Net Isolation

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Goto page 1, 2  Next
Author Message
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Fri Jun 29, 2018 19:48    Post subject: Net Isolation Reply with quote
(Sorry for my bad english, i'm a guy from Québec Razz)

Hi !

I have internet for my appartments, and i wanted to isotale each ssid to avoid someone on other ssid cast something on chromecast in other ssid.

This is my setup ( legend : -- for wired == for wireless )

CABLE MODEM --- TPLINK ARCHER C7 ======= TPLINK WL941NDV6

twice routers are on most recent beta build.
they are linked with WDS
the DHCP server is disabled on my WL941NDV6
in the archer c7, i did on each ssid a unbridged network and i activate net isolation and made a multiple dhcp for each ssid on this router (they have 7 different SSID) and it works like i want.

BUT!

when i did this on my WL941NDV6 (4 different SSID) the client lost internet. he can connect to a router, he give a ip adresses proper to his network but no internet. i need to leave this bridged to have internet, and when i leave it bridged all the ssid can talk with each others.

HOW can i active net isolation on each ssid on the WL941NDV6 and keep internet working ?

THANKS !
Sponsor
ian5142
DD-WRT Guru


Joined: 23 Oct 2013
Posts: 2319
Location: Canada

PostPosted: Fri Jun 29, 2018 23:34    Post subject: Wireless or Wired Reply with quote
Is it a wireless or Wired link between the Archer C7 and the 941ND?

If it is Wireless, use WDS, only on the 2.4GHz band. Archer C7 is WDS AP, WDS Station is the 941ND.

Then create the VAPs with Net isolation. It should work.

_________________
Before asking a question on the forums, update dd-wrt: Where do I download firmware? I suggest reading it all.
QCA Best WiFi Settings


Some dd-wrt wiki pages are up to date, others are not. PM me if you find an old one.

Atheros:
Netgear R7800 x3 - WDS AP / station, gateway, QoS
TP-Link Archer C7 v2 x2 - WDS Station
TP-Link TL-WDR3600 v1 - WDS Station
TP-Link 841nd v8 - NU
D-Link 615 C1/E3/I1 x 7 - 1 WDS station
D-Link 825 B1 - NU
D-Link 862L A1 x2 - WDS Station
Netgear WNDR3700v2 - NU
UBNT loco M2 x2 - airOS

Broadcom
Linksys EA6400 - Gateway, QoS
Asus N66U - AP
Netgear WNDR3700v3 - not used
MediaTek
UBNT EdgeRouter X - switch
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Fri Jun 29, 2018 23:37    Post subject: Reply with quote
It's a wireless link

Yes, my C7 is WDS AP and my 941ND is WDS Station.

But it still not work when i select unbridged the client lost the internet.

I don't know why
ian5142
DD-WRT Guru


Joined: 23 Oct 2013
Posts: 2319
Location: Canada

PostPosted: Fri Jun 29, 2018 23:43    Post subject: WDS Reply with quote
No, don't unbridge the WDS network. Leave it bridged, have a WDS only network. Then create Virtual AP (VAPs) for the other networks on each router. Only unbridge and turn on Net Isolation on the VAPs. You may be required to run a separate DHCP server on the 941ND because the Archer C7 will not know about the 941ND's VAPs.
_________________
Before asking a question on the forums, update dd-wrt: Where do I download firmware? I suggest reading it all.
QCA Best WiFi Settings


Some dd-wrt wiki pages are up to date, others are not. PM me if you find an old one.

Atheros:
Netgear R7800 x3 - WDS AP / station, gateway, QoS
TP-Link Archer C7 v2 x2 - WDS Station
TP-Link TL-WDR3600 v1 - WDS Station
TP-Link 841nd v8 - NU
D-Link 615 C1/E3/I1 x 7 - 1 WDS station
D-Link 825 B1 - NU
D-Link 862L A1 x2 - WDS Station
Netgear WNDR3700v2 - NU
UBNT loco M2 x2 - airOS

Broadcom
Linksys EA6400 - Gateway, QoS
Asus N66U - AP
Netgear WNDR3700v3 - not used
MediaTek
UBNT EdgeRouter X - switch
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Fri Jun 29, 2018 23:51    Post subject: Reply with quote
No i didn't unbridged the WDS, only the VAP, but i didn't try to run a second dhcp server. I tried to run a second dhcp server but it doesn't work, but i'll try again..
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Sat Jun 30, 2018 0:06    Post subject: Reply with quote
It doesn't work,

I don't know what i did wrong.

