Client bridge, WAP, VAP problem

Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.)
Author Message
DD-WRT Novice

Joined: 07 Nov 2020
Posts: 1

PostPosted: Sat Nov 07, 2020 13:16    Post subject: Reply with quote
Hey Guys,

i didn't want to start a whole new Thread because what discussed here fits perfectly to my problems! I hope it's ok if i do it this way. First of all, English is not my native language so please excuse possible grammatical errors Wink

Ok lets start:

My Setup: (both Wrt3200ACM b:40559)

A "WRT3200ACM(1)" configured as a "Client-Bridge(Routed)" -> which connects to another "WRT3200ACM(2)" which is configured as a "AP" (connected with cable to the Main-Router), this all happens on 2,4ghz band!

additionally i enabled an Access Point on the "Clientbridged-WRT3200ACM(1)" which happens on the 5ghz band!

Up to this point everything works fine!
All connected devices (no matter if cable or wireless) are in the same Subnet as the Main-Router and have access to the Internet!

And now my problem:

What i want to do is:

Configure the 5ghz AP(ath0) on the "ClientBridgedWRT3200ACM(1)" like a "GuestNet" with a seperate Subnet!

I did this 2 ways without success Sad

First try was to configure a "VirtualAccessPoint(ath0.1)" at the 5ghz Band.
Configured like in the "DDWRT-GuestNet" Guide!

- Added a "VAP(ath0.1)"
- Set to Unbridged
- Enabled Nat/Masquerade
- Enabled AP-Isolation
- Enabled Forced DNS Redirection
- Added the needed IP's

Next Step under "Services->Dnsmasq->Add.Opt."
added the DHCP orders according to my 5ghz device and VAP IP!


third step was under "Administration->Commands"

I set up the firewall rules to give internet access to the "VAP"

iptables -I FORWARD -i ath0.1 -d `nvram get lan_ipaddr`/`nvram get lan_netmask` -m state --state NEW -j REJECT
iptables -t nat -I POSTROUTING -o br0 -j SNAT --to `nvram get lan_ipaddr`

Saved all the Configuration and rebooted the Router.

So what happens now is: I can connect to my VirtualAccessPoint and i get the specific IP & the specific Subnet as configured above.
BUT: no Internet!

If i connect to the 5ghzAP(ath0) i have Internet access. Ive spend a lot of time to solve the riddle but i really dont get it Sad

The second try was to configure the Setup with adding Bridges and Assignments which led me to the same Result: I can connect to the VAP with the right IP and Subnet, but without Internet Access.

This whole thing (guestnet) works if the WRT3200ACM(1) is connected via cable to the Main-Router. But if configured as "ClientBridge" i only can access Internet when AP is bridged. Sad

I hope that what i wrote is anyhow understandable Wink

in advance: Thanks for your help!!!

Additional Info: I know that the right configuration for a Client-Bridge Setup is to change the Advanced-Routing from "Gateway" to "Router". In my case in need the "Gateway" configuration for having the NAT/Masquerade options. Maybe this is the Problem what pretends the Setup from working as it should?!


Joined: 18 Mar 2014
Posts: 6938
Location: Netherlands

PostPosted: Sat Nov 07, 2020 13:26    Post subject: Reply with quote
This is a separate topic so I moved it to a separate thread.

To get the best out of DDWRT and the forum, read and follow the forum guidelines:

Routers:Netgear R7800, R6400v1, R6400v2, Linksys EA8500, EA6900 (XvortexCFE), E2000 (converted WRT320N), WRT54GS v1.
OpenVPN Policy Based Routing:
Install guide R6400v2:
OpenVPN Server Setup:
Install guide R7800:
Wireguard Server setup guide:
Wireguard Client setup guide:
Wireguard Advanced setup guide:
Forum Guide Lines (important read):
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.) All times are GMT


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum