Deco X60 AP Mode Guest Network - Network Isolation Issue

Deco X60 AP Mode Guest Network - Network Isolation Issue
Deco X60 AP Mode Guest Network - Network Isolation Issue
2021-08-03 03:25:00 - last edited 2021-08-03 03:45:14
Model: Deco X60
Hardware Version: V2
Firmware Version: 1.5.1 Build 20210204 Rel. 50164

Hi Everyone,

 

I would like to ask for advice on isolating the guest network for Deco X60 in AP mode.

 

I am currently experiencing an issue where devices on my Main network are discoverable (Printers, Chromecast, etc.) by devices connected to the Guest network, though connections to them would fail (even pings). I do not want these devices to be discoverable, its confusing and would be one less indicator of network isolation failing (if ever it happens).

 

My network is presently constructed as follows:

 

ISP Modem -> Router -> Main Deco -> Switch -> Multiple Decos/Wired Devices.

 

I currently run an EdgeRouter-4 as my router (for failover WAN and SQM functionality).

 

My main intent is:
1. For all wired devices + main wifi network devices to be discoverable and accessible to each other.

2. For all guest network devices to be isolated from the main network devices and be unable to discover them

 

BONUS: 

1. Be unable to access router's configuration page from guest network (currently able to)

2. Use a separate DHCP server and firewall for guest network

 

Something I was looking into was using different VLANs to have separate DHCP servers and firewalls at the router for the main and guest network, but I'm not sure if the Deco in AP Mode fully supports this functionality. I believe Deco uses VLAN 1 for main network and VLAN 591 for guest network, but im not sure if this is visible to the Router and something it can take advantage of.

 

If anyone could advise me further on the solution I was looking into, or if a network topology change would help, or if its's not possible at all with the Deco on AP mode, or provide any other proposal, I would greatly appreciate it. Thank you very much.

2
2
#1
Options
2 Reply
Re:Deco X60 AP Mode Guest Network - Network Isolation Issue
2021-08-03 07:55:58

@PYellow 

Hi,

When Deco is on the access point mode, the guest network and host network are not separated by VLAN anymore and guest devices are only allowed to access the LAN IP of Deco.

If there is no client connected to the EdgeRouter-4 except for the main Deco and it is only used for failover WAN and SQM functionality, would you mind setting up Deco as wireless router mode as well?

0
0
#2
Options
Re:Deco X60 AP Mode Guest Network - Network Isolation Issue
2021-08-03 08:17:08 - last edited 2021-08-03 12:01:07

@TP-Link Thanks for the quick reply and the advice.

 

Regarding the first point, would you be able to point out how the network isolation is performed if its not through VLANs anymore in AP mode so that we could possibly explore some way to extend the recognition of the guest network all the way to the router?

 

Next point, its true that the devices connected to the guest network can only ping and access the config pages of the Deco units (+ the Router actually). But for some reason discovery of local devices still happen (for example my laptop connected to the guest network sees Printers, Chromecast, etc. connected to the main network), though attempts to connect to them fail. Ideally the discovery would not happen at all (and possibly block access to the config page of my main router).

 

Unfortunately I can't set the Deco to be in router mode also because that would cause me to have double NAT issues and that would be a much bigger problem.

 

Hope we can work something out. Thanks. :)

 

0
0
#3
Options