What's new

VLAN and Guest Network possible?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

pyrodex

New Around Here
I currently have my RT-AC66U running the latest version of Merlin and it has my normal wireless networks but I wanted to offer a guest network with a different name and different IP range. My RT-AC66U is in pure AP mode right now and that is how I plan to keep it. Here is my current setup:

Cable Modem-->pfSense-->Procurve 2810-->RT-AC66U (LAN Port 1 & 4)

I also have other network devices off the procurve that all work with no problem of course.

I have my RT-AC66U LAN Port 1 on the normal LAN VLAN 2 and all the known clients get 192.168.1X.0/24 and that DHCP is issued via pfSense.
I setup LAN Port 4 on the RT-AC66U in VLAN 3 along with another port on the firewall and another port to test with on the switch. This new setup is now the "guest" network and I've carved out a new 192.168.21X.0/24 on pfSense and tested this out using a hard wired connection in VLAN 3 to ensure it is working as expected.

I have configured my RT-AC66U with a guest network using WPA2 Personal and it created wl0.1 and wl1.1 on the device and I've tried to create a new bridge as br1 with those devices in it on VLAN 3. I've tagged VLAN 3 on LAN Port 4 and I am able to ping devices on VLAN 3 such as the firewall, switch, and a hardwired client but when the wireless clients go to get DHCP on the new guest network they are unable to authenticate and also unable to get DHCP.

Anyone have this type of configuration working where I can understand the setup and see if this is even possible for what I wanted with this device?
 
Anyone have this type of configuration working where I can understand the setup and see if this is even possible for what I wanted with this device?
I understand what you are trying to setup but what is the goal/motivation behind that ?
 
I understand what you are trying to setup but what is the goal/motivation behind that ?

We entertain a good deal and have family staying over so I wanted a network just for them. I also want to protect myself from my guest's activities so I would put up a filter to allow web traffic but reject malicious traffic and protect my home network from them. Eventually I would do a Kids' net when we have little ones so I can put filters on their network and using pfSense segment them off from the general traffic of my media servers, unprotected web traffic, etc.

Ideally my wife and I and my servers, cameras, etc would be 192.168.1.0/24 and then guest would 192.168.2.0/24.
 
We entertain a good deal and have family staying over so I wanted a network just for them. I also want to protect myself from my guest's activities so I would put up a filter to allow web traffic but reject malicious traffic and protect my home network from them. Eventually I would do a Kids' net when we have little ones so I can put filters on their network and using pfSense segment them off from the general traffic of my media servers, unprotected web traffic, etc.
[...]
Could it be a good starting point if you setup a Guest Network using the built in feature ? You can define many guest SSID with no access to the lan (intranet) and with time frames, for 2.4 or 5 Ghz.
 

Attachments

  • asus-7.jpg
    asus-7.jpg
    58.5 KB · Views: 1,144
Last edited:

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top