I attached screenshots to show to you

Link to my google drive for the screenshots

https://drive.google.com/folderview?id=1TSRCXd5ItScvXw0wSZZKKtE1ZvwT0E5c


Last edited by fpaquin92 on Sat Jun 30, 2018 12:28; edited 1 time in total
ian5142
DD-WRT Guru


Joined: 23 Oct 2013
Posts: 2319
Location: Canada

PostPosted: Sat Jun 30, 2018 11:58    Post subject: Photos Reply with quote
Please edit the previous post and zip up the files. This forum does not handle photos very well.
_________________
Before asking a question on the forums, update dd-wrt: Where do I download firmware? I suggest reading it all.
QCA Best WiFi Settings


Some dd-wrt wiki pages are up to date, others are not. PM me if you find an old one.

Atheros:
Netgear R7800 x3 - WDS AP / station, gateway, QoS
TP-Link Archer C7 v2 x2 - WDS Station
TP-Link TL-WDR3600 v1 - WDS Station
TP-Link 841nd v8 - NU
D-Link 615 C1/E3/I1 x 7 - 1 WDS station
D-Link 825 B1 - NU
D-Link 862L A1 x2 - WDS Station
Netgear WNDR3700v2 - NU
UBNT loco M2 x2 - airOS

Broadcom
Linksys EA6400 - Gateway, QoS
Asus N66U - AP
Netgear WNDR3700v3 - not used
MediaTek
UBNT EdgeRouter X - switch
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Sat Jun 30, 2018 12:11    Post subject: Re: Photos Reply with quote
ian5142 wrote:
Please edit the previous post and zip up the files. This forum does not handle photos very well.


There is a linl to my google drive with the screenshots

https://drive.google.com/folderview?id=1TSRCXd5ItScvXw0wSZZKKtE1ZvwT0E5c
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6868
Location: Romerike, Norway

PostPosted: Sat Jun 30, 2018 22:17    Post subject: Reply with quote
1) Add static routes on the C7 for the networks behind the 941ND.

2) Enable NAT from all networks on the C7

iptables -I POSTROUTING -t nat -o `get_wanface` -j MASQUERADE

Paste in Administration->Commands and save as firewall.
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Sat Jun 30, 2018 22:51    Post subject: Reply with quote
Per Yngve Berg wrote:
1) Add static routes on the C7 for the networks behind the 941ND.

2) Enable NAT from all networks on the C7

iptables -I POSTROUTING -t nat -o `get_wanface` -j MASQUERADE

Paste in Administration->Commands and save as firewall.


How i add static routes ?
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6868
Location: Romerike, Norway

PostPosted: Sat Jun 30, 2018 23:10    Post subject: Reply with quote
Setup->Advanced Routing

Add the network like 192.168.5.0/255.255.255.0 with the IP of the second router as gateway.
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Sat Jun 30, 2018 23:31    Post subject: Reply with quote
Per Yngve Berg wrote:
Setup->Advanced Routing

Add the network like 192.168.5.0/255.255.255.0 with the IP of the second router as gateway.


Like this ?

Follow the link for the screenshot
https://drive.google.com/file/d/1_YCzGjqK2zPMGedqAn5kXFDyPOL_G4lu/view?usp=drivesdk

There is a link to my whole folder contains this photo
https://drive.google.com/folderview?id=1TSRCXd5ItScvXw0wSZZKKtE1ZvwT0E5c
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6868
Location: Romerike, Norway

PostPosted: Sun Jul 01, 2018 7:42    Post subject: Reply with quote
The gateway is wrong. It cannot be on the same sub-net as the one you are routing to.

When the router have an interface to 10.50.0.0/24, it already know where it is and does not need a route.

Is the 941ND connected LAN-LAN or WAN-LAN with the C7?

Take an example:

LAN address of C7: 10.50.0.1
WAN address of 941ND: 10.50.0.2 gateway 10.50.0.1
LAN address of 941ND: 10.51.0.1

941ND is set in router mode.

Static route on C7 will be:
10.51.0.0/24 gateway 10.50.0.2
fpaquin92
DD-WRT Novice


Joined: 04 Aug 2017
Posts: 25

PostPosted: Sun Jul 01, 2018 11:24    Post subject: Reply with quote
Per Yngve Berg wrote:
Is the 941ND connected LAN-LAN or WAN-LAN with the C7?


WLAN-WLAN with WDS
Per Yngve Berg
DD-WRT Guru


Joined: 13 Aug 2013
Posts: 6868
Location: Romerike, Norway

PostPosted: Sun Jul 01, 2018 11:41    Post subject: Reply with quote
That is LAN-LAN (10.50.0.1 and 10.50.0.2, same sub-net)

You need to enter a route to the other sub-nets behind the 941ND. Can you ping the C7 (10.50.0.1) from a client on these sub-nets?
Goto page 1, 2  Next Display posts from previous:    Page 1 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum