drewski22785
Occasional Visitor
Okay so I am trying to do a lot and am running into a few walls and hoping for some help.
Original Setup: AX88U (Router Mode) -> 2x AC88U (AP Mode)
I have a 3 story house where in the basement I installed my AX88U (Router Mode) with my internet connection. I ran ethernet to the main floor and upstairs where I have an AC88U (AP Mode) on each floor. This has worked perfectly, wifi hand off is flawless, full house coverage etc...
New Need: Seperate wifi SSID that connects to an OpenVPN tunnel for work. I was able to get this to work with the use of YazFi Guest Wifi addon and a few modifications to the script. Basically I setup multiple tunnels to our headends and wanted the wifi to failover between tunnels. This is where the modifications to the YazFi script came in. This works perfect to date on my main AX88U router in router mode.
Problem: I can not figure out how to extend this to my main and upstairs routers, YazFi/Guest doesnt work the same in AP mode, so I had to convert for test the main floor back to router mode. The problem this creates is keeping the existing home network setup with graceful handoff. If I connect the ethernet cable to the WAN port it forces me to change DHCP settings to a different subnet and re-enable the DHCP server. No more graceful hand off. If I connect it the LAN port a ton of other things break like NTP, DNS etc..
I was able to work through most of the problems when connecting to the LAN port, static ntp, scripts to refresh ntp after start, static dns, scripts to re-apply dns, reload different addons once ntp is working again, static routing for the different guest networks etc... The biggest issue I was not able to overcome is the Guest networks are not able to get to the internet consistently, they work for a short time then break not rhyme or reason. The vpn director acts very similar with these non local Guest Subnets, sometimes it redirects, sometimes it blocks, sometimes it ignores the vpn and goes out the wan instead... I am guessing it is an iptables issue as YazFi creates rules for the WAN interface which is not being used (I tried modifying the rules to use br0 instead to no avail). Connectivity between the LANs all work even though the internet is not so this further makes me think this is an iptables issue but I am at a loss how to fix this option.
The alternative option connecting to the WAN port, I could probably settle for hard handoff between devices but I would rather not. I have tried adding eth0 to the bridge this did nothing. I tried overlapping the ips on the LAN and the WAN, after a few hacks this came on but wasn't always consistent in working. I tried dnsmasq dhcp-relay to use the wan port instead of local DNS, still no luck. I have not found any way online to bridge the wan and lan together to be able to share an IP/subnet successfully. Is this even possible?
So long story short, I need to tshoot my LAN port setup and see where the guest traffic is disappearing to but dont know where to start looking. I need to see if there are any other options to bridge my WAN port option to allow using the basement router dhcp to keep graceful handoff capabilities... All thoughts and ideas where to go are much appreciated!!!! Thank you!
Original Setup: AX88U (Router Mode) -> 2x AC88U (AP Mode)
I have a 3 story house where in the basement I installed my AX88U (Router Mode) with my internet connection. I ran ethernet to the main floor and upstairs where I have an AC88U (AP Mode) on each floor. This has worked perfectly, wifi hand off is flawless, full house coverage etc...
New Need: Seperate wifi SSID that connects to an OpenVPN tunnel for work. I was able to get this to work with the use of YazFi Guest Wifi addon and a few modifications to the script. Basically I setup multiple tunnels to our headends and wanted the wifi to failover between tunnels. This is where the modifications to the YazFi script came in. This works perfect to date on my main AX88U router in router mode.
Problem: I can not figure out how to extend this to my main and upstairs routers, YazFi/Guest doesnt work the same in AP mode, so I had to convert for test the main floor back to router mode. The problem this creates is keeping the existing home network setup with graceful handoff. If I connect the ethernet cable to the WAN port it forces me to change DHCP settings to a different subnet and re-enable the DHCP server. No more graceful hand off. If I connect it the LAN port a ton of other things break like NTP, DNS etc..
I was able to work through most of the problems when connecting to the LAN port, static ntp, scripts to refresh ntp after start, static dns, scripts to re-apply dns, reload different addons once ntp is working again, static routing for the different guest networks etc... The biggest issue I was not able to overcome is the Guest networks are not able to get to the internet consistently, they work for a short time then break not rhyme or reason. The vpn director acts very similar with these non local Guest Subnets, sometimes it redirects, sometimes it blocks, sometimes it ignores the vpn and goes out the wan instead... I am guessing it is an iptables issue as YazFi creates rules for the WAN interface which is not being used (I tried modifying the rules to use br0 instead to no avail). Connectivity between the LANs all work even though the internet is not so this further makes me think this is an iptables issue but I am at a loss how to fix this option.
The alternative option connecting to the WAN port, I could probably settle for hard handoff between devices but I would rather not. I have tried adding eth0 to the bridge this did nothing. I tried overlapping the ips on the LAN and the WAN, after a few hacks this came on but wasn't always consistent in working. I tried dnsmasq dhcp-relay to use the wan port instead of local DNS, still no luck. I have not found any way online to bridge the wan and lan together to be able to share an IP/subnet successfully. Is this even possible?
So long story short, I need to tshoot my LAN port setup and see where the guest traffic is disappearing to but dont know where to start looking. I need to see if there are any other options to bridge my WAN port option to allow using the basement router dhcp to keep graceful handoff capabilities... All thoughts and ideas where to go are much appreciated!!!! Thank you!