How to make Access control for a guest vlan

How to make Access control for a guest vlan

How to make Access control for a guest vlan
How to make Access control for a guest vlan
2025-07-13 21:00:16 - last edited 2025-07-21 09:38:26
Hardware Version: V1
Firmware Version: 1.4.2

I have 2 sites connected by an EAP215-Bridge pair.

                     SITE 1                                                                               SITE 2

ISP---ER7206--SG2008P ---- EAP215 = - - - - - - - - - - - - = EAP215 -- SG2008P----ER7206--ISP2

                               |    

                               |

                     EAP625-Outside

vlan      GW                          ER7206-1                           ER7206-2

  1     172.27.0.1                 172.27.0.2                            172.27.0.1

  2     192.168.0 1               192.168.0.1                          192.168.0.3

  3     192.168.1.1               192.168.1.2                          192.168.1.1

  5     172.29.0.1                 172.29.0.2                             172.29.0.1

vlan 1,2,3 access the internet   (1 & 3) go out ISP2     (2) goes out ISP1

Each VLAN only accesses the internet and other systems on the same vlan.

I am trying to setup a guest network vlan 5 can only access the DHCP server, the DNS server and the internet.

Would be going out ISP2 in the second second site.

I turn on "Guest network" in the WLAN config.  I still get DHCP working and a wired client on VLAN 5 can access the internet through ISP2

but a WiFi client cannot get to the internet.

Can I turn off "Guest network" and build an ACL that would allow this traffic.

Thank you for any assistance.
 

  0      
  0      
#1
Options
1 Accepted Solution
Re:How to make Access control for a guest vlan-Solution
2025-07-15 06:04:05 - last edited 2025-07-21 09:38:26

Hi  @MikeW1 

 

Typically, an EAP bridge is used to extend wireless networks to another site that lacks its own internet source. This doesn't quite match your current setup.

Since you already have two ISPs, why use an EAP bridge to connect these two networks? This configuration could cause issues as it would result in two DHCP servers operating on the same network.

If your goal is to enable communication between these two sites, we recommend establishing a VPN connection instead.

This is a guide:

How to Set up Site-to-Site Manual IPsec VPN Tunnels on Omada Gateway in Controller Mode

 

With proper installation, the guest network will function perfectly.

 

In summary, we strongly advise optimizing your network topology first.

Recommended Solution
  0  
  0  
#2
Options
1 Reply
Re:How to make Access control for a guest vlan-Solution
2025-07-15 06:04:05 - last edited 2025-07-21 09:38:26

Hi  @MikeW1 

 

Typically, an EAP bridge is used to extend wireless networks to another site that lacks its own internet source. This doesn't quite match your current setup.

Since you already have two ISPs, why use an EAP bridge to connect these two networks? This configuration could cause issues as it would result in two DHCP servers operating on the same network.

If your goal is to enable communication between these two sites, we recommend establishing a VPN connection instead.

This is a guide:

How to Set up Site-to-Site Manual IPsec VPN Tunnels on Omada Gateway in Controller Mode

 

With proper installation, the guest network will function perfectly.

 

In summary, we strongly advise optimizing your network topology first.

Recommended Solution
  0  
  0  
#2
Options