AP isolation not working properly

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Goto page 1, 2  Next
Author Message
Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Mon Aug 29, 2016 11:56    Post subject: AP isolation not working properly Reply with quote
I'm using DD-WRT on 2 TP-Link Archer C7s. Both running 30082 and installed as dumb wifi ap. DHCP/DNS etc is done by my pfSense firewall.

On both I have created 6 SSID's:
3 on 2.4GHz and 3 on 5GHz.
On both bands I have a guest SSID. I want the guest SSID to be isolated.
So on all guest SSIDs I have ticked the box Ap Isolation.

When connected to the guest SSID, I can still ping other clients and do a network scan and find them.
Also I can access services (web server) running on a wireless guest client. But some other devices cannot be found at all.

Why are some isolated and some are not?
Am I missing the point here or does it not work correctly?

I already use different VLANs for normal and guest network.
I just want the wireless clients connected to the guest SSID to NOT communicate with each other.
Sponsor
Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 6:25    Post subject: Reply with quote
Any one?
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Tue Aug 30, 2016 7:31    Post subject: Reply with quote
u probably have the vaps bridged, u have to select unbridged, give them whatever subnet u want, and enable net isolation for the vap. u will then need to add dhcp service to each of those vaps' subnets.

ap isolation just stops wifi clients from communicating with other wifi devices.

_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 8:03    Post subject: Reply with quote
tatsuya46 wrote:

ap isolation just stops wifi clients from communicating with other wifi devices.


That's the "feature" I want Cool .

Is it possible to do without DHCP?
I have a firewall/router (pfSense machine) already in my network.
The DD-WRT devices are dumb ap, and need to stay that way. Smile

Can't I just use unbridged only, and still use DHCP on my firewall/router?
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Tue Aug 30, 2016 8:16    Post subject: Reply with quote
when i try it it works fine but thats when the ddwrt router is in command of the network, try inputting the main routers dhcp ip and see what happens. having the vaps on another subnet with dhcp shouldnt interfere with the host router dhcp, its only local at the ddwrt device per vap, beyond that host router is still giving ddwrt a dhcp (which it sees as wan ip).
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 8:19    Post subject: Reply with quote
I just tried unbridged, set no IP or subnet just leave it 0.0.0.0 and ticked the box ap isolation.

All working, thanks! I get an IP from my pfSense box and AP isolation is working as well.

Only one question left now: to what was the VAP bridged before?
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Tue Aug 30, 2016 8:34    Post subject: Reply with quote
bridged to main interface, all ath0.x to at0, all ath1.x to ath1.
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 8:49    Post subject: Reply with quote
tatsuya46 wrote:
bridged to main interface, all ath0.x to at0, all ath1.x to ath1.


Ok, understood.
Thanks!
Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 8:55    Post subject: Reply with quote
I do read that there are some bugs with unbridged VAPs.
Though this is from years ago. Is this fixed or will I get problems?
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Tue Aug 30, 2016 9:06    Post subject: Reply with quote
which bugs?
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 9:12    Post subject: Reply with quote
https://www.dd-wrt.com/wiki/index.php/Multiple_WLANs

Basic Wireless Settings
Use a web browser to connect to your router's web GUI. Navigate to the Wireless -> Basic Settings page and under the Virtual Interfaces section press the "Add" button to add a new virtual interface. Leave the Network Configuration set to "Bridged" for all interfaces regardless of whether you want to bridge them or not because "Unbridged" has unresolved bugs at the time this was written (svn 13312). To get a working unbridged interface we will actually assign it to its own bridge later on. You may change any of the other settings to your liking..
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Tue Aug 30, 2016 9:15    Post subject: Reply with quote
thats old, years ago it was the way it is now, then went to needing to have it on a separate bridge, now back to the way it is now.
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 9:19    Post subject: Reply with quote
Ok, thanks for clearing that up.
So I don't need to worry than?
tatsuya46
DD-WRT Guru


Joined: 03 Jan 2010
Posts: 7568
Location: YWG, Canada

PostPosted: Tue Aug 30, 2016 9:24    Post subject: Reply with quote
no
_________________
LATEST FIRMWARE(S)

BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers

[x86_64] Haswell i3-4150/QCA9984/QCA9882 ------> r55797 std
[QUALCOMM] DIR-862L --------------------------------> r55797 std
▲ ACTIVE / INACTIVE ▼
[QUALCOMM] WNDR4300 v1 --------------------------> r50485 std
[BROADCOM] DIR-860L A1 ----------------------------> r50485 std


Sigh.. why do i exist anyway.. | I love you Anthony.. never forget that.. my other 99% that ill never see again..

Panja
DD-WRT User


Joined: 12 Aug 2016
Posts: 90

PostPosted: Tue Aug 30, 2016 9:27    Post subject: Reply with quote
Cheers!
Many thanks for the help and answers.
Goto page 1, 2  Next Display posts from previous:    Page 1 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum