Page 1 of 2

[Isolation not work][guest network][5G]

Posted: Sun Jan 01, 2017 10:43 am
by fengchen_gf
Hi all:

Guests with 5G can visit Gateway.
Isolation with 2.4G is OK.

/etc/config/wireless:

Code: Select all

config wifi-iface 'ap_gn_g'
	option device 'radio0'
	option mode 'ap'
	option network 'lan'
	option disassoc_low_ack '0'
	option is_guest_network '1'
	option macaddr 'bc:01:**:**:71:23'
	option ssid 'CMCC-**'
	option isolate '1'
	option encryption 'psk2'
	option key '**'


config wifi-iface 'ap_gn_a'
	option device 'radio1'
	option mode 'ap'
	option network 'lan'
	option disassoc_low_ack '0'
	option is_guest_network '1'
	option ssid 'CMCC-**2'
	option isolate '1'
	option encryption 'psk2'
	option key '**'
root@Gargoyle_wndr4300:~# ifconfig

Code: Select all

br-lan    Link encap:Ethernet  HWaddr 10:0D:**:**:61:A7  

eth0      Link encap:Ethernet  HWaddr 66:17:**:**:97:E1  

eth0.1    Link encap:Ethernet  HWaddr 66:17:**:**:97:E1  

eth0.2    Link encap:Ethernet  HWaddr 10:0D:**:**:61:A8  

wlan0     Link encap:Ethernet  HWaddr 10:0D:**:**:61:A7  

wlan0-1   Link encap:Ethernet  HWaddr BC:01:**:**:71:23  

wlan1     Link encap:Ethernet  HWaddr 10:0D:**:**:61:A9  

wlan1-1   Link encap:Ethernet  HWaddr 12:0D:**:**:61:A9  
root@Gargoyle_wndr4300:~# iwinfo

Code: Select all

wlan0     ESSID: "**unicom"
          Access Point: 10:0D:**:**:61:A7
          Mode: Master  Channel: 11 (2.462 GHz)
          Tx-Power: 22 dBm  Link Quality: unknown/70
          Signal: unknown  Noise: -95 dBm
          Bit Rate: unknown
          Encryption: WPA2 PSK (CCMP)
          Type: nl80211  HW Mode(s): 802.11bgn
          Hardware: unknown [Generic MAC80211]
          TX power offset: unknown
          Frequency offset: unknown
          Supports VAPs: yes  PHY name: phy0

wlan0-1   ESSID: "CMCC-**"
          Access Point: BC:01:**:**:71:23
          Mode: Master  Channel: 11 (2.462 GHz)
          Tx-Power: 22 dBm  Link Quality: 52/70
          Signal: -58 dBm  Noise: -95 dBm
          Bit Rate: 116.8 MBit/s
          Encryption: WPA2 PSK (CCMP)
          Type: nl80211  HW Mode(s): 802.11bgn
          Hardware: unknown [Generic MAC80211]
          TX power offset: unknown
          Frequency offset: unknown
          Supports VAPs: yes  PHY name: phy0

wlan1     ESSID: "**unicom2"
          Access Point: 10:0D:**:**:61:A9
          Mode: Master  Channel: 161 (5.805 GHz)
          Tx-Power: 22 dBm  Link Quality: unknown/70
          Signal: unknown  Noise: -92 dBm
          Bit Rate: unknown
          Encryption: WPA2 PSK (CCMP)
          Type: nl80211  HW Mode(s): 802.11an
          Hardware: 168C:0033 168C:A120 [Atheros AR9580]
          TX power offset: none
          Frequency offset: none
          Supports VAPs: yes  PHY name: phy1

wlan1-1   ESSID: "CMCC-**2"
          Access Point: 12:0D:**:**:61:A9
          Mode: Master  Channel: 161 (5.805 GHz)
          Tx-Power: 22 dBm  Link Quality: unknown/70
          Signal: unknown  Noise: -92 dBm
          Bit Rate: unknown
          Encryption: WPA2 PSK (CCMP)
          Type: nl80211  HW Mode(s): 802.11an
          Hardware: 168C:0033 168C:A120 [Atheros AR9580]
          TX power offset: none
          Frequency offset: none
          Supports VAPs: yes  PHY name: phy1

