ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated

ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated

ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated
ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated
Tuesday
Model: Archer AX55  
Hardware Version:
Firmware Version:

Hello,

 

I have a main router that provides my local network 192.168.3.x and to which Starlink is also connected.

The ARCHER AX55 is also connected to this network in router mode.

I chose router mode because I want to set up an Easy Mesh network with the AX55.

 

The AX55 now provides a Wi-Fi network 192.168.7.x.

 

I have now set up a guest Wi-Fi network and an IoT Wi-Fi network on the AX55.

 

When I connect to these two networks with my mobile phone, I can still access my NAS devices, which are on the local network.

This shouldn't be possible.

 

Conversely, my NVR, which is connected to the local network, no longer sees my Wi-Fi cameras, even when I enter the correct IP address of the camera.

 

My questions are:

How can I isolate the guest and IoT Wi-Fi networks?

Is it possible to move the guest and IoT Wi-Fi networks to a different subsegment, e.g., 192.168.8.x and 192.168.9.x?

How can I then access my Wi-Fi cameras if they are connected to the IoT Wi-Fi network?

 

Thanks.

  0      
  0      
#1
Options
4 Reply
Re:ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated
Tuesday - last edited Tuesday

  @Markus7 

 

Hi,

 

On TP-Link routers the IoT network is just an additional Wi-Fi network with another SSID and password. It does not isolate anything by default.

 

If devices on the "Guest" network can access the local network, then verify the option "Allow guests to access your local network" hasn't been activated accidently.

 

Edit: Can you please specify more clearly whether client devices are connected to the local network of the Archer AX55 or the local network of the other main router?

As you can imagine, the Archer AX55 is only able to manage traffic between devices that are connected to its own local network.

 

  1  
  1  
#2
Options
Re:ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated
Tuesday

  @woozle 

 

Thanks for the feedback.

 

No, the "Allow guests to access your local network" option is NOT enabled.

And the clients on the guest Wi-Fi network can access my NAS, which is located on the main router's local network.

  0  
  0  
#3
Options
Re:ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated
Tuesday - last edited Tuesday

  @Markus7 

 

Ok, if the network layout is as in the picture below, then the behavior you see is as expected. The AX55 cannot somehow "instruct" the main router how to handle (e.g. isolate) certain traffic. 

One method of blocking known clients connected to the AX55 from accessing certain resources on its WAN side (i.e. in your case the main router's network) would be via the AX55's Parental Controls, like shown in the screenshot below. Of course this would only help for client devices whose MAC address you already know. And this might only block certain protocols, but not all.

 


By the way, what you mentioned earlier about the NVR on the main router not being able to access the cameras on the AX55 is also as expected. You would either need to setup some advanced port forwarding stuff or resort to "Access Point Mode" on the AX55. 

  0  
  0  
#4
Options
Re:ARCHER AX55 - Guest and IoT Wi-Fi Networks are not Isolated
Tuesday

  @woozle 

 

Thank you.

 

In this case, "Allow guests to access your local network" does not refer to the local network to which the AX55 is connected, but rather to the AX55's own local network, its four LAN ports.

 

What I also noticed is the fact that the AX55 does NOT forward the guest Wi-Fi and the IoT Wi-Fi via the easy mesh.

 

Under these circumstances, neither the guest Wi-Fi nor the IoT Wi-Fi makes sense to me.

  0  
  0  
#5
Options