Isolating main network.
Isolating main network.
Hi,
I'm trying to give guests in 4 separate lodges access to the internet via starlink which is on my house, so make sure they don't have access to main network. See below for an of current setup.
I guess I'm going to have to put Starlink router into bypass mode and get a new router and switches. Could someone advise what router and switches would be required. Thanks.
The starlink router is wired into 8 port switch and then also plugged into that switch is one of the cpe210 that is configured as ap and then it connects via ptp to client CPE from that a cable is wired to another 8 port switch, a WR841N which is on the lodge is then connected via ethernet cable from that switch.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
@AndyHarrowven Will they need access to wired connection or just wireless? If only wireless, you can just provide them access to the Guest Network feature on the EAPs and the WR841N. You can even get this done with the Omada Cloud Essentials controller at no additional cost. If you have more details such as network speed/bandwidth requirements as well as expected number of clients, I can assist even further.
- Copy Link
- Report Inappropriate Content
Only need wireless connection, tried setting up guest network but it didn't work. I could still enter the IP address of the CPE and also the starlink router IP and it brings up the webpage for the device.
- Copy Link
- Report Inappropriate Content
@AndyHarrowven Double checking the model of the router again, it looks like that device falls under Home Networking; you might get better results in the Home Networking end of the forums. However, if you have Omada EAPs in the system (aside from the CPEs) you can configure a Guest Network for those through the Omada Controller or Omada App.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Guest mode wont work because the starlink is the WAN ip and therefore beyond the scope of guest mode blocking (which only blocks within the same vlan and gateway IP) not beyond to WAN otherwise internet wouldnt work since that traffic will be hopped by the gateway
You probably need a basic omada gateway where you can specifically block a LAN>WAN IP with gateway ACLs and then use vlan isolation on the LAN side for the guest network
- Copy Link
- Report Inappropriate Content
Ok thanks, any suggestions on what would be a good gateway to go for. I believe I would also need a managed switch?
So I would put Starlink router in bypass mode and then add omada gateway and replace my existing switch?
- Copy Link
- Report Inappropriate Content
ER7206 v2, SG2008P switch and a couple Omada access points, maybe EAP650 Outdoor would be fine for this use
When you block the starlink IP, its important to only block its GUI ports (22,80,443 would probably be sufficient) you dont want to just block the whole IP
If you envisage the network growing beyond this in the future, get yourself a controller to, otherwise a little network like this would be fine in standalone mode
- Copy Link
- Report Inappropriate Content
So I would need to replace the WR481N with the EAP?
What about the CPE210s I'm using as a ptp
The AP is wired to the switch that the starlink is currently connected to and then the client CPE that is in a remote garage is then wired to a central box with another switch in it. 4 separate cables then run to individual lodges that I'm trying to get internet access to.
Cheers for your help so far, I got basic network knowledge so this vlan stuff is going to be a bit of a learning curve.
- Copy Link
- Report Inappropriate Content
Can you draw a rough sketch of what the current design layout is ? we can advise better with that
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 117
Replies: 11
Voters 0
No one has voted for it yet.
