Access Restriction in switch mode?

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
jenom
DD-WRT Novice


Joined: 29 Jun 2011
Posts: 30

PostPosted: Wed Mar 17, 2021 17:18    Post subject: Access Restriction in switch mode? Reply with quote
I have setup a DDWRT device as a wired network switch: WAN disabled, LAN DHCP disabled, Wifi OFF
Just wondering if "Access Restriction" "Access Policy" " Deny Internet Access" section would still work?

If not, is there any way (like, with a command line script) to block a connected device in a specified time period ?
(I want to turn off an attached VOIP device at night)

Thank You !
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 13883
Location: Netherlands

PostPosted: Wed Mar 17, 2021 17:29    Post subject: Reply with quote
No and no

Your clients just bypass this switch, you have to block on the primary router

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
eibgrad
DD-WRT Guru


Joined: 18 Sep 2010
Posts: 9356

PostPosted: Wed Mar 17, 2021 19:34    Post subject: Reply with quote
Get yourself a wifi-enabled smart AC plug instead. I use them extensively and they work quite well for these kinds of purpose. No dependency on the router other than having internet access. Nothing beats having the device powered OFF when it comes to being sure it's denied access (to/from).

P.S. To show my own personal commitment to this approach, I'm so paranoid these days about having remote access enabled 24/7, I run my OpenVPN server on a separate router w/ a wifi-enabled smart AC plug so I can keep it OFF until I actually need it, i.e., on-demand. I do what I need to do, then shut it down. These smart plugs also serve as good replacements for WOL.

_________________
ddwrt-bind-static-routes-to-wan.sh (UPDATED! 11/12/24) * ddwrt-blacklist-domains.sh * ddwrt-dns-monitor.sh * ddwrt-ovpn-client-backup.sh * ddwrt-ovpn-client-killswitch.sh * ddwrt-ovpn-client-watchdog.sh * ddwrt-ovpn-server-watchdog.sh * ddwrt-ovpn-split-advanced.sh * ddwrt-ovpn-split-basic.sh * ddwrt-mount-usb-drives.sh * ddwrt-wol-port-forward.sh
schultzter
DD-WRT Novice


Joined: 29 Jul 2015
Posts: 11
Location: Montreal, QC

PostPosted: Fri Sep 06, 2024 3:32    Post subject: Reply with quote
egc wrote:
No and no

Your clients just bypass this switch, you have to block on the primary router


What?! You owe me a head of hair, I've torn all mine out trying to figure out why it isn't working!!!

My primary router is from the ISP and they removed Parental Controls from it.

Although it begs the question if WAN connection type is Disabled then the Access Restrictions page should be disabled - or at least a warning that it won't work!

_________________
Headed for the second star to the right and straight on 'til morning...
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 7063
Location: UK, London, just across the river..

PostPosted: Fri Sep 06, 2024 6:28    Post subject: Reply with quote
schultzter wrote:
egc wrote:
No and no

Your clients just bypass this switch, you have to block on the primary router


What?! You owe me a head of hair, I've torn all mine out trying to figure out why it isn't working!!!

My primary router is from the ISP and they removed Parental Controls from it.

Although it begs the question if WAN connection type is Disabled then the Access Restrictions page should be disabled - or at least a warning that it won't work!


Sadly, while using DDWRT firmware its suppose to have a basic knowledge on routers ...as in your case you left without hair.... Razz
The option you request is bound with some codding that will affect the firmware functionality or simply will just inflate the code...consider tons of different router supported with various hardware Cool

_________________
Atheros
TP-Link WR1043NDv2 -DD-WRT 62606 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 -DD-WRT 63257 GTW/SmDNS/DoT,AD-Blk,Forced DNS,AP&Net Isolation,x2VLAN,Vanilla
Netgear R7800 --DD-WRT 62606 Gateway/DNSCryptv2,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla,VPN cli
Netgear R9000 --DD-WRT 62606 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Dynalink DL-WRX36-DDWRT 62606
Broadcom
Netgear R7000 --DD-WRT 63257 GTW/DNScrypt-proxy2/AD-Block,IPset Firewall,Forced DNS,x4VLAN,VPN cli
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
eibgrad
DD-WRT Guru


Joined: 18 Sep 2010
Posts: 9356

PostPosted: Fri Sep 06, 2024 13:50    Post subject: Reply with quote
schultzter wrote:
Although it begs the question if WAN connection type is Disabled then the Access Restrictions page should be disabled - or at least a warning that it won't work!


If the router explicitly supported an AP mode, that would probably be the case.

https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=336991

(see post #3)

Instead, everything wrt AP mode is *implicit* and the result of YOU manually reconfiguring the router for those purposes. Yeah, it's confusing, esp. when an explicit AP mode is commonplace with other OEM and third-party firmware.

_________________
ddwrt-bind-static-routes-to-wan.sh (UPDATED! 11/12/24) * ddwrt-blacklist-domains.sh * ddwrt-dns-monitor.sh * ddwrt-ovpn-client-backup.sh * ddwrt-ovpn-client-killswitch.sh * ddwrt-ovpn-client-watchdog.sh * ddwrt-ovpn-server-watchdog.sh * ddwrt-ovpn-split-advanced.sh * ddwrt-ovpn-split-basic.sh * ddwrt-mount-usb-drives.sh * ddwrt-wol-port-forward.sh
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum