Sound like a good plan to me. Let us know how it works in real life.
Guest Network Pro is currently functioning on my AiMesh setup and my nodes are RT-BE58Us and my main router is an RT-AX88U Pro. If they forgot to mention the RT-BE58U as compatible what other products, if any, did they forget in their list?
For Guest Network Pro compatibility I would stick to the official list here:
RT-BE58U is in what Asus calls Smart Home Master products line category:
I did some more testing and have some good news... well, good for
me at least...
To recap, I originally wanted all IoT devices (Alexa, cameras, smart switches, Govee, etc.) to be on their own guest network VLAN but could never get it working with my current hardware. In the end, I was able to solve the issue and separate traffic from those devices and my local computers by creating some firewall rules on my pfSense firewall.
But I still wanted to have basic guest network functionality when friends and family do come over (because apparently Verizon's signal is crap in my house and they want to use my WiFi -- I'm personally on T-Mobile).
This especially hit me hard this past weekend because we had some neighbors over and I was forced to connect them to my
main SSID due to lack of a Guest Network. They were on iPhones and somehow they managed to figure out my SSID's password (which I've since changed)!!! I'm not an iPhone user, so I have no idea how they figured it out.
Anyway, my "a-ha" moment earlier today was to simply enable Guest Network Pro on
only my main
RT-AX86 Pro router in my office, which is directly above the family room where my guests tend to hang out.
This is what I did...
- Enable the unused Ethernet interface on my pfSense firewall (named OPT2) with a static IP of 192.168.3.1.
- Create a new VLAN52 interface in pfSense and assign it to the OPT2 interface with an IP range of 192.168.52.1/24.
- Create a new DHCP server on the VLAN52 interface with a range of 192.168.52.101 to 192.168.52.199.
- Connect a short Ethernet cable from the OPT2 port on the pfSense to LAN Port 4 on the RT-AX86U Pro.
- On the Asus GUI, create a new Guest Network on VLAN 52, but ONLY for the RT-AX86U Pro itself (since my other two nodes don't support VLANs).
- Create a firewall rule on the pfSense VLAN52 interface to allow traffic from any IP on the subnet to the local gateway 192.168.52.1.
- Create another firewall rule on the pfSense VLAN52 interface to allow traffic from any IP to any IP except local private networks (192.168.0.0/16).
And that was all!
Using my phone, I was able to connect to the new guest network running solely on the
RT-AX86U Pro, get an IP of
192.168.52.101, and reach the internet.
I then went downstairs and checked signal strength and latency:
Looks good to me!
Then I ran a speedtest:
So in conclusion, this will work for me. My IoT devices can't mess with my main network and I have guest network functionality, albeit on just my main router -- AND I didn't have to spend any money (I'm retired, so I'm on a limited income).
If you got this far, then cheers!
- Dave