ER605 - Segregating Subnet for Guest access

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

ER605 - Segregating Subnet for Guest access

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
ER605 - Segregating Subnet for Guest access
ER605 - Segregating Subnet for Guest access
2022-11-20 19:56:45
Tags: #firewall
Model: ER605 (TL-R605)  
Hardware Version:
Firmware Version:

Evening everyone,

 

Trying to come up with a solution for a friend of mine with a guest house.  Had the classic thing where he was just sharing his home network connection with guests of a separate access point thinking wireless isolation was protecting was doing its job.  Off course as soon as that traffic hit the LAN they could see his network.  So the plan was to put a security device in the mix so we dont have to reinvent the wheel.  Have done this before with a transparent firewall and seeing will the ER605 be suitable for what i need.  So what i would like is:

 

AP----------ER605 (Dhcp Server 192.168.1.128/25)---------LAN Switch (all home client devices)--------Fibre Router (DHCP Server 192.168.1.1/25)

 

Would want a rule on the ER605 denying access to the 192.168.1.1/25 from the 192.168.1.128/25 range followed by a rule allowing the 192.168.1.128/25 out the internet.

 

Would this be possible?

 

Thanks in advance

 

 

  0      
  0      
#1
Options
1 Reply
Re:ER605 - Segregating Subnet for Guest access
2022-11-21 00:27:00

  @ceolnamara 

 

I don’t think it’s possible.

 

I would suggest buying another AP and disabling the WiFi on the Fiber Router.

 

A) Simple option, but with double NATting:

 

Home AP

|

Switch (all home client devices)

|

LAN (DHCP Server 192.168.1.1/24)

ER605

WAN

|

LAN (DHCP Server 192.168.0.1/24)-Fibre Router-WAN------Internet

|

Guest AP

 

B) More complex option:

 

Two VLANs on ER605, vlan1 (Home) and vlan2 (Guest). Access control rule blocking Guest from accessing Home. NATting on the Fiber Router disabled to avoid double NATting (recommended, but optional).

 

Home AP

|

Switch (all home client devices)

|

Vlan1 (DHCP Server 192.168.1.1/24)

ER605-WAN------LAN-Fibre Router-WAN------Internet

Vlan2 (DHCP Server 192.168.2.1/24)

|

Guest AP

Kris K
  0  
  0  
#2
Options