I have an apartment, in my home, thats being rented to unknown people, and I would like to isolate the network in the apartment from the rest of the house.
My current setup is:
- Inteno VDSL modem from my ISP, in DHCP bridge mode.
- Asus RT-AC68U connected by cable, running in DHCP mode. Public IP on the outside, 10.0.1.x on the LAN side both for wireless and cabled. It is running wifi guest network thats isolated from the regular LAN. It is also an Aimesh hub, with two nodes connected by cable (RT-AC66U B1 and RT-AC68U).
The apartment has four network points and also needs wireless access.
If only the asus routers were able to delegate one LAN port to the guest network, I could just get a 5 port switch and be done with it all, but it doesnt seem like that is possible, so what do I do?
I am having a hard time figuring out how to do it without going for a double NAT solution for both networks (reset the Inteno and plug in my asus network on one LAN port and another wifi router for the apartment in another port), which will remove the possibility to access my home remotely - which I do need.
Any suggestions? Can it be done via a managed switch connected to a LAN port on the main Asus? (And another wifi router connected to the managed switch again). Will the switch be able to prevent access to 10.0.1.x?
My current setup is:
- Inteno VDSL modem from my ISP, in DHCP bridge mode.
- Asus RT-AC68U connected by cable, running in DHCP mode. Public IP on the outside, 10.0.1.x on the LAN side both for wireless and cabled. It is running wifi guest network thats isolated from the regular LAN. It is also an Aimesh hub, with two nodes connected by cable (RT-AC66U B1 and RT-AC68U).
The apartment has four network points and also needs wireless access.
If only the asus routers were able to delegate one LAN port to the guest network, I could just get a 5 port switch and be done with it all, but it doesnt seem like that is possible, so what do I do?
I am having a hard time figuring out how to do it without going for a double NAT solution for both networks (reset the Inteno and plug in my asus network on one LAN port and another wifi router for the apartment in another port), which will remove the possibility to access my home remotely - which I do need.
Any suggestions? Can it be done via a managed switch connected to a LAN port on the main Asus? (And another wifi router connected to the managed switch again). Will the switch be able to prevent access to 10.0.1.x?