HW:NETGEAR WNDR4300V1 & NETGEAR 3700V4
FW:1.8.1

What's wrong? :roll: :roll:

Re: [Isolation not work][guest network][5G]

Posted: Mon Jan 02, 2017 7:57 am
by Lantis
What do you mean by isolation?
Isolation from what?
Each wireless client? The LAN? The WAN?

Re: [Isolation not work][guest network][5G]

Posted: Tue Jan 03, 2017 12:59 am
by fengchen_gf
Lantis wrote:What do you mean by isolation?
Isolation from what?
Each wireless client? The LAN? The WAN?
Guest Network
Wireless Client Isolation

Re: [Isolation not work][guest network][5G]

Posted: Tue Jan 03, 2017 2:50 am
by Lantis
That is an openwrt function, not Gargoyle.
If it isn't working i don't believe it is through fault of Gargoyle.

Maybe your expectations of what it does are not aligned with its actual purpose?
But i wouldn't know, because you still haven't explained exactly what you're trying to achieve.

There's a fine line between minimalism and not providing enough information, and you're on it. ;)

Re: [Isolation not work][guest network][5G]

Posted: Tue Jan 03, 2017 3:30 am
by fengchen_gf
Lantis wrote:That is an openwrt function, not Gargoyle.
If it isn't working i don't believe it is through fault of Gargoyle.

Maybe your expectations of what it does are not aligned with its actual purpose?
But i wouldn't know, because you still haven't explained exactly what you're trying to achieve.

There's a fine line between minimalism and not providing enough information, and you're on it. ;)
Wireless isolation for the 2.4G device is OK, but it doesn't work for the 5G devices. 5G devices can access the gateway ip.
And the config for guest work is different from 2.4G WLAN and 5G WLAN in file /etc/config/wireless.
Less a mac address.

[1.9.2]The isolation is invalid for Guest network with 5G

Posted: Mon Mar 20, 2017 2:29 am
by fengchen_gf
HW:NETGEAR WNDR3700V4
FW:1.9.2 & 1.8.1

The isolation is invalid for Guest network with 5G .
The guests uses 5G wifi to access the gateway normally.

Re: [Isolation not work][guest network][5G]

Posted: Mon Mar 20, 2017 4:08 am
by Lantis
There is no need to create a new topic for the same thing when I already gave you the answer.

Unless you have new information and evidence, for example, that the same configuration works fine on Openwrt but not on Gargoyle, what more do you expect?

Re: [Isolation not work][guest network][5G]

Posted: Mon Mar 20, 2017 5:46 am
by fengchen_gf
I forgot it, now I understand what you mean, it is openwrt's problem. :P
Or, I thought the new version might fixed. :D

Re: [Isolation not work][guest network][5G]

Posted: Fri Mar 24, 2017 12:51 am
by rseiler
Related?
https://github.com/ericpaulbishop/gargo ... de5ca5fa04

@fengchen_gf, I always thought the built-in isolation feature here (and in OpenWRT and DD-WRT for that matter) was just to isolate wireless clients from each other. When you say isolated from the gateway, do you mean the LAN? Because if so, that would be great, but I doubt it. The only way that I know to do it is via a very tricky partially manual setup with a separate subnet.

Re: [Isolation not work][guest network][5G]

Posted: Fri Mar 24, 2017 1:47 am
by Lantis
Yes related fix.
There was a mixup in translation I expect.
When I hear "isolation" I think the openwrt built in isolation.

The error was in the Gargoyle form of isolation which is slightly different.

Now that I understand wha tproblem we were referring to, easy fix.