Reply
New Member
Posts: 5
Registered: ‎05-25-2018

Suspension Feature can't get working been trying for too long about to give up on this

Hi Guys,

 

I would like to know where i am going wrong with the configuration for the suspension, i have read the articles carefully and when over and over looking at the configurations on the UCRM  and on my ER-X Router, please assist with this issue please need to get this suspension feature working.

I am willing to pay for remote assistance in getting to feature working please reach out to me here at this email islandwifitci@gmail.com

 

Thanks

 

Island Wifi

Established Member
Posts: 1,630
Registered: ‎03-23-2013
Kudos: 235
Solutions: 54

Re: Suspension Feature can't get working been trying for too long about to give up on this

We're going to need to see the config to help you with it.  Unless your just asking for remote assistance only here.

 

Which part is failing?

 

Do the firewall rules work if you manually add an IP address to the group?

 

Is UCRM not syncing to the ERX?

 

New Member
Posts: 5
Registered: ‎05-25-2018

Re: Suspension Feature can't get working been trying for too long about to give up on this

MY NETWORK TOPOLOGY

 

Island Screen shoot for cummunity UCRM suspension diagram entire.PNG

 

 

 

 

 

 

Hi,

 

Thanks for reply to this post, i will copy setttings and show below, the firewall rules are not working because if i manually add the ip address to the BLOCKED_USERS group i am still able to get access to the internet with ip address 192.168.30.3/24 whcih is the customer ip address i have manually add this to the BLOCKED_USERS, when i check the UCRM Logs it shows the ER-X Device synrocnize and Suspension sync and

 

The customer is suspended see screen shoot below:

Island Screen shoot for cummunity UCRM showing Customer Suspended.PNG

 

 

 

 

This screen shoot shows the firewall BLOCKED_USERS group high lighted is the IP Address i manually added in which is the customer ip address:

Island Screen shoot for cummunity ER-X Firewall Group.PNG

 

 

 

This screen show is for UCRM Logs :

Island Screen shoot for cummunity UCRM Logs for Device.PNG

 

This screen shoot is showing the Devices & Sites in UCRM which is 1 ER-X Router a ES-8 150W siwtch is connected to the router which than feed into the LBE 5AC PMPT AP which than bridges to the customer LBE 5AC. i did not added the ES-8 switch top the Device becuase the article mention that the suspension should only be enable on the gateway router which is the ER-X:

Island Screen shoot for cummunity UCRM Logs for Network ER-X.PNG

 

 

Logs from the ER-X :

Island Screen shoot for cummunity UCRM Logs for Device 2.PNG

 

ER-X Interface Screen Shoot :

Island Screen shoot for cummunity UCRM Logs for Device 3.PNG

 

 

Firewall NAT Rules note tha i re arrange so the UCRM Rules gets first priority:

Island Screen shoot for cummunity ER-X Firewall Group 2.PNG

 

 

Not really sure where i when wrong with the configuration, my email address islandwifitci@gmail.com if you are willing to assist remotely for a paypal fee.

 

Thanks again

 

Island Wifi

 

Established Member
Posts: 1,630
Registered: ‎03-23-2013
Kudos: 235
Solutions: 54

Re: Suspension Feature can't get working been trying for too long about to give up on this

Your firewall rules are not set up correctly.  You added the ucrm_* rules to your WAN_IN ruleset which is only applied to the eth0 interface.

 

  1. Delete all the ucrm_* rules in WAN_IN
  2. Create a new ruleset named ucrm_blocked_users_eth5
  3. Create new rules on that ruleset like you did on the WAN_IN ruleset
  4. Make sure you add each VLAN to that ruleset that you want to block users on

Here is an example from our system

 

suspend rules.png

 

And here is the interfaces tab of that ruleset

 

add vlans.png

New Member
Posts: 5
Registered: ‎05-25-2018

Re: Suspension Feature can't get working been trying for too long about to give up on this

Hi ,

 

Thanks for the reply, have a question in reference to the intefrace, on the ER-X Eth5 is the trk port for Vlan switch0, switch0.20,switch0.30 & switch0.40.

 

When selecting interfaces should i use eth5 or switch0.20 which is the vlan for the customers that i am trying to block ?

 

Thanks

 

Reggie

Established Member
Posts: 1,630
Registered: ‎03-23-2013
Kudos: 235
Solutions: 54

Re: Suspension Feature can't get working been trying for too long about to give up on this

You need to use the interface, not the port number.  So switch0.X

Established Member
Posts: 1,630
Registered: ‎03-23-2013
Kudos: 235
Solutions: 54

Re: Suspension Feature can't get working been trying for too long about to give up on this

Yeah, I missed that when I was looking over your setup.  If an ethernet port is part of the switch interface your firewall rules etc need to be applied to the switch since it is the interface, not the physical port the traffic comes in.

Reply