What's new

Asus Merlin Question on LAN restrictions

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

junoonibhai

New Around Here
I am fairly new to Asus Merlin and while I browsed through a number of threads, I was not able to locate a solution to my predicament. I have some consumer devices (TV, Roku, etc.) connected via a network cable to my router. I would like to segment the network so the consumer devices cannot access the local LAN (almost like a guest segment). I know how to do this for the wireless network as it is pretty straightforward. I have set these devices up with a static IP to make it easier to identify them, but any guidance in sharing how to limit these devices from accessing local LAN would be much appreciated. Thanks in advance!
 
....VLANs, but that is not at all straightforward on this firmware and certainly not for the fainthearted.

Actually, I too was wary, but I found VLANs on the RT-AC68U is pretty trivial to set up (5 commands, not including Firewall rules) but to support wired VLANs naturally requires your infrastructure to support the VLAN traffic.

I also read the article regarding IoT isolation and despite the scaremongering journalistic articles warning that potentially "my toaster/fridge" could end up killing me if I didn't do something about it, I find other priorities in life take precendence, although the following story :

e.g. http://www.networkworld.com/article...-smart-light-bulbs-and-5-000-iot-devices.html made me smile! :D

So over the last few weeks (when I'm 'bored') I've been having a little tinker with IoT VLANs.

I have VLANS 5,10,15,20 & 200 daisy chained, currently off port 4 on the router to different rooms via:
Code:
1 x Netgear GS108PEv3 8-port switch (4 POE ports)
1 x Netgear GS-108Ev3 8-port switch
1 x Netgear GS-108Ev2 8-Port switch
3 x TP-Link TL-SG2008 8-Port switches

VLAN 200 is bridged (via br1) to Guest 2.4GHz Client 3 to VPN Client 1 - surprised myself when I plugged in a laptop to a VLAN200 port and https://ipleak.net showed I was in NY! :cool:

I have the BG Hive Hub isolated, and it seems fine, and so too the Samsung TV - I picked the easiest first! ;)
NOTE: Obviously (by convention) each VLAN has its own subnet and I chose to ensure they use external DNS i.e. OpenDNS/Google hybrid.

I haven't yet isolated the Wifi stuff - LIFX lights,ROKU,Chromecast and Echo dots etc. - basically not sure how best to control their management apps.:confused:

So technically IoT isolation does work on Asus routers, it's just a headache (for me at least) designing the topology and ultimately managing the devices on the VLANs - clearly they don't show up in the Network map, so I guess that APs will need to be installed or use RaspberryPis etc.? as management portals.

Suffice to say, I agree with your answer that SSID/VLANs may be the solution for the OP (unless a few simple firewall rules would suffice), but for home use it could be expensive - both in time and money. :eek:

P.S. I found this article which helped me to see how others were using VLANs in the home:
https://nguvu.org/pfsense/pfsense-router-on-a-stick-with-netgear-gs108/
 
Last edited:
Is there some way of having the built in network map show available hosts from all vlans/bridges rather than just the primary bro?
 
guys, gotta a problem , i have installed for about a week merlin 380.68.4 n my asus rt ac3200 , today i rebooted it and installed stock fw cause i was getting pissed , i accesed the router , downloaded syslog and install merlin again. Now i can.t access wired connection , wifi connection , deleted all cache on laptop, restarted and nothing. this is my log.
 
guys, gotta a problem , i have installed for about a week merlin 380.68.4 n my asus rt ac3200 , today i rebooted it and installed stock fw cause i was getting pissed , i accesed the router , downloaded syslog and install merlin again. Now i can.t access wired connection , wifi connection , deleted all cache on laptop, restarted and nothing. this is my log.
Create a new thread. Your problem has nothing to do with this topic.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top