What's new

How to block LAN access for cascaded router?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Medrey

New Around Here
Hi,

I have an AC86U (running Asuswrt-Merlin) that I use as a guest/VPN network router. It's WAN port is connected to my private network via a switch that is connected to my ISP's router/modem. NAT and DHCP is enabled on both routers. As it stands now, the guest network (192.168.1.x) on the AC86U can see and connect to devices on the private network (192.168.178.x) but not the other way around.

I don't want guests to be able to reach addresses on my private network at all (ideally not even the admin interface at 192.168.178.1) but still be able to connect to the internet. I set up client isolation between guests on the UniFi APs, but I'm not sure how to do the isolation between the private and guest subnets without affecting internet connectivity on the ASUS router. Any pointers?

Just for information, my network currently looks like this. The wireless radios on both wireless routers are turned off. Everything connects to the UniFi APs, either to the private or to the guest network SSID.
topo.jpeg
 
Last edited:
Use the Network Services Filter on the Asus. Block access to destination 192.168.178.0/24 for TCP and UDP.
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top