How to setup AP isolation from LAN to WLAN?

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Author Message
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Fri Apr 30, 2010 15:06    Post subject: How to setup AP isolation from LAN to WLAN? Reply with quote
Hi, i would like to setup my network on my Caffe shop.. i have links router WRT56G and a WAP54G v3,1 AP. so...

I have my computer on the router and from port 4 connect to the AP. on the AP i have the dd-wrt software and activated on thw wireless the AP isolation . on the wireless works fine but the wired computers are visible Sad what can i do?

thx


Last edited by olivers on Sun May 02, 2010 7:56; edited 1 time in total
Sponsor
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Fri Apr 30, 2010 16:36    Post subject: Reply with quote
http://www.dd-wrt.com/wiki/index.php/Separate_LAN_and_WLAN
_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Fri Apr 30, 2010 17:46    Post subject: Reply with quote
thank you! Now i have the lan and wlan extra . But the internet not working on wlan Sad and the lan i cant test because there is only 1 port Smile the WAN .

my MIMO route have the adress: 192.168.1.1 the dd-wrt router ( AP ) have the adress 192.168.1.2 The WAN is on auto.
Wlan 192.168.2.1

what is wrong?


big thx
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Fri Apr 30, 2010 18:42    Post subject: Reply with quote
Have someone a backup file to download for config? it would be realy cool Sad
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Sun May 02, 2010 7:46    Post subject: Reply with quote
I read the Separate LAN and WLAN and WLAN separate from LAN, with independent DHCP . But still not works for me Sad i can get the ip for Wlan. Should i disable the dhcp on the lan?

could someone help me please?`

big thx
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Sun May 02, 2010 17:22    Post subject: Reply with quote
ok, here are some pictures

Last edited by olivers on Thu May 06, 2010 11:33; edited 1 time in total
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Sun May 02, 2010 17:23    Post subject: Reply with quote
and 3 more

Last edited by olivers on Thu May 06, 2010 11:34; edited 1 time in total
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Sun May 02, 2010 17:24    Post subject: Reply with quote
and the last one .

Last edited by olivers on Thu May 06, 2010 11:33; edited 1 time in total
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Sun May 02, 2010 18:55    Post subject: Reply with quote
Sometimes unbridging the WLAN doesn't work right and you just need to add it to a new bridge interface like is explained in the multiple WLAN guide. Read this section for instructions how to create the bridge and assign an interface to it.

http://www.dd-wrt.com/wiki/index.php/Multiple_WLANs#Separating_the_WLAN.27s

_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Mon May 03, 2010 6:55    Post subject: Reply with quote
hi, i read and made this but after : Create Bridge insert br1 than apply i dont get the Current Bridging Table with the ip´s and under the dhcp i cant select br1 .. only br0


PS: I have a WAP54G with the ddwrt firmware.
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Mon May 03, 2010 19:10    Post subject: Reply with quote
It might not work on WAP devices, it's still not clear to me if they can even do routing or just bridging... Instead you can separate one of the ports on the wrt54g into another VLAN which you then connect to the wap54g.

http://www.dd-wrt.com/wiki/index.php/VLAN_Detached_Networks_%28Separate_Networks_With_Internet%29#GUI_Tutorial

_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Wed May 05, 2010 17:30    Post subject: Reply with quote
thank you Smile after i brick my WAP ( cant get the ip ) i have a wrt54g and i setup the http://www.dd-wrt.com/wiki/index.php/Multiple_WLANs#Separating_the_WLAN.27s ... i get now the ip´s extra but internet not works Sad
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Wed May 05, 2010 22:10    Post subject: Reply with quote
olivers wrote:
thank you Smile after i brick my WAP ( cant get the ip ) i have a wrt54g and i setup the http://www.dd-wrt.com/wiki/index.php/Multiple_WLANs#Separating_the_WLAN.27s ... i get now the ip´s extra but internet not works Sad

You need to add firewall commands to allow it access.

_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Thu May 06, 2010 6:52    Post subject: Reply with quote
ok, but witch one?

this? : iptables -t nat -I POSTROUTING -o br0 -j SNAT --to `nvram get lan_ipaddr`
olivers
DD-WRT Novice


Joined: 29 Apr 2010
Posts: 13

PostPosted: Thu May 06, 2010 11:27    Post subject: Reply with quote
READY Very Happy after 2 weeks... i inserted this under firewall:


if [ "`nvram get wan_proto`" = "pppoe" ]; then
wanif="`nvram get pppoe_ifname`"
else
wanif="`nvram get wan_ifname`"
fi

# Make sure br1 has access to the internet:
iptables -I INPUT -i br1 -m state --state NEW -j logaccept
iptables -I FORWARD -i br1 -o $wanif -m state --state NEW -j ACCEPT
# Keep the two wireless networks from talking to each other:
iptables -I FORWARD -i br0 -o br1 -j logdrop
iptables -I FORWARD -i br1 -o br0 -j logdrop
# Keep br1 from accessing the router:
iptables -I INPUT -i br1 -p tcp --dport telnet -j REJECT --reject-with tcp-reset
iptables -I INPUT -i br1 -p tcp --dport ssh -j REJECT --reject-with tcp-reset
iptables -I INPUT -i br1 -p tcp --dport www -j REJECT --reject-with tcp-reset
iptables -I INPUT -i br1 -p tcp --dport https -j REJECT --reject-with tcp-reset




Big thanx for all !
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum