Skip to content

🌐 Gateway, Access Points & Internet Watchdog ​

This document details the homelab edge routing, wireless access point infrastructure, integrated DNS/AdGuard Home architecture, static DHCP reservations, and the automated multi-tier self-healing internet watchdog (scripts/internet_watchdog.sh).


🏛️ Network Infrastructure Overview ​

The homelab network relies on a two-router topology:

  1. Primary Edge Gateway: GL.iNet Flint 2 (GL-MT6000) at 192.168.0.1 — handles WAN routing, NAT, firewalling, AdGuard Home DNS, authoritative DHCP, and the self-healing internet watchdog.
  2. Wired Access Point / Extender: TP-Link Archer C7 v5 at 192.168.0.2 — operates in Dumb AP mode connected via Gigabit Ethernet to extend 2.4 GHz and 5.0 GHz wireless coverage with 802.11r fast roaming.

📊 Hardware & System Specifications ​

SpecificationPrimary Gateway: Flint 2Wired Extender / AP: Archer C7 v5
Hostname / IPGL-MT6000 • 192.168.0.1OpenWrt • 192.168.0.2
ModelGL.iNet GL-MT6000 (Flint 2)TP-Link Archer C7 v5
Architecture / SoCMediaTek Filogic 830 (MT7986A Quad-Core ARMv8 @ 2.0GHz)Qualcomm Atheros QCA956X (MIPS 24Kc @ 775MHz)
Memory (RAM)1.0 GB DDR4 (~540 MB available)128 MB RAM (~50 MB available)
Storage (Flash)8 GB eMMC (7.2 GB overlay on /overlay)16 MB SPI Flash (7.6 MB overlay on /overlay)
Operating SystemOpenWrt 24.10.4 (r28959-29397011cc)OpenWrt 25.12.5 (r33051-f5dae5ece4)
Linux Kernel6.6.110 (aarch64)6.12.94 (mips)
Operational RoleGateway, DHCP Server, AdGuard DNS, NAT, WatchdogDumb AP / Layer-2 5-Port Switch, Wireless Extender
DHCP / IPv6 RAAuthoritative (Dnsmasq + odhcpd)Disabled (ignore 1, services stopped)
Firewall / NATActive (flow_offloading_hw 1)Disabled / Inactive

📶 Unified Wireless Grid & Fast Roaming (802.11k/r/v) ​

The wireless network is segmented into trusted Main LAN and isolated IoT networks across the Flint 2 gateway and Archer C7 access point. Trusted networks use 802.11k/v/r fast roaming under shared Mobility Domain 1234, while the IoT network strictly uses standard WPA2-PSK to guarantee device compatibility:

Network / SSIDBandFlint 2 (Gateway)Archer C7 v5 (Extender)Security & Roaming ProtocolNetwork / VLAN Attachment
kevin2.4 GHzChannel 11 (2462 MHz, HT20)
Interface: wlan0
NAS ID: Flint1
Channel 1 (2412 MHz, HT20)
Interface: phy1-ap0
NAS ID: Archer1
WPA2-PSK (psk2)
• 802.11k (RRM) + 802.11v (BSS-TM)
• 802.11r FT (mobility_domain 1234)
• ft_psk_generate_local '1'
Main LAN (br-lan)
192.168.0.0/24
kevin-but-better5.0 GHzChannel 36 (5180 MHz, HE80 AX)
Interface: wlan1
NAS ID: Flint1
Channel 52 (5260 MHz, VHT80 AC)
Interface: phy0-ap0
NAS ID: Archer1
WPA2-PSK (psk2)
• 802.11k (RRM) + 802.11v (BSS-TM)
• 802.11r FT (mobility_domain 1234)
• ft_psk_generate_local '1'
Main LAN (br-lan)
192.168.0.0/24
kevin-iot2.4 GHzChannel 11 (2462 MHz, HT20)
Interface: phy0-ap0 (iot_radio0)
Channel 1 (2412 MHz, HT20)
Interface: phy1-ap1 (iot_radio1)
Standard WPA2-PSK (psk2)
• 802.11r Disabled (ieee80211r '0')
• Stationary IoT compatibility mode
IoT VLAN 69 (br-iot)
192.168.69.0/24

IMPORTANT

Key Wireless Architectural Rules & Best Practices:

  1. Local FT-PSK Generation on Main LAN (ft_psk_generate_local '1'): Both Flint 2 and Archer C7 must have ft_psk_generate_local '1' enabled alongside identical mobility_domain '1234' and WPA2 preshared keys. Without this, hostapd fails to derive matching PMK-R1 keys between differing router chipsets, causing kernel key addition failed errors and connection drops when mobile devices (iPhone 16e, Apple Watch, Samsung Galaxy) attempt 802.11r fast roaming.
  2. 802.11r Disabled on kevin-iot (ieee80211r '0'): Smart TVs (Samsung Tizen OS), ESP32/ESP8266 microcontrollers, smart plugs (Meross, Tuya, SLZB-06M), and environmental sensors do not support Fast BSS Transition extensions and frequently fail initial association or drop packets when 802.11r MDIE beacons are advertised. Because all IoT devices are stationary, disabling 802.11r on kevin-iot ensures 100% connection reliability.
  3. Channel & Spectrum Independence:
    • 2.4 GHz: Channel 1 (Archer C7) vs Channel 11 (Flint 2) provides completely non-overlapping spectrum.
    • 5.0 GHz: Channel 36 (Flint 2: 5180–5240 MHz) vs Channel 52 (Archer C7: 5260–5320 MHz DFS) delivers two independent 80 MHz high-speed corridors.

🔍 Archer C7 v5 Extender Configuration Audit ​

The live configuration of the Archer C7 v5 (192.168.0.2) was verified:

  1. IP Addressing & Gateway: [PASS]
    • Static IP 192.168.0.2/24 assigned on br-lan.
    • Default route default via 192.168.0.1 dev br-lan and DNS 192.168.0.1.
  2. DHCP & IPv6 Conflict Guard: [PASS]
    • DHCPv4 disabled on LAN (option dhcpv4 'disabled', option ignore '1', option dynamicdhcp '0').
    • dnsmasq and odhcpd daemon services are disabled and stopped.
  3. Physical Switch & WAN-to-LAN Conversion: [PASS]
    • Switch VLAN 1 includes all 5 physical ports: ports: 0t 1 2 3 4 5.
    • The physical Blue WAN port (Port 1) operates as an extra 5th Gigabit LAN port on br-lan.
    • Ethernet uplink from Flint 2 connected to Switch Port 3 (1000baseT full-duplex).
  4. Firewall & Redundant Services: [PASS]
    • Firewall daemon service is disabled, eliminating redundant NAT/filtering CPU overhead.
  5. Wireless Security & Complete 802.11k/v/r Roaming: [PASS]
    • SSIDs and WPA2 keys match the primary Flint 2 gateway.
    • IEEE 802.11r Fast BSS Transition (mobility_domain '1234'), 802.11k Radio Resource Measurement (ieee80211k '1'), and 802.11v BSS Transition Management (bss_transition '1') active on both radios.
  6. On-Demand / Intermittent Power-Cycling: [PASS]
    • Pure Layer-2 bridge topology allows the Archer C7 to be powered on/off dynamically (e.g., smart plug for garden/garage usage) with zero impact on the primary network.

🛡️ DNS & AdGuard Home Architecture ​

DNS resolution on the Flint 2 combines AdGuard Home and Dnsmasq:

  1. AdGuard Home (192.168.0.1:3000 / :3053):
    • Upstream resolvers: 9.9.9.9 (Quad9), 1.1.1.1 (Cloudflare), bootstrap 9.9.9.10.
    • Config path: /etc/AdGuardHome/config.yaml.
  2. Dnsmasq (192.168.0.1:53):
    • Resolves local DHCP hosts and forwards external lookups to 127.0.0.1#3053.
  3. Anti-Leak & Redirection:
    • force_dns '1' redirects rogue client DNS lookups to the local resolver.
    • lan_drop_leak_adgdns prevents direct bypass to port 3053.

🏷️ Static DHCP Reservation & Address Map ​

Static DHCP leases defined on the primary gateway (/etc/config/dhcp):

1. Infrastructure, Hosts & Virtual Machines (Main LAN 192.168.0.0/24) ​

IP AddressHostname / DescriptionMAC AddressInterface / Role
192.168.0.1GL-MT6000 (Flint 2)94:83:C4:B1:03:24Primary Gateway & DNS
192.168.0.2Archer C7 v568:FF:7B:AB:93:06Secondary Wi-Fi AP / Extender
192.168.0.100PVE-1F0:12:04:60:FA:6Fnic1 (2.5G primary adapter)
192.168.0.101PVE-200:E0:4C:68:1C:55nic1 (2.5G primary adapter)
192.168.0.102PVE-37C:57:58:FF:50:55nic0 (1G onboard adapter)
192.168.0.103PBS84:3A:5B:90:75:C7Proxmox Backup Server
192.168.0.108ubuntu25desktop VMBC:24:11:40:BB:69VM 108 (Ubuntu Desktop)
192.168.0.110SLZB-06M dongle94:54:C5:EB:34:BBZigbee Ethernet Coordinator
192.168.0.115win11pro VMBC:24:11:47:3B:7AVM 115 (Windows 11 Pro)
192.168.0.198hildebrand_59575030:C6:F7:59:57:53Glow CAD Smart Energy Monitor
192.168.0.199homeassistant VMBC:24:11:F2:2D:52VM 199 (HAOS)

2. Core Containers & Services (Main LAN 192.168.0.0/24) ​

IP AddressHostname / TagMAC AddressDescription
192.168.0.127openwebui-lxcBC:24:11:41:CF:24LXC 127 (OpenWebUI AI interface)
192.168.0.129docker-admin LXCBC:24:11:A8:C2:DBLXC 129 (Portainer, Dockhand Admin)
192.168.0.130samba LXCBC:24:11:5F:AF:61LXC 130 (Samba / ZFS mass storage)
192.168.0.131docker-media LXCBC:24:11:30:D1:38LXC 131 (Media stack, Jellyfin, QSV)
192.168.0.132immich LXCBC:24:11:09:D9:7ELXC 132 (Immich photo server)
192.168.0.133bambuddy LXCBC:24:11:7F:F5:CFLXC 133 (3D printing manager)
192.168.0.151cloudflared-1BC:24:11:32:8F:1EPrimary Cloudflare tunnel
192.168.0.152cloudflared-2BC:24:11:EA:66:5BStandby Cloudflare tunnel
192.168.0.161pangolin-1 LXCBC:24:11:A0:31:5EPangolin tunnel node 1
192.168.0.162pangolin-2 LXCBC:24:11:65:B6:FFPangolin tunnel node 2
192.168.0.171tailscale-1 LXCBC:24:11:64:24:C7Primary Tailscale subnet router
192.168.0.172tailscale-2 LXCBC:24:11:39:80:F9Standby Tailscale subnet router
192.168.0.180ansible LXCBC:24:11:7E:E0:79LXC 180 (Automation & Semaphore)
192.168.0.181pulse LXCBC:24:11:8B:77:0FLXC 181 (Pulse monitoring)
192.168.0.182antigravity LXCBC:24:11:11:EE:82LXC 182 (AI agent workspace)
192.168.0.183docker-edge LXCBC:24:11:50:7F:DELXC 183 (Traefik, TinyAuth, Pocket-ID)
192.168.0.185edge-lxcBC:24:11:33:D3:9BStandby Edge container
192.168.0.200plex-jellyfin LXCBC:24:11:F5:3F:E9Standby streaming container
192.168.0.210EXTERNAL-plex-jellyfinBC:24:11:B2:74:DAExternal streaming container
192.168.0.222adguardhome 222 LXCBC:24:11:43:FE:22Primary containerized AdGuard Home
192.168.0.223adguardhome 223 LXCBC:24:11:77:1D:D3Secondary containerized AdGuard Home

3. Personal Mobile, Laptops & Gaming (Main LAN 192.168.0.0/24) ​

IP AddressHostname / DescriptionMAC AddressInterface / Band
192.168.0.64Samsung Galaxy watch 6D6:D0:D4:3A:61:4CWi-Fi 2.4G (kevin)
192.168.0.65Margi Samsung S26 static74:F4:41:C7:95:D5Wi-Fi 5G (kevin-but-better)
192.168.0.66XBOX series XA8:8C:3E:7F:CC:63Ethernet / Wi-Fi
192.168.0.67apple watch s998:FE:E1:13:AD:DDWi-Fi 2.4G (kevin)
192.168.0.68Macbook M4 pro84:2F:57:42:73:0BWi-Fi 5G (kevin-but-better)
192.168.0.70iPhone 16e78:5E:CC:F0:25:F0Wi-Fi 5G (kevin-but-better)
192.168.0.71HP elitebook laptopE0:D4:64:C9:53:3DWi-Fi 5G (kevin-but-better)

4. Smart Home, Appliances & Sensors (IoT VLAN 69 192.168.69.0/24) ​

IP AddressHostname / TagMAC AddressCategory / Device
192.168.69.10Amazon echo dot alexa Office58:A8:E8:6D:48:BBVoice Assistant
192.168.69.11Amazon echo dot alexa Bedroom68:B6:91:56:DD:80Voice Assistant
192.168.69.12Amazon echo dot alexa Kitchen00:F3:61:94:EB:74Voice Assistant
192.168.69.13Amazon echo plus Alexa50:DC:E7:63:11:CEVoice Assistant / Zigbee Hub
192.168.69.20Amazon ring doorbell cam64:9A:63:99:D0:0CDoorbell Camera
192.168.69.21Amazon ring cam wireless garden90:48:6C:DE:C3:B0Security Camera
192.168.69.22Amazon ring stick up cam90:48:6C:DE:05:CESecurity Camera
192.168.69.23Amazon ring cam wired usb garageAC:9F:C3:DB:54:6BSecurity Camera
192.168.69.30amoled-dashboardD0:CF:13:32:BA:C0Wall Display Dashboard
192.168.69.31esp32-s3-board-01CC:BA:97:24:26:04ESP32-S3 Microcontroller
192.168.69.32esp32-s3-board-021C:DB:D4:AD:DD:E4ESP32-S3 Microcontroller
192.168.69.33esp32-s3-board-031C:DB:D4:AE:B0:68ESP32-S3 Microcontroller
192.168.69.34esp32-s3-board-041C:DB:D4:AE:7B:84ESP32-S3 Microcontroller
192.168.69.35esp32-s3-board-05-ant10:B4:1D:CE:B6:7CESP32-S3 Microcontroller
192.168.69.36esp32-s3-board-06-ant44:1B:F6:8D:62:5CESP32-S3 Microcontroller
192.168.69.41irk-capture3C:0F:02:E0:9A:E4BLE IRK Capture Node
192.168.69.42esp32-bed-presence5C:01:3B:66:EC:B8Bed Presence Sensor
192.168.69.43esp32-camC0:CD:D6:CF:B0:B4Security Camera
192.168.69.51Power PDU1 Meross - behind sofa48:E1:E9:A5:55:80Smart PDU
192.168.69.52power PDU2 bedroom margi sideD8:BF:C0:D9:58:D1Smart PDU
192.168.69.53Power PDU3 P304 under TV8C:90:2D:93:91:67Smart PDU
192.168.69.54power PDU4 P304 by bed ray side3C:78:95:D6:6C:59Smart PDU
192.168.69.55power PDU5 P304 washing machine3C:78:95:D6:6E:F6Smart PDU
192.168.69.61Power plug wifi 1 - SLZB-06M28:87:BA:37:7E:DASmart Plug
192.168.69.62Power plug wifi 2 - Unmanaged sw28:87:BA:37:86:7BSmart Plug
192.168.69.63power plug mss315 - Tumble dryer48:E1:E9:DC:A7:EASmart Plug
192.168.69.64power supply eWeLinkCC:50:E3:1B:5B:B9Smart Power Supply
192.168.69.71light sofa lamp bulb20:F1:B2:E1:21:BDSmart Lighting
192.168.69.72light ambient Meross48:E1:E9:E3:5D:C3Smart Lighting
192.168.69.73light TV-LED GoveeD4:AD:FC:A1:C7:D3Smart Lighting
192.168.69.81Temperature sensor - garage1C:90:FF:F2:3E:E3Environmental Sensor
192.168.69.82Temperature sensor probe kitchen3C:0B:59:CE:F4:D5Environmental Sensor
192.168.69.83Temperature sensor inside HP PC50:8B:B9:27:0C:50Environmental Sensor
192.168.69.84Temperature sensor - 3d printer50:8B:B9:27:A0:02Environmental Sensor
192.168.69.85Temperature sensor garden50:8B:B9:26:89:E6Environmental Sensor
192.168.69.91lidlomixD4:82:FF:D8:2A:5BKitchen Appliance
192.168.69.92Pienislaw robovac eufy78:22:88:77:1F:93Robot Vacuum
192.168.69.933D printer Bambu Lab A1AC:A7:04:16:05:2C3D Printer
192.168.69.94TV 42 Bedroom64:E7:D8:70:69:0ESmart TV (IoT VLAN)
192.168.69.95TV 65 Living Room00:7C:2D:C2:D9:5BSmart TV (IoT VLAN)
192.168.69.96amazon firestick bedroom90:39:5F:22:E3:18Media Player (IoT VLAN)

