GUARD-F2 Frequently Asked Questions

PDF Manuals, Data Sheets, and Press Releases can be found in the MPL Documentation area of this homepage.


Question #425: I'm trying to update the package repository, but it fails with the following errors:
# opkg update
Collected errors:
 * opkg_download: Failed to download https://.../packages/Packages.gz, wget returned 5.
 * opkg_download: Failed to download https://.../base/Packages.gz, wget returned 5.
 * opkg_download: Failed to download https://.../luci/Packages.gz, wget returned 5.

Answer: In September 2021, a so-called root certificate used by "Let's Encrypt" expired. Please check this article for details. As a consequence, access to all "Let's Encrypt" protected web pages (including the one with the GUARD software repositories) started to fail if no updated root certificate is installed.

Please follow the steps below to update the GUARD's certificate store with the new "Let's Encrypt ISRG Root X1 certificate":
  1. Download the following packages from the specifed URLs:
    • https://guard.mpl.ch/GUARD64/LEDE-17.01.2/packages/x86_64/packages/wget_1.18-2_x86_64.ipk
    • https://guard.mpl.ch/GUARD64/LEDE-17.01.2/packages/x86_64/packages/libpcre_8.40-2_x86_64.ipk
    • https://archive.openwrt.org/releases/packages-21.02/x86_64/base/ca-certificates_20210119-1_all.ipk
  2. Log into the GUARD
  3. Transfer (USB, SSH, ..) the downloaded package files to the /tmp directory on your GUARD
  4. Install the package files using opkg
    • root@LEDE:/# opkg install /tmp/libpcre_8.40-2_x86_64.ipk
    • root@LEDE:/# opkg install /tmp/wget_1.18-2_x86_64.ipk
    • root@LEDE:/# opkg install /tmp/ca-certificates_20210119-1_all.ipk
  5. Remove the "old" DST_Root_CA_X3 certificate (this is required because of this "OpenSSL problem")
    root@LEDE:/# rm /etc/ssl/certs/DST_Root_CA_X3.crt
  6. Remove the no longer used "uclient-fetch" package
    root@LEDE:/# opkg remove --force-depends uclient-fetch


Question #421: I'm unable to establish ethernet communication with the GUARD. What can I do?
Answer: If you are unable to ping the GUARD or open the web interface, please check the following points:

  • Is the system powered ("Power LED" is lit green)?
  • Is the system firmware up and running (Does the "Status LED" blink in a heartbeat-like rhythm)?
  • Is the connection between the GUARD and your PC/laptop correctly set up? Please check chapter 2.1 of the "GUARD OpenWrt User Manual" for details. The "LAN LED" of the corresponding ethernet port must be lit.

If there is no improvement, initiate a "factory reset" of the system. Please check chapter 5.1 of the "GUARD OpenWrt User Manual" for details.
As a last resort, do a "reflash" of the firmware. Please check chapter 5.2 of the "GUARD OpenWrt User Manual" for details.

Question #408:
  • Please provide a list of network protocols suppored by the GUARD?
  • For my application I must use network protocol XYZ. Does the GUARD support protocol XYZ?
Answer:
  • The GUARD software is based on OpenWrt. The list of supported protocols is therefore (more or less) the same as the one of OpenWrt.
  • If OpenWrt has support for protocol XYZ, the odds are good that your desired protocol will as be available* on the GUARD.

* Depending on the precise requirements, some additional effort and/or manual configuration may be needed.


Question #375: What operating system is installed on the GUARD?
Answer: All GUARDs come with OpenWrt preinstalled. This is a Linux based distribution specialized for firewall and routing tasks. For more information about OpenWrt, please check the Documentation and FAQ sections on the OpenWrt homepage.

Question #378: Do you provide Communications Assistance for Law Enforcement Act (CALEA) functionality for the GUARD?
Answer: No.
 Copyright © 1997-2022 MPL AG Elektronikunternehmen, a member of the HT Holding AG  |  Privacy Statement
MPL on LinkedIn    MPL on twitter