Appearance
🌐 Gateway, Access Points & Internet Watchdog
This document details the homelab edge routing, wireless access point infrastructure, integrated DNS/AdGuard Home architecture, static DHCP reservations, and the automated multi-tier self-healing internet watchdog (scripts/internet_watchdog.sh).
🏛️ Network Infrastructure Overview
The homelab network relies on a two-router topology:
- Primary Edge Gateway: GL.iNet Flint 2 (GL-MT6000) at
192.168.0.1— handles WAN routing, NAT, firewalling, AdGuard Home DNS, authoritative DHCP, and the self-healing internet watchdog. - Wired Access Point / Extender: TP-Link Archer C7 v5 at
192.168.0.2— operates in Dumb AP mode connected via Gigabit Ethernet to extend 2.4 GHz and 5.0 GHz wireless coverage with 802.11r fast roaming.
📊 Hardware & System Specifications
| Specification | Primary Gateway: Flint 2 | Wired Extender / AP: Archer C7 v5 |
|---|---|---|
| Hostname / IP | GL-MT6000 • 192.168.0.1 | OpenWrt • 192.168.0.2 |
| Model | GL.iNet GL-MT6000 (Flint 2) | TP-Link Archer C7 v5 |
| Architecture / SoC | MediaTek Filogic 830 (MT7986A Quad-Core ARMv8 @ 2.0GHz) | Qualcomm Atheros QCA956X (MIPS 24Kc @ 775MHz) |
| Memory (RAM) | 1.0 GB DDR4 (~540 MB available) | 128 MB RAM (~50 MB available) |
| Storage (Flash) | 8 GB eMMC (7.2 GB overlay on /overlay) | 16 MB SPI Flash (7.6 MB overlay on /overlay) |
| Operating System | OpenWrt 24.10.4 (r28959-29397011cc) | OpenWrt 25.12.5 (r33051-f5dae5ece4) |
| Linux Kernel | 6.6.110 (aarch64) | 6.12.94 (mips) |
| Operational Role | Gateway, DHCP Server, AdGuard DNS, NAT, Watchdog | Dumb AP / Layer-2 5-Port Switch, Wireless Extender |
| DHCP / IPv6 RA | Authoritative (Dnsmasq + odhcpd) | Disabled (ignore 1, services stopped) |
| Firewall / NAT | Active (flow_offloading_hw 1) | Disabled / Inactive |
📶 Unified Wireless Grid & Fast Roaming (802.11k/r/v)
The wireless network is segmented into trusted Main LAN and isolated IoT networks across the Flint 2 gateway and Archer C7 access point. Trusted networks use 802.11k/v/r fast roaming under shared Mobility Domain 1234, while the IoT network strictly uses standard WPA2-PSK to guarantee device compatibility:
| Network / SSID | Band | Flint 2 (Gateway) | Archer C7 v5 (Extender) | Security & Roaming Protocol | Network / VLAN Attachment |
|---|---|---|---|---|---|
kevin | 2.4 GHz | Channel 11 (2462 MHz, HT20) Interface: wlan0NAS ID: Flint1 | Channel 1 (2412 MHz, HT20) Interface: phy1-ap0NAS ID: Archer1 | WPA2-PSK (psk2)• 802.11k (RRM) + 802.11v (BSS-TM) • 802.11r FT ( mobility_domain 1234)• ft_psk_generate_local '1' | Main LAN (br-lan)192.168.0.0/24 |
kevin-but-better | 5.0 GHz | Channel 36 (5180 MHz, HE80 AX) Interface: wlan1NAS ID: Flint1 | Channel 52 (5260 MHz, VHT80 AC) Interface: phy0-ap0NAS ID: Archer1 | WPA2-PSK (psk2)• 802.11k (RRM) + 802.11v (BSS-TM) • 802.11r FT ( mobility_domain 1234)• ft_psk_generate_local '1' | Main LAN (br-lan)192.168.0.0/24 |
kevin-iot | 2.4 GHz | Channel 11 (2462 MHz, HT20) Interface: phy0-ap0 (iot_radio0) | Channel 1 (2412 MHz, HT20) Interface: phy1-ap1 (iot_radio1) | Standard WPA2-PSK (psk2)• 802.11r Disabled ( ieee80211r '0')• Stationary IoT compatibility mode | IoT VLAN 69 (br-iot)192.168.69.0/24 |
IMPORTANT
Key Wireless Architectural Rules & Best Practices:
- Local FT-PSK Generation on Main LAN (
ft_psk_generate_local '1'): Both Flint 2 and Archer C7 must haveft_psk_generate_local '1'enabled alongside identicalmobility_domain '1234'and WPA2 preshared keys. Without this, hostapd fails to derive matching PMK-R1 keys between differing router chipsets, causing kernelkey addition failederrors and connection drops when mobile devices (iPhone 16e, Apple Watch, Samsung Galaxy) attempt 802.11r fast roaming. - 802.11r Disabled on
kevin-iot(ieee80211r '0'): Smart TVs (Samsung Tizen OS), ESP32/ESP8266 microcontrollers, smart plugs (Meross, Tuya, SLZB-06M), and environmental sensors do not support Fast BSS Transition extensions and frequently fail initial association or drop packets when 802.11r MDIE beacons are advertised. Because all IoT devices are stationary, disabling 802.11r onkevin-iotensures 100% connection reliability. - Channel & Spectrum Independence:
- 2.4 GHz: Channel 1 (Archer C7) vs Channel 11 (Flint 2) provides completely non-overlapping spectrum.
- 5.0 GHz: Channel 36 (Flint 2: 5180–5240 MHz) vs Channel 52 (Archer C7: 5260–5320 MHz DFS) delivers two independent 80 MHz high-speed corridors.
🔍 Archer C7 v5 Extender Configuration Audit
The live configuration of the Archer C7 v5 (192.168.0.2) was verified:
- IP Addressing & Gateway: [PASS]
- Static IP
192.168.0.2/24assigned onbr-lan. - Default route
default via 192.168.0.1 dev br-lanand DNS192.168.0.1.
- Static IP
- DHCP & IPv6 Conflict Guard: [PASS]
- DHCPv4 disabled on LAN (
option dhcpv4 'disabled',option ignore '1',option dynamicdhcp '0'). dnsmasqandodhcpddaemon services are disabled and stopped.
- DHCPv4 disabled on LAN (
- Physical Switch & WAN-to-LAN Conversion: [PASS]
- Switch VLAN 1 includes all 5 physical ports:
ports: 0t 1 2 3 4 5. - The physical Blue WAN port (Port 1) operates as an extra 5th Gigabit LAN port on
br-lan. - Ethernet uplink from Flint 2 connected to Switch Port 3 (
1000baseT full-duplex).
- Switch VLAN 1 includes all 5 physical ports:
- Firewall & Redundant Services: [PASS]
- Firewall daemon service is disabled, eliminating redundant NAT/filtering CPU overhead.
- Wireless Security & Complete 802.11k/v/r Roaming: [PASS]
- SSIDs and WPA2 keys match the primary Flint 2 gateway.
- IEEE 802.11r Fast BSS Transition (
mobility_domain '1234'), 802.11k Radio Resource Measurement (ieee80211k '1'), and 802.11v BSS Transition Management (bss_transition '1') active on both radios.
- On-Demand / Intermittent Power-Cycling: [PASS]
- Pure Layer-2 bridge topology allows the Archer C7 to be powered on/off dynamically (e.g., smart plug for garden/garage usage) with zero impact on the primary network.
🛡️ DNS & AdGuard Home Architecture
DNS resolution on the Flint 2 combines AdGuard Home and Dnsmasq:
- AdGuard Home (
192.168.0.1:3000/:3053):- Upstream resolvers:
9.9.9.9(Quad9),1.1.1.1(Cloudflare), bootstrap9.9.9.10. - Config path:
/etc/AdGuardHome/config.yaml.
