Help: Setting up two isolated networks with AX72 and AX53

Help: Setting up two isolated networks with AX72 and AX53

Help: Setting up two isolated networks with AX72 and AX53
Help: Setting up two isolated networks with AX72 and AX53
17 hours ago
Model: Archer AX72   Archer AX53  
Hardware Version:
Firmware Version:

Hello community,

 

I need help configuring two completely isolated networks that can both access the internet. I've tried several configurations without success.

 

**My scenario:**

- **Main router**: TP-Link Archer AX72 connected directly to ISP

- **Secondary router**: TP-Link Archer AX53

- **ISP**: Provides a single public IP in bridge/transparent mode (doesn't act as router)

 

**Desired topology:**

```

ISP (bridge mode) → AX72 (192.168.1.x) → AX53 (192.168.2.x)

```

 

**Important constraints:**

1. **I cannot swap the routers** because the AX72 already has multiple port forwarding rules and other services configured that need direct access from the internet

2. The AX72 must remain as the main router handling PPPoE/DHCP connection with the ISP

 

**Objective:**

- Network A (AX72): 192.168.1.x - Main network with existing services

- Network B (AX53): 192.168.2.x - Secondary network completely isolated

- **Complete isolation**: Neither network should be able to "see" devices from the other

- Both networks must have full internet access

 

**What I've tried:**

- Connecting AX53's WAN port to AX72's LAN port

- Configuring different IP ranges on each router

- Enabling/disabling various security and firewall options

 

**Problems encountered:**

- Devices from network A can access devices from network B

- Can't find advanced firewall options to block traffic between subnets

- Isolation is not complete

 

**Specific questions:**

1. Do TP-Link Archer routers have firewall capabilities to block traffic between specific subnets?

2. Is there any specific configuration I should enable/disable to achieve complete isolation?

3. Is this possible with these models or do I need a router with more advanced capabilities?

 

**Additional technical information:**

- Updated firmware on both routers

- Current configuration: AX72 in router mode, AX53 in router mode (not AP)

- DHCP enabled on both routers with different ranges

 

I appreciate any guidance or experience you can share.

 

Best regards

 

 

File:
dad0987cc157423d9a924d004b5b03df.jpgDownload
  0      
  0      
#1
Options
2 Reply
Re:Help: Setting up two isolated networks with AX72 and AX53
10 hours ago
If you connect the AX53 by its WAN port to a LAN port of the AX72, and set the AX53 in router mode with its own DHCP range (for example 192.168.2.x), then normally devices on 192.168.1.x should not be able to reach 192.168.2.x because the NAT on the AX53 blocks incoming connections. The only traffic that should pass is internet traffic going out from 192.168.2.x. TP-Link Archer models like AX72 and AX53 don’t have advanced firewall rules to selectively block subnets, so you cannot fine-tune it inside the interface. For strict separation the simplest way is double NAT: AX72 does PPPoE and provides 192.168.1.x, AX53 does NAT again and provides 192.168.2.x. This way the two networks are effectively isolated, each with internet access. If you still see devices across networks, make sure the AX53 is really in router mode (not AP mode, not OneMesh), the cable goes into the WAN port of AX53, and both DHCP servers are active with different ranges. That setup should already give you the separation you want. If you need more control (like firewall rules between networks) you would need a more advanced router or firewall appliance, but for most cases double NAT works fine to isolate the two networks
Play Advanced
  0  
  0  
#2
Options
Re:Help: Setting up two isolated networks with AX72 and AX53
8 hours ago

  @Thenandouy 

 

Hi,

 

Does the Archer AX72 have the "Device Isolation" feature? (I don't have this model myself, so i can't check)

 

In case it does, then you could add the Archer AX53 as an isolated device on the Archer AX72 and see if that suits your needs.

 

  0  
  0  
#3
Options