R7000 tagged VLAN for Guest WiFi

Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Broadcom SoC based Hardware
Author Message
RockNLol
DD-WRT Novice


Joined: 21 Jan 2016
Posts: 11

PostPosted: Sun May 26, 2019 19:47    Post subject: R7000 tagged VLAN for Guest WiFi Reply with quote
hi,
since I did not have any luck with Guest-WiFi on the same LAN as private WiFi just with firewall rules, and did not get any answers on the German part of this forum I'll try it again here:

I'm trying to set up a guest-WiFi on wl0.1 of my Netgear R7000 running r37015 kongac and routing its traffic to tagged VLAN3 on the same network-port as my normal WiFi, which should be on VLAN1.

The R7000 is only an access point, my gateway is a opnsense firewall which hosts a dhcp-server on VLAN3, so this is not needed on the R7000. The R7000s only connected network port is the WAN-port (because I cannot switch off the annoying LAN-LEDs with the startup script).

What I did so far is create the wl0.1 as bridged network and setup the encryption. Then on setup > vlans I ticked "tagged" for the WAN-Port and "VLAN 3". Finally I created a new network bridge br1 under setup > networks, assigned an appropriate IP address and added wl0.1 and vlan3 to it.

When connected to the R7000 via ssh i can ping the firewall on its VLAN3-IP and vice versa. But if I try to connect a WiFi-client to the guest wifi it fails. Windows for example simply says "Connection not possible". Also with static IP configuration on the client side it won't connect, so there is no DHCP issue here. Also if i enter an incorrect password on purpose the error message is different, so the encryption/password shouldn't be the issue here as well.

Does anybody know what I have to configure exactly to get this to work? I'll attach my current settings here, mind that they are in German.

thanks in advance!



DD-WRT_NETWORKING.PNG
 Description:
 Filesize:  26.48 KB
 Viewed:  173 Time(s)

DD-WRT_NETWORKING.PNG



DD-WRT_WLAN.PNG
 Description:
 Filesize:  14.49 KB
 Viewed:  173 Time(s)

DD-WRT_WLAN.PNG



DD-WRT_VLAN.PNG
 Description:
 Filesize:  34.5 KB
 Viewed:  173 Time(s)

DD-WRT_VLAN.PNG




Last edited by RockNLol on Sun May 26, 2019 19:53; edited 1 time in total
Sponsor
RockNLol
DD-WRT Novice


Joined: 21 Jan 2016
Posts: 11

PostPosted: Sun May 26, 2019 19:48    Post subject: Reply with quote
attachment 4:


DD-WRT_NETWORKING2.PNG
 Description:
 Filesize:  17.42 KB
 Viewed:  172 Time(s)

DD-WRT_NETWORKING2.PNG


RockNLol
DD-WRT Novice


Joined: 21 Jan 2016
Posts: 11

PostPosted: Mon May 27, 2019 16:33    Post subject: Reply with quote
hi,
I tried to redo everything and test it step by step. When I create the vap it works fine until I reassign wl0.1 from the default br0 to br1. It then immediately stops working.
Do I have to do something with the mac-addresses?
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 3403
Location: Netherlands

PostPosted: Mon May 27, 2019 16:49    Post subject: Reply with quote
Why not set the router up as a Wireless Access point in the first place?
See: https://wiki.dd-wrt.com/wiki/index.php/Wireless_Access_Point

Then create a VAP and unbridge that and put a DHCP server on wl0.1 you do not need a br1.

When you setup a VAP on a WAP you need a special firewall rule to NAT the traffic on the LAN see my attached notes (or set a static route)

If you want to have one wired port on the guest network only then you have to create a bridge and set the wired port on its own vlan and attach it to the bridge and keep the VAP bridged and attach it to br1.

Do not have the wired ports on more than one vlan (I know you can have a trunk and tagging etcetera but for this setup it seems overly complicated)



DDWRT Virtual Access Point Public.doc
 Description:

Download
 Filename:  DDWRT Virtual Access Point Public.doc
 Filesize:  254.5 KB
 Downloaded:  9 Time(s)


_________________
Routers: Netgear R6400v1, Netgear R6400v2, Linksys EA6900 (XvortexCFE), Linksys E2000 (converted WRT320N), WRT54GS v1.
Install guide Linksys EA6900: http://www.dd-wrt.com/phpBB2/viewtopic.php?t=291230
Simple PBR (Policy Based Routing) script: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=318662
Install guide R6400v2:http://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
OpenVPN server setup guide:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=318795
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 4944
Location: Akershus, Norway

PostPosted: Tue May 28, 2019 7:15    Post subject: Reply with quote
What is the output of?

nvram show | grep vlan.*ports

You tag the port by adding a "t" after the port number.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum