Multiple Guest Accounts With DNSMasq DHCP Server?

Post new topic   Reply to topic    DD-WRT Forum Forum Index -> General Questions
Author Message
eginnc
DD-WRT Novice


Joined: 23 Jul 2017
Posts: 20

PostPosted: Sun Feb 10, 2019 22:44    Post subject: Multiple Guest Accounts With DNSMasq DHCP Server? Reply with quote
I'd like to have a guest VAP on both the 2.4 and 5 GHz radios. My Archer C7 (DD-WRT v3.0-r38535 std (01/31/19)) is running as a WAP and switch for a Roku and Ooma VOIP box, to which I lose connectivity when I replicate my 2.4 VAP setup for the 5GHz radio. Network isolation doesn't work on the VAP's either when I do this. To add the second VAP (ath1.1)

In DNSMasq I add the second interface (ath1.1 below):
Code:

interface=ath0.1
dhcp-option=ath0.1,3,10.10.12.1
dhcp-range=ath0.1,10.10.12.2,10.10.12.60,255.255.255.0,23h
interface=ath1.1
dhcp-option=ath1.1,3,10.10.13.1
dhcp-range=ath1.1,10.10.13.2,10.10.13.60,255.255.255.0,23h


And in my firewall I add the second iptables line:
Code:

iptables -I FORWARD -i ath0.1 -d `nvram get lan_ipaddr`/`nvram get lan_netmask` -m state --state NEW -j DROP
iptables -I FORWARD -i ath1.1 -d `nvram get lan_ipaddr`/`nvram get lan_netmask` -m state --state NEW -j DROP
iptables -t nat -I POSTROUTING -o br0 -j SNAT --to `nvram get lan_ipaddr`


And the 2.4 and 5 GHz VAP's are unbridged, with AP and Net isolation enabled. My WAN connection type is disabled, and the WAN port is assigned to the switch, and the Advanced Router operating mode is "Router". Security on the VAPs is WPA2 AES (just like the WAPs).

Am I trying to do something that doesn't work and never will? Anyone get this working that can tell me what I'm doing wrong? Thank you for any help!

_________________
TP-Link Archer C7v2(US)
TP-Link Archer C9v1
Trendnet TEW824DRU
Edgerouter X
Sponsor
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 4244
Location: Texas

PostPosted: Sun Feb 10, 2019 23:49    Post subject: Reply with quote
Do you also have ath0.1 IP as 10.10.12.1 and subnet mask 255.255.255.0 in its unbridged wireless settings
and the
ath1.1 IP 10.10.13.1 with netmask as 255.255.255.0 ??????
and you rebooted router?

that should work but I have never had a Archer C7 so don't know.....

EDIT:
don't know why you want 2 separate guest networks anyways ...
...if you want both radios for guest then leave both VAPs as bridged and in 'Networking' create br1 the network then assign ath0.1 & ath1.1 to it.
On the WAP still have to it put in Additional DNSMASq options same IP & netmask as br1 in 'Networking'
Be sure interface=br1...and so on Rolling Eyes
eginnc
DD-WRT Novice


Joined: 23 Jul 2017
Posts: 20

PostPosted: Tue Feb 12, 2019 1:33    Post subject: Reply with quote
Yes. I had ath[0.1 or 1.1] set up as 10.10.[12 or 13].1, unbridged, with 255.255.255.0 net mask in wireless settings. Might not have been a reboot in the mix [I think there was, but not sure], but I did save and then apply all settings and run the firewall commands explicitly before saving them to the firewall. I'll try again with a reboot and report back. Might be this weekend before I have time to mess around with it again.

You know, I never thought enough to realize I don't need two guest networks. I was thinking I needed to go the route I did, to utilize the network isolation check box instead of the "old" bridged network and lots of firewall rules approach to guest networks, but with two radios, yeah, cool - that makes a lot of sense. I'll experiment with that too this weekend [my kids have banned me from "fixing" the internet during the week when they have homework requiring it].

Thanks for the ideas mrjcd - I'm slowly learning enough to be dangerous! I couldn't have set up my last guest network without your help last time I hit the wall!

_________________
TP-Link Archer C7v2(US)
TP-Link Archer C9v1
Trendnet TEW824DRU
Edgerouter X
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum