What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Feature Request: "Guest" Wireless Intranet ONLY

Potato Sack

New Around Here
Merlin,

Thanks for what you do - great firmware, rock solid. I'm wondering if there's a possibility you could add a third option to the Guest Wireless feature.

Basically, I want the option of a Guest Wireless network that can access the internal network, but NOT the internet. Bonus points if you could firewall certain ports and IPs between the untrusted guest network and the trusted network.

I have some devices on my network that I explicitly don't want to talk to the internet for any reason (think IP cameras with suspect Chinese firmware), and I think this would be a good compromise.

Happy to donate for your time!

Thanks!
 
Try creating a rule for that camera's IP under Firewall -> Network Services Filter, blocking ports 1:65535.
 
Try creating a rule for that camera's IP under Firewall -> Network Services Filter, blocking ports 1:65535.

Does this block the "ping" command?

If not, is it possible to stop pings through the GUI?
 
Does this block the "ping" command?

If not, is it possible to stop pings through the GUI?


This was actually going to be my next question. The Network Services Filter is OK for making broad rules (blocking 1:65535 on either TCP or UDP), but a little short on doing other things, like:

1) blocking ICMP (this has to be done globally, not per-IP)
2) Adding an exception for certain other types of communication (block everything outbound except NTP, or block everything except to one specific internal IP)
3) Adding more than one type of rule per IP

etc.

I suppose you could start mucking with iptables via CLI, but not sure how to make those changes persist.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top