OpenWrt VLAN Configuration
Option 1: The UCI Method (quickest)
Best for reproducibility and remote configuration via SSH. for fast deployment but note that you have to edit the script accordingly.
# 1. Define the VLAN on the Hardware Bridge
# We use 'add' to create a new bridge-vlan section
uci add network bridge-vlan
uci set network.@bridge-vlan[-1].device='br-lan'
uci set network.@bridge-vlan[-1].vlan='43'
# IMPORTANT: 'lan1' is the port to Proxmox. ':t' means Tagged.
# You MUST also tag the 'vlan43' (CPU/Local) port so the router can talk to it.
uci add_list network.@bridge-vlan[-1].ports='lan1:t'
uci add_list network.@bridge-vlan[-1].ports='vlan43:t'
# 2. Create the Logic Interface (The Gateway)
uci set network.matrix_vlan=interface
uci set network.matrix_vlan.proto='static'
uci set network.matrix_vlan.device='br-lan.43'
uci set network.matrix_vlan.ipaddr='192.168.43.1'
uci set network.matrix_vlan.netmask='255.255.255.0'
# 3. Configure the DHCP Server
uci set dhcp.matrix_vlan=dhcp
uci set dhcp.matrix_vlan.interface='matrix_vlan'
uci set dhcp.matrix_vlan.start='100'
uci set dhcp.matrix_vlan.limit='50'
uci set dhcp.matrix_vlan.leasetime='12h'
# 4. Create the Firewall Zone and Rules
uci add firewall zone
uci set firewall.@zone[-1].name='vlan43'
uci set firewall.@zone[-1].network='matrix_vlan'
uci set firewall.@zone[-1].input='ACCEPT'
uci set firewall.@zone[-1].output='ACCEPT'
uci set firewall.@zone[-1].forward='REJECT'
# Allow the VLAN to reach the Internet (WAN)
uci add firewall forwarding
uci set firewall.@forwarding[-1].src='vlan43'
uci set firewall.@forwarding[-1].dest='wan'
# 5. Apply changes
uci commit
/etc/init.d/network restart
/etc/init.d/firewall restart
Option 2: The LuCI (Web GUI) Method
Best for visual verification of port status.
Step 1: Bridge Configuration
- Navigate to Network -> Interfaces -> Devices.
- Click Configure next to
br-lan. - Go to the Bridge VLAN filtering tab.
- Ensure Enable VLAN filtering is checked.
- Click Add:
- VLAN ID:
43 - Local: Checked (Crucial: This lets the router’s CPU join the VLAN).
- Ports: Find the port connected to Proxmox (e.g., LAN 1) and set it to tagged.
- VLAN ID:
- Save (Do not click Save & Apply yet).
Step 2: Interface Creation
- Navigate to Network -> Interfaces.
- Click Add new interface….
- Name:
MATRIX_VLAN - Protocol:
Static address - Device: Select
@br-lan.43(This represents the tagged traffic from the bridge).
- Name:
- Settings:
- IPv4 address:
192.168.43.1 - Netmask:
255.255.255.0
- IPv4 address:
- Go to the DHCP Server tab -> General Setup and click Setup DHCP Server.
Step 3: Firewall Zone
- While still in the
MATRIX_VLANinterface settings, go to Firewall Settings. - In Create / Assign firewall-zone, type
vlan43and press enter. - Save & Apply.
- Navigate to Network -> Firewall.
- Find your new
vlan43zone and ensure the Forward is set to allow traffic to the WAN zone.
The “Don’t Get Locked Out” Checklist
- Always make sure your computer’s current port is set to Untagged on VLAN 1 before clicking Apply.
- The “Local” Checkbox: In LuCI, if “Local” isn’t checked for a VLAN, the router’s software can’t “see” that traffic, and your DHCP server won’t work.
- Standardized Octets: Notice how we used
VLAN 43and192.168.43.1. This is your new standard.
To finish the loop, we need to make sure Proxmox knows how to handle that VLAN 43 tag. In Proxmox, the default networking is usually a “Linux Bridge” (vmbr0). By default, it acts like an unmanaged switch—it doesn’t care about tags unless you tell it to.
Here is how to set up the Proxmox side to match your new OpenWrt configuration.
1. Make the Proxmox Bridge “VLAN Aware”
If your bridge isn’t VLAN-aware, it will drop any tagged packets coming from your LXC before they even reach the physical cable.
- Log into your Proxmox Web UI.
- Go to System -> Network.
- Select your main bridge (usually
vmbr0). - Click Edit.
- Check the box for VLAN Aware.
- Apply Configuration (This does not usually require a reboot, but it will momentarily restart the network stack).
2. Configure the LXC Container
Now you need to tell the specific Matrix LXC to “sit” on VLAN 43.
- Select your Matrix LXC from the left-hand sidebar.
- Go to the Network tab.
- Select the network interface (usually
net0) and click Edit. - In the VLAN Tag field, enter
43. - Ensure IPv4 is set to
DHCP. - Click OK.
3. The “Moment of Truth” Test
Start your LXC and open the console. Run the following commands to verify the “Subnet-Nightmare” is actually working:
- Check IP:
ip addr show- Result: You should see an IP like
192.168.43.XXX.
- Result: You should see an IP like
- Check Gateway:
ip route- Result: The default via should be
192.168.43.1.
- Result: The default via should be
- Check DNS/Internet:
ping -c 3 google.com- Result: If this fails but the IP is correct, check your OpenWrt Firewall zone to ensure
vlan43is allowed to forward towan.
- Result: If this fails but the IP is correct, check your OpenWrt Firewall zone to ensure
Troubleshooting “Subnet-Nightmare”
- OpenWrt Side: Ensure the physical port (e.g.,
lan1) in yourbridge-vlansection has the:t(tagged) suffix. - Proxmox Side: Ensure the physical network card (e.g.,
eno1oreth0) is actually a member ofvmbr0. - The Cable: Ensure you aren’t using a “dumb” unmanaged switch between OpenWrt and Proxmox. Some cheap switches strip VLAN tags, which will kill the connection.
Pro-Tip for Matrix
Once the networking is solid, remember that Matrix Synapse defaults to port 8008. You will eventually need to create a Port Forward in OpenWrt (WAN port 443 -> LXC IP port 8008) so your students can connect from outside your home lab.
Would you like the homeserver.yaml snippets to configure the listener and database connection for Synapse once you’re inside the LXC?
Leave a Reply
You must be logged in to post a comment.