Search results

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

  1. R

    How to block LAN access for a wired device on ASUS Merlin (Firmware 3004.388.8_2)?

    Also, wouldn't a couple of managed switches work for that? I understand they are not expensive. Combine and uncombine two ports on the router: the isolated port and a regular port.
  2. R

    How to block LAN access for a wired device on ASUS Merlin (Firmware 3004.388.8_2)?

    You are correct. Yes, everything on the switch would be isolated, but could still be useful for some but maybe not op.
  3. R

    How to block LAN access for a wired device on ASUS Merlin (Firmware 3004.388.8_2)?

    I have it working with some scripts on my router. Not sure if it would work on other router types: https://www.snbforums.com/threads/rt-ax86u-pro-lan-port-on-guest-network.91966/post-928266 Rung
  4. R

    RT-AX3000 gen 1 is unbale to go back to stock firmware

    Check the release notes for Version 3.0.0.4.386.47029 here: https://www.asus.com/networking-iot-servers/wifi-routers/asus-wifi-routers/rt-ax58u/helpdesk_bios?model2Name=RT-AX58U "*Due to core software module upgrade, if you wanna to upgrade to this version, please must update your router to...
  5. R

    RT-AX86U Pro LAN Port on Guest Network

    So I could never get either iptables or ebtables to isolate the LAN port. The filters are seeing the traffic but do not seem to be able to filter it. I am assuming there is some hardware acceleration happening that causes the data to flow unimpeded by the software. So, mostly for my own...
  6. R

    RT-AX86U Pro LAN Port on Guest Network

    I have not been successful in isolating the eth3 port and hope someone here can help. For example, I tired to replicate the other broute rules with the flowing commands: #!/bin/sh PORT="eth3" LAN_SUBNET="192.168.101.0/24" ROUTER_IP="192.168.101.1" ebtables -t broute -D BROUTING -p IPv4 -i...
  7. R

    RT-AX86U Pro LAN Port on Guest Network

    I wanted to add that I am concerned that this was just way too easy. I must be missing something. I read through a bunch of posts and scripts for something similar and they were all much more complicated. Is this only because of my model or has something changed with the recent firmware to make...
  8. R

    RT-AX86U Pro LAN Port on Guest Network

    As I wait for a 3006 version of Merlin for my RT-AX86U Pro to get VLAN capability someday, I have been moving some less trusted devices to GW1 which acts somewhat like an IOT VLAN. Some of the devices are connecting to the AX3000 mesh node and some are local to the RT-AX86U Pro. I feel this...
  9. R

    RT-AX92U Local LAN to LAN Communications Blocked

    Might want to supply more info about the clients. Are they all on main 2.4GHz, guest wireless, ethernet lan on the router, etc.?
  10. R

    Is RT-AX86U Pro meshed w/ RT-AX3000 (satellite) still a good option?

    Not sure why you would not upgrade to the latest firmware. Benchmarking with older firmware seems pointless to me. Do this for the router and the test AiMesh node.
  11. R

    Is RT-AX86U Pro meshed w/ RT-AX3000 (satellite) still a good option?

    I currently are doing option 1 with good results. The ax3000 replaced a powerline ap. Aimesh is working well with the 5GHz backhaul. It connects with 4x streams @160MHz. Only issue I had with AiMesh was my Amazon music mesh wasn't reliable. I had to tie all speakers to the main AX86 Pro router.
  12. R

    TAILMON TAILMON v1.0.20 -July 27, 2024- WireGuard-based Tailscale Installer, Configurator and Monitor (THREAD #1 CLOSED)

    At one point, many versions ago, I started using the --advertise-exit-node for this exact reason. Seemed to work, so I left it in there. Not sure if it's still needed.
  13. R

    dnsmasq.config.add without ip?

    Yes, that works. This is how I give my guest network clients hostnames.
  14. R

    TAILMON TAILMON v1.0.20 -July 27, 2024- WireGuard-based Tailscale Installer, Configurator and Monitor (THREAD #1 CLOSED)

    Haven't tried site2site but I am pretty sure you need to be in kernel mode for it to work (tailmon default is user space mode). Good luck and let us know if you get it working and how!
  15. R

    TAILMON TAILMON v1.0.20 -July 27, 2024- WireGuard-based Tailscale Installer, Configurator and Monitor (THREAD #1 CLOSED)

    My My understanding (at least in user mode) is that when you connect to devices on the local lan from the tailnet, it appears to the device to be coming from the router ip, not some new vpn subnet like the other vpn servers do. So if the tailnet process initiates the outbound connection to the...
  16. R

    TAILMON TAILMON v1.0.20 -July 27, 2024- WireGuard-based Tailscale Installer, Configurator and Monitor (THREAD #1 CLOSED)

    The way I read this description, you could only achieve what your are trying to do in kernel mode and not user space mode: https://tailscale.com/kb/1112/userspace-networking Without a network inteface how would your local devices tunnel out of your network?
  17. R

    TAILMON TAILMON v1.0.20 -July 27, 2024- WireGuard-based Tailscale Installer, Configurator and Monitor (THREAD #1 CLOSED)

    I think I misunderstood your problem. Now that I read it, it's opposite from what I first thought. I can access the devices behind router from outside via the tailnet. I now see you are trying to connect the other way around to devices outside the router. I haven't tried that. Sorry.
  18. R

    TAILMON TAILMON v1.0.20 -July 27, 2024- WireGuard-based Tailscale Installer, Configurator and Monitor (THREAD #1 CLOSED)

    Still just guessing here, but I have tailscale service version "v1.70.0" and the following default options: ARGS: --tun=userspace-networking --state=/opt/var/tailscaled.state --statedir=/opt/var/lib/tailscale PREARGS: nohup
  19. R

    TAILMON TAILMON v1.0.20 -July 27, 2024- WireGuard-based Tailscale Installer, Configurator and Monitor (THREAD #1 CLOSED)

    I also had to override dns: Not sure why but it works with this setting for me.
Top