What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

BE98 Pro Mesh System – Constant Instability Issues, Anyone Else Experiencing This?

These are the lists I use.. I don't think though this is the problem is caused by that @SomeWhereOverTheRainBow . Also, in the log (which I don't know how to share) I searched all amazon / ring domains I don't see any blocked for the IPs of the cameras. Also I never had this problem before only on the BE98pros and the other quad band router the AXE-11000 I also whitelist most things and these are the blocklist and whitelists - I'm using adguard for blocking streaming ads mostly:

Custom Rules:
||*.mediatailor.*.amazonaws.com^$important
||.mediatailor.*.amazonaws.com^$important
||*s3-iad-ww.cf.dash.row.aiv-cdn.net^$important
||*s3-iad-2.cf.dash.row.aiv-cdn.net^$important
||*shard-1.pop-iad-2.cf.dash.row.aiv-cdn.net^$important
||*shard-2.pop-iad-2.cf.dash.row.aiv-cdn.net^$important
||*shard-3.pop-iad-2.cf.dash.row.aiv-cdn.net^$important
||*shard-4.pop-iad-2.cf.dash.row.aiv-cdn.net^$important
||vtrk.doubleverify.com^$important
||video.adsafeprotected.com^$important
||vae-bid.adsrvr.org^$important
||unified.adsafeprotected.com^$important
||tpsc-video-ue.doubleverify.com^$important
||securepubads.g.doubleclick.net^$important
||s.update.adsrvr.org^$important
||s.innovid.com^$important
||s-static.innovid.com^$important
||rtr.innovid.com^$important
||ravm.tv^$important
||px.moatads.com^$important
||pubads.g.doubleclick.net^$important
||pi.ispot.tv^$important
||p.ads.roku.com^$important
||obo.moatads.com^$important
||lciapi.ninthdecimal.com^$important
||i.w55c.net^$important
||googleads4.g.doubleclick.net^$important
||googleads.g.doubleclick.net^$important
||events.tremorhub.com^$important
||enduser.adsrvr.org^$important
||dsa.moatads.com^$important
||dmp.truoptik.com^$important
||csm-e-dfwvod-eb.geoloc.yospace.com^$important
||b.videoamp.com^$important
||ads.w55c.net^$important
||ade.googlesyndication.com^$important
||ad.doubleclick.net^$important
||5af10.v.fwmrm.net^$important
||*vtrk.dv.tech^$important
||*csi.gstatic.com^$important
||*safebrowsing.googleapis.com^$important
||vtrk.dv.tech^$important
||csi.gstatic.com^$important
||safebrowsing.googleapis.com^$important
@@||adserver.adtech.advertising.com^
@@||*adserver.adtech.advertising.com^
@@||click.a-ads.com^
@@||*click.a-ads.com^
@@||static.a-ads.com^
@@||*static.a-ads.com^
@@||ad.a-ads.com^
@@||*ad.a-ads.com^
@@||a-ads.com^
@@||*a-ads.com^
@@||wp.com^
@@||*wp.com^
@@||wipteetolu.net^
@@||*wipteetolu.net^
@@||pagead2.googlesyndication.com^
@@||*pagead2.googlesyndication.com^
@@||p11.techlab-cdn.com^
@@||*p11.techlab-cdn.com^
@@||api2.amplitude.com^
@@||*api2.amplitude.com^
@@||edge.fullstory.com^
@@||*edge.fullstory.com^
@@||www.clarity.ms^
@@||*www.clarity.ms^
@@||c.clarity.ms^
@@||*c.clarity.ms^
@@||t.clarity.ms^
@@||*t.clarity.ms^
@@||rs.fullstory.com^
@@||*rs.fullstory.com^
@@||websdk.appsflyer.com^
@@||*websdk.appsflyer.com^
@@||sc-static.net^
@@||*sc-static.net^
@@||static.ads-twitter.com^
@@||*static.ads-twitter.com^
@@||tr.snapchat.com^
@@||*tr.snapchat.com^
@@||pagead2.googlesyndication.com^
@@||*pagead2.googlesyndication.com^
@@||agkn.com^
@@||agkn.com^
@@||*mediaplex.com^
@@||mediaplex.com^
@@||jwpltx.com^
@@||*jwpltx.com^
@@||apple.com^
@@||*apple.com^
@@||icloud.com^
@@||*icloud.com^
@@||partnerlinks.io^
@@||*partnerlinks.io^
@@||saatva.com^
@@||*saatva.com^
@@||*saatvamattress.com^
@@||saatvamattress.com^
@@||contextweb.com^
@@||*contextweb.com^
@@||*aylanetworks.com^
@@||aylanetworks.com^
@@||lijit.com^
@@||*lijit.com^
@@||*nbcstreaming.sc.omtrdc.net^
@@||nbcstreaming.sc.omtrdc.net^
@@||47e224be59415ec068b94bca857581bd7dde7fb6.cws.conviva.com^
@@||*47e224be59415ec068b94bca857581bd7dde7fb6.cws.conviva.com^
@@||udm.scorecardresearch.com^
@@||*udm.scorecardresearch.com^
@@||*log-api.dualstack.nr-data.net^
@@||log-api.dualstack.nr-data.net^
@@||cm.everesttech.net^
@@||*cm.everesttech.net^
@@||*nbcuss.demdex.net^
@@||nbcuss.demdex.net^
@@||firebaselogging.googleapis.com^
@@||*firebaselogging.googleapis.com^
@@||logs.netflix.com^
@@||*logs.netflix.com^
@@||saa.paramountplus.com^
@@||*saa.paramountplus.com^
@@||*vortex.hulu.com^
@@||vortex.hulu.com^
@@||*sessions.bugsnag.com^
@@||sessions.bugsnag.com^
@@||bridge.lga1.admarketplace.net^
@@||*bridge.lga1.admarketplace.net^
@@||*url1445.affirm.com^
@@||url1445.affirm.com^
@@||succeedscene.com^
@@||*succeedscene.com^
@@||*ct.pinterest.com^
@@||ct.pinterest.com^
||vam-bid.adsrvr.org^$important
||ad-events.flashtalking.com^$important
||cdn.flashtalking.com^$important
||d9.flashtalking.com^$important
||pixel.adsafeprotected.com^$important
||29773.v.fwmrm.net^$important
||track.activemetering.com^$important
||pn.ybp.yahoo.com^$important
||imtwjwoasak.com^$important
||p.tvpixel.com^$important
||ir.surveywall-api.survata.com^$important
||s2s.us1.mparticle.com^$important
||tv.rlcdn.com^$important
||tpsc-video.doubleverify.com^$important
||d.agkn.com^$important
||us-east-1.event.prod.bidr.io^$important
||bam.nr-data.net^$important
||mt.ssai.peacocktv.com^$important
||xtv.clients.peacocktv.com^$important
||nbcstreaming.hb.omtrdc.net^$important
/nbcstreaming\.[^.]+\.omtrdc\.net/
@@/g[^.]+-vod-us-cmaf-prd-mc.cdn.peacocktv.com/$important
/g[^.]+-vod-us-cmaf-prd-[^.]+.cdn.peacocktv.com/
@@||g008-vod-us-cmaf-prd-ak.cdn.peacocktv.com^$important
@@||g008-vod-us-cmaf-prd-cf.cdn.peacocktv.com^$important
@@||g008-vod-us-cmaf-prd-ak-a122.cdn.peacocktv.com^$important
@@/g001-vod-us-cmaf-prd-[^.]+.cdn.peacocktv.com/$important
||g001-sle-us-cmaf-prd-cf.cdn.peacocktv.com^
||g008-sle-us-cmaf-prd-cf.cdn.peacocktv.com^
@@/g\d+-vod-us-cmaf-prd-mc\.cdn\.peacocktv\.com/
/g\d+-vod-us-cmaf-prd-[a-z]+\.cdn\.peacocktv\.com/
@@||g006-vod-us-cmaf-prd-cf.cdn.peacocktv.com^$important


Blocklist:
https://v.firebog.net/hosts/Easyprivacy.txt

Whitelist:
Try my allowlist see if it helps.

 
Thanks. However, I’m still not understanding why this was working fine on my GT-AX11000 and my AC5300 routers but now it’s not working. Meaning it’s something else going on. I’m not only having issues with ring devices. My little smart IR sensors are randomly offline at random times. My Frigidaire AC is offline and has never came back online this whole time the separate network was created for IOT.
 
Thanks. However, I’m still not understanding why this was working fine on my GT-AX11000 and my AC5300 routers but now it’s not working. Meaning it’s something else going on. I’m not only having issues with ring devices. My little smart IR sensors are randomly offline at random times. My Frigidaire AC is offline and has never came back online this whole time the separate network was created for IOT.
So IOT devices do not cooperate if several environment variables are impacting their operations. In one of the previous messages i mentioned how these devices operate. They operate by making outbound connections to CDN (content delivery network). Some also connect their own server API, while others just simply refuse to operate if they are not able to properly set their clock to a remote ntp server -- which may also use dns. What will happen eventually is the device will disconnect and fall off your network because it will not keep attempting to communicate with these services that are necessary for them to properly function. IOT devices do not handle rejection very well. If that is what is happening, then it has nothing to do with your actual wireless settings, and has everything to do with your dns settings. You may just be seeing the wireless logs from your devices falling off the network when they assume the internet is down because they are failing to reach hardcoded remote services because the domains are being blocked over dns.
 
Last edited:
So IOT devices do not cooperate if several environment variables are impacting their operations. In one of the previous messages i mentioned how these devices operate. They operate by making outbound connections to CDN (content delivery network). Some also connect their own server API, while others just simply refuse to operate if they are not able to properly set their clock to a remote ntp server -- which may also use dns. What will happen eventually is the device will disconnect and fall off your network because it will not keep attempting to communicate with these services that are necessary for them to properly function. IOT devices do not handle rejection very well. If that is what is happening, then it has nothing to do with your actual wireless settings, and has everything to do with your dns settings. You may just be seeing the wireless logs from your devices falling off the network when they assume the internet is down because they are failing to reach hardcoded remote services because the domains are being blocked over dns.
@SomeWhereOverTheRainBow well heres another question is there a way to make Adguard not apply to the SDN network ? Meaning let's say I just wanted Adguard being applied to my main network is that possible ? I am noticing that even though I have a different subnet it seems to still be showing in the adguard logs and I think ad-blocking is still applying to my iOT devices because I see them in the adguard log.
 
@SomeWhereOverTheRainBow well heres another question is there a way to make Adguard not apply to the SDN network ? Meaning let's say I just wanted Adguard being applied to my main network is that possible ? I am noticing that even though I have a different subnet it seems to still be showing in the adguard logs and I think ad-blocking is still applying to my iOT devices because I see them in the adguard log.
Yes, when i get home i will given you a screenshot demo of what you can do. There is a way in adguardhome gui to segregate blocking via subnet, and even mac address if you wanted.
 
@SomeWhereOverTheRainBow well heres another question is there a way to make Adguard not apply to the SDN network ? Meaning let's say I just wanted Adguard being applied to my main network is that possible ? I am noticing that even though I have a different subnet it seems to still be showing in the adguard logs and I think ad-blocking is still applying to my iOT devices because I see them in the adguard log.
So under AdGuardHome settings "client settings"
1758663098394.png


You can configure persistent client rules. Here you can define client rules based on subnet, mac address, or simply by hostname or single IP. Since your clients are talking directly to adguardhome, and you are talking about controling via subnet, you can define your persistent rules here. If you wanted to setup rules based on single IP, you first have to register a static dhcp lease for the client in the Asuswrt Webui, then add the client rule here.

Lets say your IOT subnet is 192.168.7.0/24, here is an example of what you could do:

1758663433087.png

If you don't want any of the blocking rules uncheck the global settings and uncheck all of the block rules. You can also assign tags if you want that client to only be the device that gets a certain whitelist rule. They call it a ctag modifier.
example: @@||example.org^$ctag=device_camera|device_securityalarm , this would create a specific unblock rule that only that subnet would use.
 
So under AdGuardHome settings "client settings"
View attachment 68035

You can configure persistent client rules. Here you can define client rules based on subnet, mac address, or simply by hostname or single IP. Since your clients are talking directly to adguardhome, and you are talking about controling via subnet, you can define your persistent rules here. If you wanted to setup rules based on single IP, you first have to register a static dhcp lease for the client in the Asuswrt Webui, then add the client rule here.

Lets say your IOT subnet is 192.168.7.0/24, here is an example of what you could do:

View attachment 68036
If you don't want any of the blocking rules uncheck the global settings and uncheck all of the block rules. You can also assign tags if you want that client to only be the device that gets a certain whitelist rule. They call it a ctag modifier.
example: @@||example.org^$ctag=device_camera|device_securityalarm , this would create a specific unblock rule that only that subnet would use.
Ok so I'm going to make the whole IOT network excluded ! I will let you know if that helps ! thanks @SomeWhereOverTheRainBow
 
Ok so I'm going to make the whole IOT network excluded ! I will let you know if that helps ! thanks @SomeWhereOverTheRainBow
You can also specify what dns servers those devices use e.g.
1758664173592.png


This is good if you know your IOT devices communicate better with google, or cloudflare, or quad9, or even all three. You can then make the devices use a specific unfiltered upstream for dns requests.

You can also exclude these devices chatter from the query log so you can monitor only the traffic of the devices you are concerned about monitoring by checking these boxes:

1758664328731.png


Just an FYI: I am using the edge version of adguardhome.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Staff online

Back
Top