Home network DD-WRT Access Point with Firewall

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
paulmarku
DD-WRT Novice


Joined: 19 Apr 2021
Posts: 1

PostPosted: Mon Apr 19, 2021 9:07    Post subject: Home network DD-WRT Access Point with Firewall Reply with quote
I would like to isolate some devices on my home network from Internet access (inbound & outbound) and I cannot achieve this using my current setup:

1. Huawei GPON Terminal with ISP installed framework installed
1.1. Firewall settings blocked by ISP
1.2. This is the main device transforming the fiber optic signal

2. D-Link DIR-879 setup as Access Point connected via LAN cable to the GPON
2.1. Firewall settings disabled if not in router mode

I would like to know if i buy a new inexpensive router (DD-WRT supported ofc) and install DD-WRT, would i be able to achieve the following setup

1. Setup the new router as an access point, connected to the GPON with a LAN cable
1.1. Does the router have to support an "Access point" mode, i.e. with a phisical switch to toggle between router/extender/AP or can DD-WRT handle this via software ?

2. DD-WRT: Setup firewall rules to block internet access for certain IPs/MACs
2.1. The DD-WRT Access Point setup mentions to disable firewall rules (Normal Version (Same Subnet) => section Cool when running in AP mode
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12889
Location: Netherlands

PostPosted: Mon Apr 19, 2021 9:25    Post subject: Reply with quote
When running in WAP mode ( https://wiki.dd-wrt.com/wiki/index.php/Wireless_access_point ) the router is more or less acting a as dumb switch so traffic does not go through the router and thus the firewall is not hit.

It only works when you daisy chain the router so connect to the WAN of your secondary router where that router is on its own subnet.

There is an exception if you create an unbridged VAP on the WAP (or unbridge one of the ethernet ports) and put that on its own subnet then traffic will hit the firewall also but effectively you have the same situation i.e. a different subnet.

For some examples see my personal notes (slightly outdated) see paragraph about a VAP on a WAP

I transferred this thread to the appropriate Advanced networking forum.

To get the best out of DDWRT and the forum read the forum guidelines with helpful pointers:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

If you have not already read the forum guidelines, please do !!

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum