That's all. Nothing changed from factory otherwise but the problem still persists. When a MAC address on VLAN3 is denied internet access, it also becomes inaccessible from VLAN1. I feel without anyone trying to replicate, we will be in a circular discussion.
And we still have no idea how exactly your router is configured.
In the example "Net Isolation" is enabled - if "Net Isolation" is enabled then of course there can be no traffic between br0 and br1.
But you say in an earlier post that you don't have "Net Isolation" enabled.
So I tested the example without "Net Isolation" enabled for br1.
Then I blocked the internet access via iptable rule for a VLAN3 device = result the device has no internet access anymore but the access VLAN1<-->VLAN3 still works.
So no idea what you are doing but you are doing it wrong.
Code:
:~$ ifconfig
enp0s31f6: inet 192.168.5.135
:~$ ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) Bytes Daten.
Von 192.168.5.1 icmp_seq=1 Zielport nicht erreichbar
Von 192.168.5.1 icmp_seq=2 Zielport nicht erreichbar
Von 192.168.5.1 icmp_seq=3 Zielport nicht erreichbar
:~$ ping 192.168.1.110
PING 192.168.1.110 (192.168.1.110) 56(84) Bytes Daten.
64 Bytes von 192.168.1.110: icmp_seq=1 ttl=63 Zeit=0.969 ms
64 Bytes von 192.168.1.110: icmp_seq=2 ttl=63 Zeit=0.897 ms
Removing the rule
Code:
root@DD-WRT:~# iptables -D FORWARD -i br1 -o $(get_wanface) -m mac --mac-source
4C:CC:6A:11:22:33 -m state --state NEW -j REJECT
Code:
:~$ ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) Bytes Daten.
64 Bytes von 8.8.8.8: icmp_seq=1 ttl=119 Zeit=10.6 ms
64 Bytes von 8.8.8.8: icmp_seq=2 ttl=119 Zeit=10.3 ms
64 Bytes von 8.8.8.8: icmp_seq=3 ttl=119 Zeit=10.3 ms
^C
--- 8.8.8.8 ping-Statistik ---
3 Pakete übertragen, 3 empfangen, 0% Paketverlust, Zeit 2003ms
rtt min/avg/max/mdev = 10.313/10.414/10.595/0.128 ms
As per the initial post, MAC address internet blocking is done through the GUI: >>Access restrictions>>WAN Access.
blocking a MAC through an IPtable rule works fine, but from the GUI it doesnt. If this question seems to be wasting the time of the community members, I won't pursue it further.