- Upstream resolvers:
- Dnsmasq (
192.168.0.1:53):- Resolves local DHCP hosts and forwards external lookups to
127.0.0.1#3053.
- Resolves local DHCP hosts and forwards external lookups to
- Anti-Leak & Redirection:
force_dns '1'redirects rogue client DNS lookups to the local resolver.lan_drop_leak_adgdnsprevents direct bypass to port 3053.
🏷️ Static DHCP Reservation & Address Map
Static DHCP leases defined on the primary gateway (/etc/config/dhcp):
1. Infrastructure, Hosts & Virtual Machines (Main LAN 192.168.0.0/24)
| IP Address | Hostname / Description | MAC Address | Interface / Role |
|---|---|---|---|
192.168.0.1 | GL-MT6000 (Flint 2) | 94:83:C4:B1:03:24 | Primary Gateway & DNS |
192.168.0.2 | Archer C7 v5 | 68:FF:7B:AB:93:06 | Secondary Wi-Fi AP / Extender |
192.168.0.100 | PVE-1 | F0:12:04:60:FA:6F | nic1 (2.5G primary adapter) |
192.168.0.101 | PVE-2 | 00:E0:4C:68:1C:55 | nic1 (2.5G primary adapter) |
192.168.0.102 | PVE-3 | 7C:57:58:FF:50:55 | nic0 (1G onboard adapter) |
192.168.0.103 | PBS | 84:3A:5B:90:75:C7 | Proxmox Backup Server |
192.168.0.108 | ubuntu25desktop VM | BC:24:11:40:BB:69 | VM 108 (Ubuntu Desktop) |
192.168.0.110 | SLZB-06M dongle | 94:54:C5:EB:34:BB | Zigbee Ethernet Coordinator |
192.168.0.115 | win11pro VM | BC:24:11:47:3B:7A | VM 115 (Windows 11 Pro) |
192.168.0.198 | hildebrand_595750 | 30:C6:F7:59:57:53 | Glow CAD Smart Energy Monitor |
192.168.0.199 | homeassistant VM | BC:24:11:F2:2D:52 | VM 199 (HAOS) |
2. Core Containers & Services (Main LAN 192.168.0.0/24)
| IP Address | Hostname / Tag | MAC Address | Description |
|---|---|---|---|
192.168.0.127 | openwebui-lxc | BC:24:11:41:CF:24 | LXC 127 (OpenWebUI AI interface) |
192.168.0.129 | docker-admin LXC | BC:24:11:A8:C2:DB | LXC 129 (Portainer, Dockhand Admin) |
192.168.0.130 | samba LXC | BC:24:11:5F:AF:61 | LXC 130 (Samba / ZFS mass storage) |
192.168.0.131 | docker-media LXC | BC:24:11:30:D1:38 | LXC 131 (Media stack, Jellyfin, QSV) |
192.168.0.132 | immich LXC | BC:24:11:09:D9:7E | LXC 132 (Immich photo server) |
192.168.0.133 | bambuddy LXC | BC:24:11:7F:F5:CF | LXC 133 (3D printing manager) |
192.168.0.151 | cloudflared-1 | BC:24:11:32:8F:1E | Primary Cloudflare tunnel |
192.168.0.152 | cloudflared-2 | BC:24:11:EA:66:5B | Standby Cloudflare tunnel |
192.168.0.161 | pangolin-1 LXC | BC:24:11:A0:31:5E | Pangolin tunnel node 1 |
192.168.0.162 | pangolin-2 LXC | BC:24:11:65:B6:FF | Pangolin tunnel node 2 |
192.168.0.171 | tailscale-1 LXC | BC:24:11:64:24:C7 | Primary Tailscale subnet router |
192.168.0.172 | tailscale-2 LXC | BC:24:11:39:80:F9 | Standby Tailscale subnet router |
192.168.0.180 | ansible LXC | BC:24:11:7E:E0:79 | LXC 180 (Automation & Semaphore) |
192.168.0.181 | pulse LXC | BC:24:11:8B:77:0F | LXC 181 (Pulse monitoring) |