⏰ Cron Jobs & Active Automations (Flint 2) ​

The primary gateway crontab (crontab -l) maintains two core automated tasks:

text
# 1. Healthchecks.io Gateway Heartbeat (Every 2 minutes)
*/2 * * * * curl -fsS -m 10 --retry 5 -o /dev/null https://hc-ping.com/f5cdb39a-83b8-403b-8622-3dda510e5754

# 2. Multi-Tier Internet Self-Healing Watchdog (Every 5 minutes)
*/5 * * * * /usr/bin/internet_watchdog.sh

🛠️ Multi-Tier Self-Healing Watchdog Architecture ​

The watchdog script (scripts/internet_watchdog.sh) continuously validates actual external connectivity, handles progressive recovery tiers, persists outage history across reboots, and sends Telegram alerts upon restoration.

Watchdog Capabilities: ​

  1. Direct Public DNS Query: Executes nslookup google.com 1.1.1.1 bypassing local AdGuard Home/dnsmasq cache.
  2. Tier 1 (15 min / 3 fails): Drops physical eth1 link to trigger ONT port state reset and requests a clean DHCP lease.
  3. Tier 2 (30 min / 6 fails): Clean software reboot (reboot).
  4. Outage Tracking: Persists start time in /etc/internet_outage_active across reboots and maintains history in /etc/internet_outages.log.
  5. New Device Discovery Alerts: Tracks all connected devices across ARP, DHCP leases, and GL client registries; sends instant Telegram notifications with MAC, IP, Hostname, and network interface whenever a new device connects.
  6. VLAN Cross-Migration Guard: Immediately detects and alerts on unexpected movements between Main LAN (192.168.0.0/24) and IoT VLAN 69 (192.168.69.0/24).
  7. Telegram Alerts: Dispatches HTML formatted alerts with downtime duration, recovery action, WAN IP, port negotiation changes, new device connections, and VLAN shifts.

🔧 Operational & Diagnostic Commands ​

1. Flint 2 Gateway (ssh router or ssh root@192.168.0.1): ​

bash
# Check system status, board info, and memory
ubus call system board
uptime
free -m
df -h /overlay

# View network interfaces & routing
ip -br addr
ip route
cat /etc/config/network

# View Wi-Fi radio status & associated clients
iwinfo wlan0 info
iwinfo wlan1 info

# Run manual interactive test of the watchdog script
/usr/bin/internet_watchdog.sh

2. Archer C7 v5 Extender (ssh ap or ssh root@192.168.0.2): ​

bash
# Check system board, memory, and switch status
ubus call system board
free -m
swconfig dev switch0 show

# Check wireless interface association lists
iwinfo phy0-ap0 info
iwinfo phy1-ap0 info
iwinfo phy0-ap0 assoclist
iwinfo phy1-ap0 assoclist

# Confirm DHCP and firewall remain inactive
/etc/init.d/dnsmasq status
/etc/init.d/odhcpd status
/etc/init.d/firewall status

🔒 Deployed IoT VLAN 69 Architecture (192.168.69.0/24) ​

Smart home devices (cameras, smart plugs, Alexa, robot vacuums) are isolated on a dedicated Layer-2 bridge and subnet (br-iot • 192.168.69.1/24) while retaining full Home Assistant control:

Firewall & Communication Matrix: ​

  1. Unicast Control: Home Assistant (192.168.0.199) and admin workstations can initiate connections to any device on 192.168.69.x.
  2. Local Push / MQTT: Pinhole rule permits IoT devices to communicate with Home Assistant on TCP 80 (Home Assistant Webhooks/API/HTTP) and TCP 1883 / 1884 (Mosquitto MQTT).
  3. Multicast Discovery: Avahi daemon with enable-reflector=yes repeats mDNS packets across 192.168.0.0/24 and 192.168.69.0/24.
  4. Isolated Default: IoT devices cannot probe, scan, or establish connections to Proxmox nodes (192.168.0.100-103), PBS, NAS storage, or personal workstations.

💾 Router Configuration Backups ​

Full pre-VLAN system backups and raw /etc/config/ snapshots are archived under admin/network/backups/:


Authoritative operational repository and DR hub.