Question about Edgerouter X for guest wifi firewall rules

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Uranium-235
    Comrade Glimmer
    • Aug 2007
    • 5046
    • US

    #1

    Question about Edgerouter X for guest wifi firewall rules

    I'm not new to networking, but I never dealt with firewalls and vlans (aside from default SPI firewalls)

    So I have a company that has a wifi 6 pro unifi AP and even though I set it up months ago with AP isolation, I realize now that doesn't mean anything for local resources from the private network. Oops.

    So, I've been doing some reading and I ran into some videos some with seemingly an older firewall interface, and some with a newer one that has the established/related checkboxes. But it might have been another unifi device. There is no separate unifi switch here. It's unneeded. I plan to just plug the AP into eth4 and setup the vlan, rules, then put the vlanid into the guest network. But this AP also had a regular non-guest network too. Will assigning the guest vlan to eth4 not allow regular network traffic for the private network.

    Will not using 'related' on the firewall rule for the guest create problems? I don't want any uninitiated traffic into the guest. Of course, I have to allow dhcp right? I think those initial requests are uninitiated because they're multicast. The video i watched had rules that had the private network access the guest devices, I don't even want that. So do I just add a rule to drop 'new' incoming into the guest network, or would that also cause issues with dhcp. Would I put rules to allow the dhcp (and I guess DNS?) port to pass through ahead of the 'new' packet block (and malformed packet block)?

    An example is here: https://www.youtube.com/watch?v=fQJe4RCWoaQ&t=221s

    this confuses me. Why is the rule applied to traffic out? Shouldn't we want established/related traffic in? and not new traffic?
    Cap Datasheet Depot: http://www.paullinebarger.net/DS/
    ^If you have datasheets not listed PM me

Related Topics

Collapse

  • howardc64
    Samsung UN55JU650DF network/streaming problem
    by howardc64
    Fixed a 9 year old UN55JU650 by replacing backlight. Original backlight LED was still working after 27k! hours but terrible picture of course. Few LEDs were out, 5-6 lens fell off (bright white spots) and another few popped off with slightest force. Surviving LEDs were all slightly blue so picture has a blue tint.

    This TV runs older Tizen OS (updated to latest version, see pic) and have problems with network (wifi or ethernet) connection. The Tizen UI frequently switch to coax input source while changing content sources. . If no good signal (coax not connected, no prior antenna/cable...
    07-09-2025, 12:44 PM
  • davg
    Home network connection problem
    by davg
    I just bought a new ThinkPad laptop and I need to connect it to my home network. I have several computers on my network and can see each other in File Explorer and the older ones can communicate with each other (even with the new one) but the ThinkPad can see the other computers but can't communicate with them. I get the (network error 0x80070035 The network path not found). I tried several scenarios that I found on line but none of them worked?? Since the other computers on the network can communicate fine I'm assuming the problem is with the setup of the ThinkPad? All computers are running Windows...
    03-06-2021, 07:13 AM
  • japlytic
    Maximum speed should be marked on network ports
    by japlytic
    I noted that a number of consumer entertainment devices have the maximum speed marked on the wired network port and considering that there are broadband plans faster than 100 Mbit, the wired network port can be a bottleneck since some routers do not have Gigabit (only 100 Mbit) support for the WAN port let alone the wired network ports.

    One other thing: Certain low cost network cables only have two pairs which limits speed to 100 Mbit.​
    12-19-2024, 05:04 PM
  • hikomalek
    SYMSI70 gas heater, TOP247Y exploded, power supply, snubber network
    by hikomalek
    Hello, I have a SYMSI70 gas heater board, which has issues with its primary side power supply, controlled by TOP247Y chip.
    When I replace a TOP247Y it explode in 1 second. I have desoldered transformer and measured a winding ratio, so transformer looks like OK.

    Transformer:

    |Info| Primary | Aux | AB | CD|
    |-|----------|----------|-|-|
    |Ratio|1|25|40|12|
    |Voltage AC|230V|9.2V|5.8V|19V|
    |Voltage DC (*1.41)|230V|13V|8.1V|27V|

    I have disabled a undervoltage protection of TOP247Y, disconnected secondaries and tried to power it up...
    09-19-2025, 03:30 AM
  • Hondaman
    Hardware firewall to block ad servers?
    by Hondaman
    I found an interesting summary on a wiki that Youtube "right to repair" enthusiast Louis Rossman put up. He suggested I could use a hardware firewall and pfSense as a firewall, and use pfSenseNG as an ad blocker. Or use OPNSense as a similar alternative. Seems like it would be easy to set up, but it only runs on the hardware supported by BSD. (I'm sure the developers and maintainers of BSD are super-busy and cannot support every single piece of hardware out there, so I can't fault them.)

    The trick, apparently, is to "assign IP address lists from sites like I-blocklist...
    02-05-2025, 05:04 AM
  • Loading...
  • No more items.
Working...