCP server is displayed. Subnet • The IP address and subnet mask of the DHCP server are displayed in slash notation. Ubiquiti Networks, Inc.
The number of times the user has accessed the EdgeRouter is displayed. Date Connected The date of the user’s most recent access is displayed. Uptime The duration of the user’s access is displayed. Status The status of the user is displayed. Ubiquiti Networks, Inc.
The number of packets transmitted is displayed. Click Save to apply your changes, or click Cancel. TX bytes The number of bytes transmitted is displayed. RX packets The number of packets received is displayed. RX bytes The number of bytes received is displayed. Ubiquiti Networks, Inc.
Specify the size of the packet. • Discover Run Test Click this button to start the test. • Packet Capture Packet loss statistics and latency time evaluation are • Log Monitor displayed after the test is completed. Ubiquiti Networks, Inc.
Enter the port number to filter. can click it to access the device’s configuration through its web management interface. • Negate filter Check this box to capture all packets except for the ones matching the selected filter(s). Ubiquiti Networks, Inc.
Click a column heading to sort by that heading. Time The system time is displayed next to every log entry that registers a system event. Message A description of the system event is displayed. Ubiquiti Networks, Inc.
Default User Account” on page 41. • terminal emulator Go to the following section, Access Using a Terminal Emulator. Go to “Access Using SSH” on page 38. • • Telnet Go to “Access Using Telnet” on page 38. Ubiquiti Networks, Inc.
Page 41
• Set up a new user account (preferred option). For details, go to “Remove the Default User Account” on page 41. • Change the default password of the ubnt login. Use the set command as detailed in “Remove the Default User Account” on page 41. Ubiquiti Networks, Inc.
EdgeRouter from its • Change the default password of the ubnt login. power supply, runs the risk of data corruption! Use the set command as detailed in “Remove the Default User Account” on page 41. Ubiquiti Networks, Inc.
• Assign an IP address and subnet mask --- 10.1.0.1 ping statistics --- • Enter a description 2 packets transmitted, 2 received, 0% packet loss, time 999 ms Use the set, compare, commit, and save commands. rtt min/avg/max/mdev = 0.407/0.433/0.460/0.033 ms Ubiquiti Networks, Inc.
Page 44
[edit firewall name TEST] [edit] ubnt@ubnt# set enable-default-log admin1@ubnt# show system login [edit firewall name TEST] user admin1 { ubnt@ubnt#edit rule 10 authentication { [edit firewall name TEST rule 10] encrypted-password $1$mv8ERQ1T$7xq/eUDwy/5And7nV.9r6. plaintext-password ““ [edit] admin1@ubnt# exit exit admin1@ubnt:~$ Ubiquiti Networks, Inc.
Page 45
[edit firewall name TEST] action accept ubnt@ubnt# up destination { [edit firewall] port 22 ubnt@ubnt# compare [edit firewall] protocol tcp +name TEST { default-action drop enable-default-log [edit] rule 10 { action accept description “allow icmp” protocol icmp [edit firewall] Ubiquiti Networks, Inc.
Page 46
{ invalid enable rule 20 { action drop state { rule 30 { invalid enable action accept destination { port 22 rule 30 { action accept protocol tcp destination { port 22 [edit] protocol tcp [edit] ubnt@ubnt# Ubiquiti Networks, Inc.
2012-08-17 18:31:52 by ubnt via cli commit ‘/config/config.boot-ipsec’... 2012-08-17 18:31:51 by root via init commit Load complete. Use ‘commit’ to make changes active. [edit] ubnt@RTR# commit [edit] ubnt@RTR# save; exit Saving configuration to ‘/config/config.boot’... Done exit ubnt@RTR:~$ Ubiquiti Networks, Inc.
Page 48
15:09:12 2012): [edit] ubnt@RTR# set firewall name WAN_IN rule 50 destination The system is going down for reboot NOW! address 172.16.0.0/16 [edit] ubnt@RTR# commit-confirm commit confirm will be automatically reboot in 10 minutes unless confirmed Proceed? [confirm][y] [edit] Ubiquiti Networks, Inc.
1,000,000 pps Packet Size: 512 Bytes or Larger 3 Gbps (Line Rate) LEDs Per Port Serial Console Port Power Data Ports Speed/Link/Activity Networking Interfaces Serial Console Port (1) RJ45 Serial Port Data Ports (3) 10/100/1000 Ethernet Ports Ubiquiti Networks, Inc.
Page 50
VRRP RADIUS Client Web Caching FIFO Stochastic Fairness Queueing Random Early Detection Token Bucket Filter Deficit Round Robin Hierarchical Token Bucket Ingress Policing Management Web UI CLI (Console, SSH, Telnet) SNMP NetFlow LLDP UBNT Discovery Protocol Logging Ubiquiti Networks, Inc.
Protective earthing is provided by Listed AC adapter. Building installation shall provide appropriate short-circuit backup protection. e. Protective bonding must be installed in accordance with local national wiring rules and regulations. Ubiquiti Networks, Inc.
(III) The Product has been properly installed and used at of all liabilities of UBIQUITI NETWORKS with respect to all times in accordance, and in all material respects, the quality and performance of the Products. UBIQUITI with the applicable Product documentation.
Entsorgungsdienste oder an den Händler, bei dem Sie das Produkt erworben haben. Japan VCCI-A CE Marking CE marking on this product represents the product is in compliance with all directives that are applicable to it. Ubiquiti Networks, Inc.
Page 54
Per ricevere informazioni più dettagliate circa lo smaltimento delle vecchie apparecchiature in Vostro possesso, Vi invitiamo a contattare gli enti pubblici di competenza, il servizio di smaltimento rifiuti o il negozio nel quale avete acquistato il prodotto. Ubiquiti Networks, Inc.
UBIQUITI NETWORKS device, megfelel a vonatkozó alapvetõ [Hungarian] követelményeknek és az 1999/5/EC irányelv egyéb elõírásainak. Íslenska Hér me l sir UBIQUITI NETWORKS yfir ví a UBIQUITI NETWORKS device, er í samræmi vi grunnkröfur og a rar kröfur, sem ger ar [Icelandic] eru í tilskipun 1999/5/EC.