WhyNetworkAtAll
Occasional Visitor
Here is my network
Main router @ 192.168.1.1 : Asuswrt-Merlin 384.17 on an RT-AC68U
DNS1 on PiHole 5.x @ 192.168.1.9 : RaspberryPi 4
DNS2 on PiHole 5.x @ 192.168.1.8 : OrangePi Zero (fallback DNS)
WiFi: 1x main network (2.4G + 5G) and two guest networks ("IoT" and "Visitors", on both 2.4G and 5G). I am keeping the guest networks isolated from the intranet.
I really like PiHole 5.x's ability to apply different rules to different devices (e.g. more aggressive filtering on children's devices, less aggressive filtering on everything). I want the PiHole perform DHCP duties too but when I do that, my guest WiFi devices are unable to connect to the PiHole DHCP service and consequently "lose internet".
Is there a way I can configure my main router to permit only DNS and DHCP requests between guest and intranet without losing the greater isolation between them? I'm not sure since those are IP services while my link level seems to be setup to disallow any traffic on the forward chain.
PS: I also have another AC68U on latest Asus stock firmware as an AiMesh node working just fine but I think it's not relevant to this issue.
Main router @ 192.168.1.1 : Asuswrt-Merlin 384.17 on an RT-AC68U
DNS1 on PiHole 5.x @ 192.168.1.9 : RaspberryPi 4
DNS2 on PiHole 5.x @ 192.168.1.8 : OrangePi Zero (fallback DNS)
WiFi: 1x main network (2.4G + 5G) and two guest networks ("IoT" and "Visitors", on both 2.4G and 5G). I am keeping the guest networks isolated from the intranet.
I really like PiHole 5.x's ability to apply different rules to different devices (e.g. more aggressive filtering on children's devices, less aggressive filtering on everything). I want the PiHole perform DHCP duties too but when I do that, my guest WiFi devices are unable to connect to the PiHole DHCP service and consequently "lose internet".
Is there a way I can configure my main router to permit only DNS and DHCP requests between guest and intranet without losing the greater isolation between them? I'm not sure since those are IP services while my link level seems to be setup to disallow any traffic on the forward chain.
Code:
admin@router:/# ebtables -L
Bridge table: filter
Bridge chain: INPUT, entries: 0, policy: ACCEPT
Bridge chain: FORWARD, entries: 8, policy: ACCEPT
-i wl0.1 -j DROP
-o wl0.1 -j DROP
-i wl0.2 -j DROP
-o wl0.2 -j DROP
-i wl1.1 -j DROP
-o wl1.1 -j DROP
-i wl1.2 -j DROP
-o wl1.2 -j DROP
Bridge chain: OUTPUT, entries: 0, policy: ACCEPT
admin@router:/#
PS: I also have another AC68U on latest Asus stock firmware as an AiMesh node working just fine but I think it's not relevant to this issue.