What's new

Guest Networks not isolated in AP mode?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

BeachBum

Regular Contributor
Hello, I have a Asus RT-3200 in AP mode connected to a pfSense router. I have a Guest Network turned on and it appears to not be isolated from the LAN. Connected clients can ping and mount shares from the LAN.

I see no option listed to isolate the Guest Network, and interestingly the description says '...restricts access to your local network.'

Firmware is Merlin 380.59_0

How can I isolate clients on the Guest Network?

SS1.png SS2.png
 
Guest isolation is not possible in AP mode, because the AP has no control over the traffic once it leaves the AP and reaches your pfsense firewall.
 
Might be possible to VLAN out the guest SSID, so at least the Guest Network remains isolated, not sure if AsusWRT can do this - and if not, I'm not sure it would be worth the effort, however this question has been asked many times over..

(Airports can support Guest Networks using VLAN 1003 when in Bridged Mode (AP mode in AsusWRT speak))

Within pfSense, you would still have to create the VLAN and the FW rules (WAN <-> VLAN1003), and setup the DHCP scope for VLAN1003.

OpenWRT is similar in this respect... and perhaps OpenWRT on the AP might be able to do more what you're looking for...
 
@RMerlin, can 380.59 create VLAN's? (in APmode)


I guess the only other way to achieve the isolation would to give each device a static mapping and then block them from the lan via firewall rules. That is a pia...
 
@RMerlin, can 380.59 create VLAN's? (in APmode)


I guess the only other way to achieve the isolation would to give each device a static mapping and then block them from the lan via firewall rules. That is a pia...

Not through the webui. You'll have to manually create everything yourself through scripting.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top