192.168.0.182 | antigravity LXC | BC:24:11:11:EE:82 | LXC 182 (AI agent workspace) |
192.168.0.183 | docker-edge LXC | BC:24:11:50:7F:DE | LXC 183 (Traefik, TinyAuth, Pocket-ID) |
192.168.0.185 | edge-lxc | BC:24:11:33:D3:9B | Standby Edge container |
192.168.0.200 | plex-jellyfin LXC | BC:24:11:F5:3F:E9 | Standby streaming container |
192.168.0.210 | EXTERNAL-plex-jellyfin | BC:24:11:B2:74:DA | External streaming container |
192.168.0.222 | adguardhome 222 LXC | BC:24:11:43:FE:22 | Primary containerized AdGuard Home |
192.168.0.223 | adguardhome 223 LXC | BC:24:11:77:1D:D3 | Secondary containerized AdGuard Home |
3. Personal Mobile, Laptops & Gaming (Main LAN 192.168.0.0/24)
| IP Address | Hostname / Description | MAC Address | Interface / Band |
|---|---|---|---|
192.168.0.64 | Samsung Galaxy watch 6 | D6:D0:D4:3A:61:4C | Wi-Fi 2.4G (kevin) |
192.168.0.65 | Margi Samsung S26 static | 74:F4:41:C7:95:D5 | Wi-Fi 5G (kevin-but-better) |
192.168.0.66 | XBOX series X | A8:8C:3E:7F:CC:63 | Ethernet / Wi-Fi |
192.168.0.67 | apple watch s9 | 98:FE:E1:13:AD:DD | Wi-Fi 2.4G (kevin) |
192.168.0.68 | Macbook M4 pro | 84:2F:57:42:73:0B | Wi-Fi 5G (kevin-but-better) |
192.168.0.70 | iPhone 16e | 78:5E:CC:F0:25:F0 | Wi-Fi 5G (kevin-but-better) |
192.168.0.71 | HP elitebook laptop | E0:D4:64:C9:53:3D | Wi-Fi 5G (kevin-but-better) |
4. Smart Home, Appliances & Sensors (IoT VLAN 69 192.168.69.0/24)
| IP Address | Hostname / Tag | MAC Address | Category / Device |
|---|---|---|---|
192.168.69.10 | Amazon echo dot alexa Office | 58:A8:E8:6D:48:BB | Voice Assistant |
192.168.69.11 | Amazon echo dot alexa Bedroom | 68:B6:91:56:DD:80 | Voice Assistant |
192.168.69.12 | Amazon echo dot alexa Kitchen | 00:F3:61:94:EB:74 | Voice Assistant |
192.168.69.13 | Amazon echo plus Alexa | 50:DC:E7:63:11:CE | Voice Assistant / Zigbee Hub |
192.168.69.20 | Amazon ring doorbell cam | 64:9A:63:99:D0:0C | Doorbell Camera |
192.168.69.21 | Amazon ring cam wireless garden | 90:48:6C:DE:C3:B0 | Security Camera |
192.168.69.22 | Amazon ring stick up cam | 90:48:6C:DE:05:CE | Security Camera |
192.168.69.23 | Amazon ring cam wired usb garage | AC:9F:C3:DB:54:6B | Security Camera |
192.168.69.30 | amoled-dashboard | D0:CF:13:32:BA:C0 | Wall Display Dashboard |
192.168.69.31 | esp32-s3-board-01 | CC:BA:97:24:26:04 | ESP32-S3 Microcontroller |
192.168.69.32 | esp32-s3-board-02 | 1C:DB:D4:AD:DD:E4 | ESP32-S3 Microcontroller |
192.168.69.33 | esp32-s3-board-03 | 1C:DB:D4:AE:B0:68 | ESP32-S3 Microcontroller |
192.168.69.34 | esp32-s3-board-04 | 1C:DB:D4:AE:7B:84 | ESP32-S3 Microcontroller |
192.168.69.35 | esp32-s3-board-05-ant | 10:B4:1D:CE:B6:7C | ESP32-S3 Microcontroller |
192.168.69.36 | esp32-s3-board-06-ant | 44:1B:F6:8D:62:5C | ESP32-S3 Microcontroller |
192.168.69.41 | irk-capture | 3C:0F:02:E0:9A:E4 | BLE IRK Capture Node |
192.168.69.42 | esp32-bed-presence | 5C:01:3B:66:EC:B8 | Bed Presence Sensor |
192.168.69.43 | esp32-cam | C0:CD:D6:CF:B0:B4 | Security Camera |
192.168.69.51 | Power PDU1 Meross - behind sofa | 48:E1:E9:A5:55:80 | Smart PDU |
192.168.69.52 | power PDU2 bedroom margi side | D8:BF:C0:D9:58:D1 | Smart PDU |
192.168.69.53 | Power PDU3 P304 under TV | 8C:90:2D:93:91:67 | Smart PDU |
192.168.69.54 | power PDU4 P304 by bed ray side | 3C:78:95:D6:6C:59 | Smart PDU |
192.168.69.55 | power PDU5 P304 washing machine | 3C:78:95:D6:6E:F6 | Smart PDU |
192.168.69.61 | Power plug wifi 1 - SLZB-06M | 28:87:BA:37:7E:DA | Smart Plug |
192.168.69.62 | Power plug wifi 2 - Unmanaged sw | 28:87:BA:37:86:7B | Smart Plug |
192.168.69.63 | power plug mss315 - Tumble dryer | 48:E1:E9:DC:A7:EA | Smart Plug |
192.168.69.64 | power supply eWeLink | CC:50:E3:1B:5B:B9 | Smart Power Supply |
192.168.69.71 | light sofa lamp bulb | 20:F1:B2:E1:21:BD | Smart Lighting |
192.168.69.72 | light ambient Meross | 48:E1:E9:E3:5D:C3 | Smart Lighting |
192.168.69.73 | light TV-LED Govee | D4:AD:FC:A1:C7:D3 | Smart Lighting |
192.168.69.81 | Temperature sensor - garage | 1C:90:FF:F2:3E:E3 | Environmental Sensor |
192.168.69.82 | Temperature sensor probe kitchen | 3C:0B:59:CE:F4:D5 | Environmental Sensor |
192.168.69.83 | Temperature sensor inside HP PC | 50:8B:B9:27:0C:50 | Environmental Sensor |
192.168.69.84 | Temperature sensor - 3d printer | 50:8B:B9:27:A0:02 | Environmental Sensor |
192.168.69.85 | Temperature sensor garden | 50:8B:B9:26:89:E6 | Environmental Sensor |
192.168.69.91 | lidlomix | D4:82:FF:D8:2A:5B | Kitchen Appliance |
192.168.69.92 | Pienislaw robovac eufy | 78:22:88:77:1F:93 | Robot Vacuum |
192.168.69.93 | 3D printer Bambu Lab A1 | AC:A7:04:16:05:2C | 3D Printer |
192.168.69.94 | TV 42 Bedroom | 64:E7:D8:70:69:0E | Smart TV (IoT VLAN) |
192.168.69.95 | TV 65 Living Room | 00:7C:2D:C2:D9:5B | Smart TV (IoT VLAN) |
192.168.69.96 | amazon firestick bedroom | 90:39:5F:22:E3:18 | Media Player (IoT VLAN) |
⏰ Cron Jobs & Active Automations (Flint 2)
The primary gateway crontab (crontab -l) maintains two core automated tasks:
text
# 1. Healthchecks.io Gateway Heartbeat (Every 2 minutes)
*/2 * * * * curl -fsS -m 10 --retry 5 -o /dev/null https://hc-ping.com/f5cdb39a-83b8-403b-8622-3dda510e5754
# 2. Multi-Tier Internet Self-Healing Watchdog (Every 5 minutes)
*/5 * * * * /usr/bin/internet_watchdog.sh🛠️ Multi-Tier Self-Healing Watchdog Architecture
The watchdog script (scripts/internet_watchdog.sh) continuously validates actual external connectivity, handles progressive recovery tiers, persists outage history across reboots, and sends Telegram alerts upon restoration.
Watchdog Capabilities:
- Direct Public DNS Query: Executes
nslookup google.com 1.1.1.1bypassing local AdGuard Home/dnsmasq cache. - Tier 1 (15 min / 3 fails): Drops physical
eth1link to trigger ONT port state reset and requests a clean DHCP lease. - Tier 2 (30 min / 6 fails): Clean software reboot (
reboot). - Outage Tracking: Persists start time in
/etc/internet_outage_activeacross reboots and maintains history in/etc/internet_outages.log. - New Device Discovery Alerts: Tracks all connected devices across ARP, DHCP leases, and GL client registries; sends instant Telegram notifications with MAC, IP, Hostname, and network interface whenever a new device connects.
- VLAN Cross-Migration Guard: Immediately detects and alerts on unexpected movements between Main LAN (
192.168.0.0/24) and IoT VLAN 69 (192.168.69.0/24). - Telegram Alerts: Dispatches HTML formatted alerts with downtime duration, recovery action, WAN IP, port negotiation changes, new device connections, and VLAN shifts.
🔧 Operational & Diagnostic Commands
1. Flint 2 Gateway (ssh router or ssh root@192.168.0.1):
bash
# Check system status, board info, and memory
ubus call system board
uptime
free -m
df -h /overlay
# View network interfaces & routing
ip -br addr
ip route
cat /etc/config/network
# View Wi-Fi radio status & associated clients
iwinfo wlan0 info
iwinfo wlan1 info
# Run manual interactive test of the watchdog script
/usr/bin/internet_watchdog.sh2. Archer C7 v5 Extender (ssh ap or ssh root@192.168.0.2):
bash
# Check system board, memory, and switch status
ubus call system board
free -m
swconfig dev switch0 show
# Check wireless interface association lists
iwinfo phy0-ap0 info
iwinfo phy1-ap0 info
iwinfo phy0-ap0 assoclist
iwinfo phy1-ap0 assoclist
# Confirm DHCP and firewall remain inactive
/etc/init.d/dnsmasq status
/etc/init.d/odhcpd status
/etc/init.d/firewall status🔒 Deployed IoT VLAN 69 Architecture (192.168.69.0/24)
Smart home devices (cameras, smart plugs, Alexa, robot vacuums) are isolated on a dedicated Layer-2 bridge and subnet (br-iot • 192.168.69.1/24) while retaining full Home Assistant control:
Firewall & Communication Matrix:
- Unicast Control: Home Assistant (
192.168.0.199) and admin workstations can initiate connections to any device on192.168.69.x. - Local Push / MQTT: Pinhole rule permits IoT devices to communicate with Home Assistant on TCP 80 (Home Assistant Webhooks/API/HTTP) and TCP 1883 / 1884 (Mosquitto MQTT).
- Multicast Discovery: Avahi daemon with
enable-reflector=yesrepeats mDNS packets across192.168.0.0/24and192.168.69.0/24. - Isolated Default: IoT devices cannot probe, scan, or establish connections to Proxmox nodes (
192.168.0.100-103), PBS, NAS storage, or personal workstations.
💾 Router Configuration Backups
Full pre-VLAN system backups and raw /etc/config/ snapshots are archived under admin/network/backups/:
- Flint 2 (Primary Gateway):
- Sysupgrade archive:
admin/network/backups/flint2/backup-flint2.tar.gz - Full UCI export:
admin/network/backups/flint2/flint2-uci-export.txt - Raw configuration files:
admin/network/backups/flint2/config/
- Sysupgrade archive:
- Archer C7 v5 (Extender AP):
- Sysupgrade archive:
admin/network/backups/archer-c7/backup-archerc7.tar.gz - Full UCI export:
admin/network/backups/archer-c7/archerc7-uci-export.txt - Raw configuration files:
admin/network/backups/archer-c7/config/
- Sysupgrade archive: