Check out the new blog at http://linuxehacking.ovh , this one will no longer be updated

giovedì 3 settembre 2015

Blog moving to linuxehacking.ovh

Because of some limitations of blogger platform i have moved the blog to this new address http://linuxehacking.ovh
This one will not be deleted but i'll no longer post here.

mercoledì 26 agosto 2015

Convert your cheap "unmanaged" switch to a VLAN capable layer 2 managed switch for just $2

The title of that post may look crazy at first, but it's not, it is entirely possible to convert your cheap 100M 8 port switch or stuff like that to a managed switch.

That's possible simply because, if you open up one of these and look at the datasheet, you will find out that they use the same switch chips used frequently inside of routers ( which they can be reprogrammed as you like with openwrt ).

The switch i've used this time is a "digicom 10/100" switch, digicom is an italian rebrand of some other stuff probably, but anyway, let's get straight to the point, below you can see the PCB of that switch



Switch chip is IP178CH, and since today luck is on our side, its datasheet can easily be found there http://www.icplus.com.tw/Data/Datasheet/IP178Cx-DS-R13-20080925.pdf .



Serial management interface timing diagram and command format

Now by taking a quick look at the datasheet some important things for that modification are easily found:

  • The switch chip can be programmed by pulling up or down it's pins but only basic features are programmable that way
  • The switch chip can be programmed from the EEPROM ( which on that switch board is not present, but there are unpopulated pads for it ), for the switch to take in account the EEPROM , first two bytes must be 0x55AA
  • The switch chip can be programmed using a synchronous serial interface at pins MDC & MDIO, on the fly.
    This one is the most useful one to create a managed switch

The serial interface is similiar to I2C but much simpler, it does not support multiple devices on the same bus and devices don't have an address.
MDC Clock has to be generated from CPU side ( in that case an arduino ) , so you can operate it at whatever speed you want provided you don't exceed maximum ratings.

Now once you know how to operate communicate with the switch it's just matter of programming an arduino.
To do that, if you want just to test and you are going to power the arduino over usb. you are going to need to modify an USB cable to give arduino 3.3v instead of 5v.
You could also use a level shifter for that, but i prefer powering the entire arduino at 3.3v because it's simpler and cheaper.
To power an arduino with 3.3v you can simple take an usb cable and cut red and black wires and insert a regulator between PC side and arduino side.

Arduino usb cable modification
After doing that modification, just adjust the regulator to give 3.3v and you are ready to go
On that switch , since again , we are lucky today, the IC pins of the serial management interface were already routed to an unpopulated header, on which i soldered a 3 pin strip header

The pinout is the following:
1 :   GND
2 :   MDIO
3 :   MDC

MDIO must be pulled high using a 2.2k resistor or some similiar value, again, if you are using a level shifter instead of the 3.3 cable mod, be sure to connect pullup resistor to 3.3v and not 5V.
To protect I/O lines also add two 100 ohm resistors or 200 ohm at most between MDIO,MDC and arduino pins ( 2,3 )

After doing that the HW part is done, if you want to make it permanent, just buy an arduino pro mini ( NOT NANO ) , and an usb-serial, the two should be around $2 total, max 3$.
You can also easily find on the board the 3.3v power rail and power the pro-mini from there, DO NOT power the arduino pro mini from usb or use an arduino nano or you will fry everything.
When connecting usb-serial adapter to it you will only connect GND, RX, TX wires , also DTS if you want to be able to program it from usb.

Now let's take a look of a basic software to have a managed switch which can save configuration on arduino eeprom and restore it at boot.


  1. #include <EEPROM.h>
  2. #define MDIO 2
  3. #define MDC 3
  4. #define PHY30_REG13_PORT1_REMOVE_TAG 0x10
  5. #define PHY30_REG13_VLAN_EN 0x8
  6. void outBit(int b)
  7. {
  8.   digitalWrite(MDC,LOW);
  9.   if ( b == 0 )
  10.     digitalWrite(MDIO,LOW);
  11.   else
  12.     digitalWrite(MDIO,HIGH);
  13.   delayMicroseconds(1);
  14.   digitalWrite(MDC,HIGH);
  15.   delayMicroseconds(1);
  16. }
  17. int inBit()
  18. {
  19.   digitalWrite(MDC,LOW);
  20.   delayMicroseconds(1);
  21.   unsigned int res = digitalRead(MDIO);
  22.   digitalWrite(MDC,HIGH);
  23.   delayMicroseconds(1);
  24.   return res == HIGH ? 1 : 0;
  25. }
  26. unsigned int readReg(unsigned int phyaddr, unsigned int regaddr)
  27. {
  28.   int k = 0;
  29.   unsigned int res = 0;
  30.   pinMode(MDC,OUTPUT);
  31.   inBit();
  32.   inBit();//IDLE
  33.   pinMode(MDIO,OUTPUT);
  34.   pinMode(MDC,HIGH);
  35.   outBit(0);//START
  36.   outBit(1);
  37.   outBit(1);//READ
  38.   outBit(0);
  39.   for ( k = 4; k >= 0; k-- )
  40.     outBit((phyaddr >> k) & 0x1);
  41.   for ( k = 4; k >= 0; k-- )
  42.     outBit((regaddr >> k) & 0x1);
  43.   pinMode(MDIO,INPUT);
  44.   digitalWrite(MDIO,HIGH);//Pullup
  45.   inBit(); //Z
  46.   inBit();
  47.   for ( k = 15; k >= 0; k-- )
  48.     res |= ( inBit() << k );
  49.   return res;
  50. }
  51. void writeReg(unsigned int phyaddr, unsigned int regaddr, unsigned int value)
  52. {
  53.   int k = 0;
  54.   unsigned int res = 0;
  55.   pinMode(MDC,OUTPUT);
  56.   inBit();
  57.   inBit();//IDLE
  58.   pinMode(MDIO,OUTPUT);
  59.   pinMode(MDC,HIGH);
  60.   outBit(0);//START
  61.   outBit(1);
  62.   outBit(0);//WRITE
  63.   outBit(1);
  64.   for ( k = 4; k >= 0; k-- )
  65.     outBit((phyaddr >> k) & 0x1);
  66.   for ( k = 4; k >= 0; k-- )
  67.     outBit((regaddr >> k) & 0x1);
  68.   outBit(1); //TA
  69.   outBit(0);
  70.   for ( k = 15; k >= 0; k-- )
  71.     outBit((value >> k) & 0x1);
  72.   pinMode(MDIO,INPUT);
  73.   digitalWrite(MDIO,HIGH);
  74.   inBit();
  75.   inBit();//IDLE
  76. }
  77. void saveReg(unsigned int eebase, unsigned int phy , unsigned int reg)
  78. {
  79.   unsigned int regval = readReg(phy,reg);
  80.   EEPROM.write(eebase,regval&0xff);
  81.   EEPROM.write(eebase+1,regval>>8);
  82. }
  83. void loadReg(unsigned int eebase, unsigned int phy , unsigned int reg)
  84. {
  85.   unsigned int regval = 0;
  86.   regval |= EEPROM.read(eebase);
  87.   regval |= EEPROM.read(eebase+1) << 8;
  88.   writeReg(phy,reg,regval);
  89. }
  90. void saveSettings()
  91. {
  92.   int i;
  93.   saveReg(2,30,13);
  94.   for ( i = 0; i < 8; i++ )
  95.   {
  96.     saveReg(4+i*2,30,3+i);
  97.   }
  98.   saveReg(20,30,12);
  99.   for ( i = 0; i < 16; i++ )
  100.   {
  101.     saveReg(22+i*2,30,14+i);
  102.   }
  103.    
  104.   EEPROM.write(0,0x54);
  105.   EEPROM.write(1,0x78);
  106. }
  107. void loadApplySettings()
  108. {
  109.   int i;
  110.   if ( EEPROM.read(0) != 0x54 || EEPROM.read(1) != 0x78 )
  111.   {
  112.     Serial.println("Invalid settings found, loading defaults");
  113.     writeReg(30,13,PHY30_REG13_VLAN_EN); //Enable vlan
  114.    
  115.     for ( i = 3; i < 11; i++ )//All untagged packets from ports will have VID 1 by default
  116.     {
  117.       writeReg(30,i,0);
  118.     }
  119.    
  120.     writeReg(30,12,0); //No port has tagged traffic by default
  121.    
  122.     writeReg(30,14,0x1ff); //All ports are member of VID0 (Untagged)
  123.     for ( i = 15; i < 30; i++ )//A
  124.     {
  125.       writeReg(30,i,0);
  126.      
  127.     }
  128.    
  129.    
  130.     saveSettings();
  131.    
  132.   }else{
  133.    
  134.     int i;
  135.     loadReg(2,30,13);
  136.     for ( i = 0; i < 8; i++ )
  137.     {
  138.       loadReg(4+i*2,30,3+i);
  139.     }
  140.    
  141.     loadReg(20,30,12);
  142.    
  143.    
  144.     for ( i = 0; i < 16; i++ )
  145.     {
  146.       loadReg(22+i*2,30,14+i);
  147.     }
  148.    
  149.     Serial.println("Loaded settings from eeprom");
  150.    
  151.   }
  152. }
  153. void setup()
  154. {
  155.   Serial.begin(115200);
  156.   Serial.setTimeout(60L*60L*1000L);
  157.   pinMode(MDIO,INPUT);
  158.   pinMode(MDC,INPUT);
  159.   Serial.println("Waiting for the switch chip to start-up ( 10 secs)");
  160.   delay(10000);
  161.   loadApplySettings();
  162. }
  163. int getInt()
  164. {
  165.   while( Serial.available() <= 0) {}
  166.   char c1 = Serial.read();
  167.   int n1 = c1-'0';
  168.   Serial.print(c1);
  169.   while( Serial.available() <= 0) {}
  170.   char c2 = Serial.read();
  171.   int n2 = c2-'0';
  172.   Serial.println(c2);
  173.   if ( n1 >= 0 && n1 <= 9 && n2 >= 0 && n2 <= 9 )
  174.     return n1*10+n2;
  175.   else
  176.     return -1;
  177. }
  178. unsigned int printPortMask(unsigned int current)
  179. {
  180.   int i;
  181.   for ( i = 0; i < 8; i++ )
  182.   {
  183.     if ( (current >> i) & 0x1 )
  184.        Serial.print("y");
  185.     else
  186.        Serial.print("n");
  187.    
  188.   }
  189. }
  190. unsigned int inputPortMask(unsigned int current)
  191. {
  192.   unsigned int n = 0;
  193.   int i;
  194.   Serial.print("Current ports (1-8 left to right):");
  195.   printPortMask(current);
  196.   Serial.println("");
  197.   Serial.print("Insert new ports ( y = assign, n = not assign ):");
  198.   for ( i = 0; i < 8; i++ )
  199.   {
  200.     char in;
  201.     while ( 1 )
  202.     {
  203.       in = Serial.read();
  204.       if ( in == 'y' || in == 'n' )
  205.       {
  206.         Serial.print(in);
  207.         break;
  208.       }
  209.     }
  210.     if ( in == 'y' )
  211.     {
  212.       n |= 1 << i;
  213.     }
  214.   }
  215.   Serial.println("");
  216.   return n;
  217. }
  218. void loop()
  219. {
  220.   int k;
  221.   Serial.println("Arduino switch configuration");
  222.   Serial.println("0. Show current configuration");
  223.   Serial.println("1. Assign ports to a specified VID");
  224.   Serial.println("2. Select which ports should remove VLAN tag from outgoing packets");
  225.   Serial.println("3. Select which ports should add a VLAN tag to outgoing packets");
  226.   Serial.println("4. Assign a VID to untagged traffic from a port");
  227.   Serial.println("5. Show link status");
  228.   Serial.println("6. Load factory defaults");
  229.   Serial.print("Enter you choice:");
  230.   while( Serial.available() <= 0) {}
  231.   int ch = Serial.read()-'0';
  232.   Serial.println(ch);
  233.   if ( ch >= 0 && ch < 7 )
  234.   {
  235.     if ( ch == 0 ) //Show current
  236.     {
  237.       Serial.println("VID Assignment ( 0 = untagged ):");
  238.       for ( k = 0; k < 16; k++ )
  239.       {
  240.         Serial.print(k);
  241.         Serial.print(" ports ");
  242.         printPortMask(readReg(30,14+k));
  243.         Serial.println("");
  244.       }
  245.       Serial.print("Remove VLAN tag ports: ");
  246.       printPortMask(readReg(30,13) >> 4);
  247.       Serial.println("");
  248.       Serial.print("Add VLAN tag ports: ");
  249.       printPortMask(readReg(30,12));
  250.       Serial.println();
  251.       Serial.println("Default VID assignment for untagged traffic:");
  252.       for ( k = 0; k < 8; k++ )
  253.       {
  254.         Serial.print("Port ");
  255.         Serial.print(k+1);
  256.         Serial.print(" untagged traffic will have VID ");
  257.         Serial.println(readReg(30,3+k));
  258.       }
  259.     }
  260.     if ( ch == 1 ) //Assign ports to a specified VID
  261.     {
  262.       Serial.print("Insert VID(0-15) with a leading 0 if needed ( 04, 09, 13 , .. ):");
  263.       int vid = getInt();
  264.       if ( vid < 0 || vid > 15 )
  265.       {
  266.         Serial.println("Invalid VID");
  267.         return;
  268.       }
  269.       unsigned int current = readReg(3014+vid);
  270.       unsigned int newmask = inputPortMask(current);
  271.       writeReg(3014+vid, newmask);
  272.      
  273.       if ( readReg(30,14+vid) != newmask )
  274.       {
  275.         Serial.println("Can't set register value");
  276.       }
  277.       saveSettings();
  278.       Serial.println("OK");
  279.     }
  280.     if ( ch == 2 )
  281.     {
  282.       unsigned int current = readReg(30,13) >> 4;
  283.       unsigned int newmask = inputPortMask(current);
  284.       writeReg(3013, PHY30_REG13_VLAN_EN | ( newmask << 4 ) );
  285.       saveSettings();
  286.       Serial.println("");
  287.       Serial.println("OK");
  288.     }
  289.     if ( ch == 3 )
  290.     {
  291.       unsigned int current = readReg(30,12);
  292.       unsigned int newmask = inputPortMask(current);
  293.       writeReg(3012, newmask );
  294.       saveSettings();
  295.       Serial.println("");
  296.       Serial.println("OK");
  297.     }
  298.     if ( ch == 4 )
  299.     {
  300.       Serial.print("Insert port (1-8): ");
  301.       while( Serial.available() <= 0) {}
  302.       int chp = Serial.read()-'0';
  303.       Serial.println(chp);
  304.      
  305.       if ( chp <= 0 || chp > 8 )
  306.       {
  307.         Serial.println("Invalid port");
  308.         return;
  309.       }
  310.      
  311.       Serial.print("Insert default VID for untagged traffic:");
  312.      
  313.       int vid = getInt();
  314.       if ( vid < 0 || vid > 15 )
  315.       {
  316.         Serial.println("Invalid VID");
  317.         return;
  318.       }
  319.      
  320.      
  321.       writeReg(30,3+chp-1,vid);
  322.       saveSettings();
  323.       Serial.println("OK");
  324.      
  325.     }
  326.     if ( ch == 5 )
  327.     {
  328.       for ( k = 0; k < 8; k++ )
  329.       {
  330.         Serial.print("Port ");
  331.         Serial.print(k+1);
  332.         Serial.print(" Link ");
  333.         int r = readReg(k,1);
  334.         if ( (>> 2) & 0x1 )
  335.           Serial.println("UP   ");
  336.         else
  337.           Serial.println("DOWN ");
  338.       }
  339.     }
  340.     if ( ch == 6 )
  341.     {
  342.       Serial.print("Are you sure you want to load factory defaults ( y = yes ): ");
  343.       while( Serial.available() <= 0) {}
  344.       if ( Serial.read() != 'y' )
  345.          return;
  346.       EEPROM.write(0,0x00);
  347.       loadApplySettings();
  348.     }
  349.    
  350.   }
  351. }

Don't worry about line-numbers, they won't appear when copypasted to a text editor

outBit and inBit generate a clock cycle on MDC while reading or writing an output value to/from MDIO

readReg reads an entire register by submitting read command, phy address and reg address

writeReg writes an entire register by submitting a write command together with phy address, reg address and the 16 bit value to write.

The switch itself works in a fairly simple way, you can assign which ports belongs to a VLAN ( that is independent from whether the packets will be tagged or not) and then you can configure how to treat untagged packet and what to do when a packet from a VID port group goes out of a port.

For example if you want to use port 1 as trunking port ( multiple vlan tagged networks on the same physical port ) , and you want to tag untagged traffic from ports 2,3,4 with vlan ids 2,3,4 you have to:

  • Assign ports 1,2 to VID 2
  • Assign ports 1,3 to VID 3
  • Assign ports 1,4 to VID 4
  • Set ports 2,3,4 to remove VLAN tags from outgoing packets
  • Set port 1 to add VLAN tag to outgoing packets
  • Set default VID for untagged traffic of port 2 to 2
  • Set default VID for untagged traffic of port 3 to 3
  • Set default VID for untagged traffic of port 4 to 4
With that configuration for example you will be able to connect 3 different networks to a single ethernet cable, which may be useful when you have a radio tower with multiple devices on it and only a single cable going to the ground equipment.

That's just the beginning, similiar mods can in most of the cases be done on all switches and probably with more features on newer ( gigabit ones ) switches.

You could also use a raspberry to manage the switch instead of an arduino to be able to work on it from ethernet with some nice web interface.