kurjak wrote:Hi!
I've tried everything you guys have written, but i still cannot isolate guest wlan. I'm using 1043nd v1.10, 1.5.9
What do you get when you type ebtables --list? My result is:
Code: Select all
root@Lagunitas:/etc/config# ebtables --list
Bridge table: filter
Bridge chain: INPUT, entries: 2, policy: ACCEPT
-p IPv4 -i wlan0-1 --ip-src 0.0.0.0 --ip-dst 255.255.255.255 --ip-proto udp -j ACCEPT
-p IPv4 -i wlan0-1 --ip-src ! 192.168.1.128/25 -j DROP
Bridge chain: FORWARD, entries: 2, policy: ACCEPT
-i wlan0-1 -o eth0 -j DROP
-i wlan0-1 -o wlan0 -j DROP
Bridge chain: OUTPUT, entries: 0, policy: ACCEPT
To do this, I have the following in /usr/lib/gargoyle_firewall_util/gargoyle_firewall_util.sh initialize_firewall():
Code: Select all
# Isolate the guest wifi from your LAN.
ebtables -I FORWARD -i wlan0-1 -o wlan0 -j DROP
ebtables -I FORWARD -i wlan0-1 -o eth0 -j DROP
# Allow DHCP requests
ebtables -I INPUT -i wlan0-1 -p IPv4 --ip-dst 255.255.255.255 --ip-source 0.0.0.0 --ip-proto udp -j ACCEPT
# Require IPs > .128 for guest wifi for QoS purposes
ebtables -A INPUT -p IPv4 -i wlan0-1 --ip-src ! 192.168.1.128/25 -j DROP
When I tested before, it looked like the networks were isolated. I will test again next week.