# Remerciements et references utilesD'abord un grand merci a c0mm0n pour ses recherches et surtout le partage d'infos sur ce merveilleux routeur
Les posts référence :
https://lafibre.info/remplacer-sfr/bypasser-la-neufbox/msg101223/#msg101223https://lafibre.info/orange-tutoriels/en-cours-remplacer-sa-livebox-par-un-routeur-ubiquiti-edgemax/https://lafibre.info/orange-tutoriels/en-cours-remplacer-sa-livebox-par-un-routeur-ubiquiti-edgemax/msg136801/#msg136801http://community.ubnt.com/t5/EdgeMAX/dhcp-client-Tuning-vendor-class-identifier-dhcp-option-60/td-p/581069Connections physique:- eth0 : reseau local
- eth1 : ONT
- eth2 : Management (optionnel)
Configuration du routeurConfigurer son PC en 192.168.1.2 255.255.255.0 192.168.1.1
se connecter depuis un browser a
http://192.168.1.1login : ubnt
password : ubnt
Onglet Dashboard
eth0 / Actions / Config
Description : LAN
Reglages par default a part
Use DHCP a selectionner
eth1 / Actions / Config
Description : WAN-ONT
Reglages par default a part
Use DHCP a selectionner
Onglet Services
Add DHCP Server
Save
Toujours dans Services / DNS
Cache Size : 150
Interface : eth1
Save
# Configuration du client DHCP (wan) uniquement valable à partir de la version 1.5 beta 1changez email@mail.com par votre email, ce n'est pas obligatoire techniquement mais aidera le technicien SFR a vous contacter si besoin
configure
set interfaces ethernet eth1 dhcp-options client-option "send vendor-class-identifier "neufbox6-email@mail.com";"
commit
save
Apres le reboot se reconnecter sur l'interface web onglet Firewall / NAT
Onglet NAT / Add Source NAT Rule
save
# Creer les regles de firewall par exemple en suivant le mode d'emploi suivant
http://community.ubnt.com/t5/EdgeMAX-Configuration-Examples/EdgeMAX-SOHO-Example/ta-p/413019Vous pouvez aussi le faire en ligne de commande voici ma configuration simplifiee avec une redirection RDP, Minecraft et https
configure
set firewall name WAN_LOCAL description "packets from internet to the router"
set firewall name WAN_LOCAL default-action drop
set firewall name WAN_LOCAL enable-default-log
set firewall name WAN_LOCAL rule 10 description "allow established sessions"
set firewall name WAN_LOCAL rule 10 action accept
set firewall name WAN_LOCAL rule 10 state established enable
set firewall name WAN_LOCAL rule 10 state related enable
set firewall name WAN_LOCAL rule 10 state invalid disable
set firewall name WAN_LOCAL rule 10 state new disable
set firewall name WAN_LOCAL rule 10 protocol all
set firewall name WAN_LOCAL rule 20 description "drop invalid state"
set firewall name WAN_LOCAL rule 20 action drop
set firewall name WAN_LOCAL rule 20 state established disable
set firewall name WAN_LOCAL rule 20 state related disable
set firewall name WAN_LOCAL rule 20 state invalid enable
set firewall name WAN_LOCAL rule 20 state new disable
set firewall name WAN_LOCAL rule 20 protocol all
set interfaces ethernet eth1 firewall local name WAN_LOCAL
set firewall name WAN_IN description "packets from internet to LAN & WLAN"
set firewall name WAN_IN default-action drop
set firewall name WAN_IN enable-default-log
set firewall name WAN_IN rule 10 description "allow established sessions"
set firewall name WAN_IN rule 10 action accept
set firewall name WAN_IN rule 10 state established enable
set firewall name WAN_IN rule 10 state related enable
set firewall name WAN_IN rule 10 state invalid disable
set firewall name WAN_IN rule 10 state new disable
set firewall name WAN_IN rule 10 protocol all
set firewall name WAN_IN rule 20 description "drop invalid state"
set firewall name WAN_IN rule 20 action drop
set firewall name WAN_IN rule 20 state established disable
set firewall name WAN_IN rule 20 state related disable
set firewall name WAN_IN rule 20 state invalid enable
set firewall name WAN_IN rule 20 state new disable
set firewall name WAN_IN rule 20 protocol all
set firewall name WAN_IN rule 30 description "minecraft"
set firewall name WAN_IN rule 30 action accept
set firewall name WAN_IN rule 30 protocol tcp
set firewall name WAN_IN rule 30 destination port 25565-25566
set firewall name WAN_IN rule 30 destination address 192.168.1.2
set firewall name WAN_IN rule 40 description "RDP"
set firewall name WAN_IN rule 40 action accept
set firewall name WAN_IN rule 40 protocol rdp
set firewall name WAN_IN rule 40 destination address 192.168.1.2
set firewall name WAN_IN rule 50 description "Https web server"
set firewall name WAN_IN rule 50 action accept
set firewall name WAN_IN rule 50 protocol tcp
set firewall name WAN_IN rule 50 destination port 443
set firewall name WAN_IN rule 50 destination address 192.168.1.2
set interfaces ethernet eth1 firewall in name WAN_IN
set service nat rule 1 type destination
set service nat rule 1 description "RDP"
set service nat rule 1 destination port 3389
set service nat rule 1 inbound-interface eth1
set service nat rule 1 inside-address address 192.168.1.2
set service nat rule 1 inside-address port 3389
set service nat rule 1 log disable
set service nat rule 1 protocol tcp
set service nat rule 2 type destination
set service nat rule 2 description "Minecraft"
set service nat rule 2 destination port 25565-25566
set service nat rule 2 inbound-interface eth1
set service nat rule 2 inside-address address 192.168.1.2
set service nat rule 2 inside-address port 25565-25566
set service nat rule 2 log disable
set service nat rule 2 protocol tcp
set service nat rule 3 type destination
set service nat rule 3 description "web https"
set service nat rule 3 destination port 443
set service nat rule 3 inbound-interface eth1
set service nat rule 3 inside-address address 192.168.1.2
set service nat rule 3 inside-address port 443
set service nat rule 3 log disable
set service nat rule 3 protocol tcp
commit
save
Rebootez et vous devriez avoir le web maintenant !!!!