I have a RT-AC68U, with Merlin 386.7.2.
I need to put a couple of crappy cameras on the network while traveling, and I need to open two port forwarding for each one, for web access and RTSP. I don't trust those cameras, so I want to put them on a guest network and block intranet access. If they get hacked, won't compromise the rest of the network. Problem is, when I block intranet access for the guest network from the WEB UI, port forwarding stops working.
I tried to look at iptables to understand if blocking local access changes something, but there is nothing obvious
I see that the Guest network 3 I'm using is wl0.3, and I'm thinking of deleting the bridge between br0 and wl10.3, set up a new bridge and then in firewall-start use iptables to route traffic as appropriate... but I'm sure it will be a long trial and error, so I'm hoping for suggestions
I need to put a couple of crappy cameras on the network while traveling, and I need to open two port forwarding for each one, for web access and RTSP. I don't trust those cameras, so I want to put them on a guest network and block intranet access. If they get hacked, won't compromise the rest of the network. Problem is, when I block intranet access for the guest network from the WEB UI, port forwarding stops working.
I tried to look at iptables to understand if blocking local access changes something, but there is nothing obvious
I see that the Guest network 3 I'm using is wl0.3, and I'm thinking of deleting the bridge between br0 and wl10.3, set up a new bridge and then in firewall-start use iptables to route traffic as appropriate... but I'm sure it will be a long trial and error, so I'm hoping for suggestions