Archer ax1500 device isolation not working

Archer ax1500 device isolation not working

Archer ax1500 device isolation not working
Archer ax1500 device isolation not working
2024-08-17 22:58:05 - last edited 3 weeks ago
Model: Archer AX1500  
Hardware Version: V1
Firmware Version: 1.3.10 Build 20240130 Rel. 77367(4555)

I have a weird situation where 2 issues are combined and not working. is not nice.

 

my setup is 2 archer ax1500 in easymesh over wireless backhaul (ethernet backhaul makes no difference)

 

1- device isolation in the main netowkr does not work no matter what I do.

2- devices in the guest network with allow access to local network devices can see also my wireless devices in the main network. Local network should be only LAN port devices. why does this feature even exist if it just bridges the 2 networks and not the interfaces. (poor choice)

3- 1 specific device cannot connect to the main network when 5ghz is enabled (it is a N/AC device an android tv official device) hence my use of the guest network as 2.4 only with allow local network access enabled. (I have no idea whats happening here. I tried an archer A6 and the device conencts to the N/AC 5ghz networks but cannot in any way negotiate 5ghz connectivity with the archer ax1500)

 

  0      
  0      
#1
Options
4 Reply
Re:Archer ax1500 device isolation not working
2024-08-18 00:14:17

 for any readers of this undocumented buggy features.

 

if you use ip address reservation. any devices in the "main network" either with static or reserved ips are always shared to the guest network.
I assume the address separation is gone all at the dhcp level and is buggy as hell.

 

if you have any servers or nas etc with static ips or iot devices u want to reserve.

 

1- DO NOT enable guest allow network as these are shared by default.

2- AP isolation on the main network is wonky it only prevents the wireless devices provisioned with dhcp to not see other devices provisioned with dhcp. it will always show the static and reserved ip sets regardless. For my use case I left it enabled and it just prevented access within the only 2 devices in the main network with dynamic dhcp allocation.

IMO this is a lame way to implement network isolation and firewall ruling.
At least it could be better documented in more complex scenarios and not let users to discover and think its a bug.

Although it looks and feels like a buggy implementation while is not.
 

  0  
  0  
#2
Options
Re:Archer ax1500 device isolation not working
3 weeks ago

  @sbearg 

 

Hi, thanks for posting question on our community.

1. As this guide says, while isolated, the devices can still access the internet and are able to communicate with other isolated devices. However, isolated devices cannot transfer data with devices on your home network, including managing gateway devices, accessing USB devices, etc. So you may share more details about how it does not work, then we can get better understanding about your problem.

2. For Easymesh network, currently guest network can not synchronize to satellite router. On your main router, did you enable "Allow guests to access your local network"?  "Local network should be only LAN port devices. "--Sorry, I am afraid it is only your understanding. All wireless and wired connection to main router belongs to local network. 

3. Can I confirm whether you use Archer A6 to replace main Archer AX1500? Please check whether their 5GHz wirless settings are totally the same.

Thanks for your cooperation~

 

  0  
  0  
#3
Options
Re:Archer ax1500 device isolation not working
a week ago
Marvin, learn how to read.
  0  
  0  
#4
Options
Re:Archer ax1500 device isolation not working
a week ago - last edited a week ago

what a secure network looks like is

 

1: devices in LAN ports

2: devices in main-wifi

3: devices in guest-wifi

 

devices in lan can access internet and can see main and guest wifi devices.

devices in main-wifi cannot see devices in guest-wifi but can access lan devices such as nas or dns server.

devices in guest-wifi can access lan devices such as a nas or dns server and internet but cannot see main-wifi devices.

 

this has eternally been impossible in tplink routers. always one side does not work and leads to compromise. if you enable in guest that devices have access to local they can see the wifi devices in the main wifi network. allowing my guest for example to scan my network and discover my phone when they should only discover my nas.

  0  
  0  
#5
Options

Information

Helpful: 0

Views: 125

Replies: 4

Related Articles