What's new

RT-AC68U iptables query.

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

TomT

Regular Contributor
Hi
If I run my RT-AC68U as a wireless access point can I still use iptable rules? Can they be loaded from a script on startup ?

The AP, router, LAN devices and wireless clients are all in the same IP range.

Is it possible on the AP to block access for the wireless clients to all LAN devices except the router ?

Thanks
 
For your purpose, it sounds like "hotspot" mode, not access point mode.

Thanks,
Vanic
 
The firewall is disabled in AP mode...... so afraid not
 
Hi

Whats hotspot mode ?

Even though the firewall is disabled, doesn't iptables work ?

Thanks
 
Thanks for the reply. If I change the router back to its normal 'router' mode, I will have access to iptables.

Any issue running it like that but using it as an AP only ?
 
Thanks for the reply. If I change the router back to its normal 'router' mode, I will have access to iptables.

Any issue running it like that but using it as an AP only ?
Running a router behind another router will give you other issues ( such as double NAT).
I think the solution to your problem will be to leave your device in AP mode but put it on a separate VLAN ( configured on the main router) and isolate it from the rest of the LAN that way.... there are some threads on the forum that discuss this if you do a bit of searching around.
 
Thanks for the reply.
I have debated using a vlan for it, but it may not work for me as it will cause issues with dnla and multicast between the LAN and vlan.

I had hoped to keep it all on one LAN and restrict what devices can access each other.

When you set the router to AP mode it states "In this mode, the firewall, IP sharing, and NAT functions are disabled by default."

'By default' does that mean they can be enabled ?

Thanks
 
'By default' does that mean they can be enabled ?
No, not without writing your own custom scripts. If you're thinking you could "re-enable" iptables, you can't. As @tomsk pointed out, iptables manipulate traffic moving from one interface to another. In AP mode all the ports are connected to the same switch so the traffic isn't being routed anywhere.
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top