By default, ssh shouldn't be accessible from guess network. I don't want to create another iptables rule since this should be a default deny rule.
Why is it open?
Because there is no restriction on Guest clients toward the router itself.
...
374.43 (6-June-2014)
...
- FIXED: Restricted guests still had access to the router (Asus bug introduced in GPL 4887)
...
Are you saying this has gotten broken again by Asus?
From your change log:
I will check once I get home. I remember not turning it on especially I recently installed Merlin.It's been so long, I don't remember the details of that particular fix. I'd make sure that the OP did disable Intranet access on his Guest network configuration first.
Guest Network page, try:
Access Intranet = OFF
My Wi-Fi guests cannot access the router. The TCP ports are all blocked by default. However, the ICMP ping is not blocked.
Sorry guys, I didn't forget you. I was so busy working on my diy camera slider
Here it is. It's set to off. So looks like bug resurrected.
What's missing in my configuration then? Is it because I have a firewall-start script?
fyi, my firmware is 378.51
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!