AX5400 Allow lan to see 1 device on guest network

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

AX5400 Allow lan to see 1 device on guest network

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
AX5400 Allow lan to see 1 device on guest network
AX5400 Allow lan to see 1 device on guest network
2021-06-02 16:23:16
Model: Archer AX73  
Hardware Version: V1
Firmware Version: 1.0.1 Build 20200908 rel.69273(5553)

What's with the naming convention?  Is it AX5400 or AX73???

 

Anyhow, I just installed this and seems to work well and has better coverage than my previous router, a Linksys WRT-1900ACS.  I was running OpenWRT on the Linksys and knew I wouldn't have nearly the number of configuration options with this unit, but I'm a little disappointed at the lack of options or even a configurable firewall.

 

On the LInksys running OpenWRT, I had three networks and SSIDs configured.  One for my computers, one for my IOT devices and one for guest access.  The AX5400 has no such options, all I have is a guest network.  Since I rarely used the guest network, I'm using that for my IOT devices to keep them isolated from my computers, NAS, etc.

 

I can live without a guest network but I have a couple of devices on the "IOT" (guest) network that I need to see from the local network.  Short of enabling "Allow guests to access  your local network" is there any way to accomplish this?  What I really need is a "allow local network to access your guest network" option.  I want a computer on my local network to open a connection to a device on the guest network, but not allow the device on the guest network to initiate a connection to anything on the local network.

 

 

Any way to do this?

 

  2      
  2      
#1
Options
4 Reply
Re:AX5400 Allow lan to see 1 device on guest network
2021-06-03 08:18:57

@Don1220 

 

The options you can see is what you can configure on the AX73, there is no such option like only "allow local network to access your guest network".

 

Just out of curiosity, is there a specific reason why you want to isolate those IoT devices from the main network?

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer AX55V2 Supports WireGuard VPN, EasyMesh Ethernet Backhaul, IoT Network, Speed Limit,and More If you found a post or response helpful, please click Helpful (arrow pointing upward icon). If you are the author of a topic, remember to mark a helpful reply as the "Recommended Solution" (star icon) so that others can benefit from it.
  0  
  0  
#2
Options
Re:AX5400 Allow lan to see 1 device on guest network
2021-06-04 15:50:25 - last edited 2021-06-04 15:51:38

 

Kevin_Z wrote

@Don1220 

 

Just out of curiosity, is there a specific reason why you want to isolate those IoT devices from the main network?

@Kevin_Z 

 

Sure.  Same reason people set up guest networks.  My main network is limited to my computers and NAS, and I've taken the appropriate steps to try and prevent viruses and such from getting at those devices.

 

IOT devices are completely untrustworthy. Many if not most phone home and who knows to where, and what data they're trying to collect from your network. IOT devices and their cloud services are hacked on a regular basis. It's one thing if someone hacks into a camera or doorbell for example; they're not going to see anything terribly interesting.  It's quite another for such a device to have network access to my computers and NAS.  I don't have the time to babysit and block suspicious connections or DNS requests, or set up complex firewall rules to keep them isolated (which you can't even do with this router!), so a separate network keeps them isolated from the main network, and from each other. 

 

Unfortunately, I have to use the guest network for this purpose.  With DD-WRT and OpenWRT you can create as many SSIDs and networks as you want, but there's no DD-WRT or OpenWRT compatible WiFi 6 routers at present.

 

This is not an uncommon setup, and a savvy vendor would add a the ability to create an "Iot" network without having to sacrifice the guest network.  Would be a good marketing feature, I'd think.  Virtually every wifi router can create a guest network; it should be a fairly trivial programming task to allow the creation of a third.

  1  
  1  
#3
Options
Re:AX5400 Allow lan to see 1 device on guest network
2021-06-07 02:28:38

@Don1220 

 

Thanks for the exhaustive explanation. We will surely keep an eye on this kind of request, and feedback to the developers to evaluate if this can be achieved in the future.

Nice to Meet You in Our TP-Link Community. Check Out the Latest Posts: Connect TP-Link Archer BE550 to Germany's DS-Lite (Dual Stack Lite) Internet via WAN Archer GE550 - BE9300 Tri-Band Wi-Fi 7 Gaming Router EasyMesh Is Available When Wi-Fi Routers Work in AP Mode as A Controller. Archer AX55V2 Supports WireGuard VPN, EasyMesh Ethernet Backhaul, IoT Network, Speed Limit,and More If you found a post or response helpful, please click Helpful (arrow pointing upward icon). If you are the author of a topic, remember to mark a helpful reply as the "Recommended Solution" (star icon) so that others can benefit from it.
  0  
  0  
#4
Options
Re:AX5400 Allow lan to see 1 device on guest network
2021-06-25 22:06:27 - last edited 2021-06-25 22:07:03

Thanks for taking this request seriously!

 

I came across this post looking for the same solution and signed up for an account just to comment.  =)

 

I would love to have the ability to split up my network and dedicate a VLAN to guest/IoT devices, and manually add routes between them.  The three use cases I have right now are:

 

1.  I would like to keep my work laptop on my guest network and still have RDP access from my main machine.

 

2.  I would like to keep IoT devices on my guest network and be able to cast from my computer or phone without joining to the guest network first.

 

3.  I would like to put my Oculus VR on my guest network and still have access to PCVR gaming.

 

 

Thanks again!

  1  
  1  
#5
Options