How to isolate ER605 VLANs?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

How to isolate ER605 VLANs?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
24 Reply
Re:How to isolate ER605 VLANs?
2023-03-14 19:01:47

  @mati2762 

I got it, had to add

Host 192.168.100.1
   KexAlgorithms +diffie-hellman-group1-sha1
   HostKeyAlgorithms +ssh-rsa

to /.ssh/config file .

Definitely not something that should be considered is normal though.

  0  
  0  
#12
Options
Re:How to isolate ER605 VLANs?
2023-03-14 19:03:44
I tried that command, which was the recommended way, and it wouldn't work. Had to add that line to config file.
  0  
  0  
#13
Options
Re:How to isolate ER605 VLANs?
2023-03-14 19:09:34

  @mati2762 

OK, I got in, but the directory you mentioned doesn't exist.

Did you have to do anything special to get it to show up?

I also noticed my firmware version is 13MB (Canada) and the US is 19MB. Maybe that would explain the missing files..   

 

  0  
  0  
#14
Options
Re:How to isolate ER605 VLANs?
2023-03-14 19:12:56

  @minks1 

 

show your output from command mount

  0  
  0  
#15
Options
Re:How to isolate ER605 VLANs?
2023-03-14 19:17:35

  @mati2762 

 

doesn't work. basically only LS works.. I am logged in as the user I created when I set up the router. The user is not root.. that's the only user I have though.

  0  
  0  
#16
Options
Re:How to isolate ER605 VLANs?
2023-03-14 19:21:32

  @minks1 

 

I got password from this post https://community.tp-link.com/en/business/forum/topic/598192

 

Meybe we have diffrent software, in my ER8411 is OpenWrt CC

  0  
  0  
#17
Options
Re:How to isolate ER605 VLANs?
2023-03-14 19:48:45

  @mati2762 

this one doesn't seem like openwrt at all, and if it was I'd be upset, cause the reason I bought it is because my Openwrt router just got hacked.. or a device got hacked which then hacked the Openwrt,.. either case, I've been having big router/security issues.. so I don't really trust Openwrt much. DD-wrt was running fine for a while until it started having strange DHCP issues, and flashing to Openwrt led straight to a virus going into compter as soon as I flashed it and connected to it.. I didn't verify the Openwrt download unfortunately, so I don't know how it happened.

 

Either way, I figured out how to block the vlans beween each other using IP Groups.. It's very tedious..

It will need a lot of lines, vlan1 to 2,3,4 , vlan2 to 1,3,4 etc. but it works!

Then I have to do vlan1,2,3,4 to ME with http service, and add 443 as https, because http is only 80.

that should do it, but tplink should've made this easier

  0  
  0  
#18
Options
Re:How to isolate ER605 VLANs?
2023-03-14 21:16:11

  @minks1 

 

I used a lot of devices with OpenWRT and i thing it is the good software. It is open source. Maybe your software not lived from official site or you not updated it when CVE is discovered.

 

If your solution will block vlan network to router ports please let me know.

  0  
  0  
#19
Options
Re:How to isolate ER605 VLANs?
2023-03-14 21:52:38

  @mati2762 

Yes, it blocks vlan to vlan and vlan to router using ME. I got it all done, and accidentally locked myself out of the GUI too. I think I have to do it all over again, withfactory reset. I wish SSH had a tool to remove entries from the firewall, but SSH is 100% useless from what I see..

 

Blocking ALL directions from VLAN3 to ME with service HTTP blocks all admin gui access.

I still added service type HTTPS with port 443 , and that closes the port too. But seelecting HTTP service actually does block all GUI Access on 80 and 443, although 443 is still open and doesn't respond. Pretty strange, because HTTP is just 80-80.

I had to block VLAN1 to 2 , VLAN1 to 3, VLAN1 to 4 , and do this for each one, to isolate them.

 

As long as an IP group is created for each VLAN, then it can be used in the firewall as the source/destination.

Lots of rules, but it works well.

 

 

  0  
  0  
#20
Options
Re:How to isolate ER605 VLANs?
2023-03-14 22:05:45

  @minks1 

 

thx for your answer, i will test it on next week :) 

  0  
  0  
#21
Options