Allowing 2 interface to connect


I have a bare openwrt router, with 2 ethernet port

One port is set to
The other, to

If I connect a cable one port, I can access Luci, but can not ping the other interface

(Ping -> no route to host)

How to make the 2 interfaces exchange data ?

Thank you very much

can't route between those two, same subnet.

or it's not a router.


You cannot have two interfaces with the same subnet. It breaks routing.

What exactly are you trying to achieve, though. If this is a single device with 2 ports, those ports can simply be bridged together if desired. But I am a bit confused as to why you want to transfer data between two ports on the same device - it doesn’t seem to have a practical function.


The complete setup is
(A) a Wifi AP (no control over it)
(B) this device with 2 ethernet and one Wlan

Wlan connects properly on the AP (gets a IP)

Can get acess to it from

I tried to reduce the complexity by avoiding the wifi amd replicate with 2 ethernet

you're still not routing, I agree with @psherman why this set up ?
are you using the computer as a switch ?

I changed the IPs


Still, connecting from 10.0.0.x does not give access to

any clue ?

that's because both interfaces are in the lan firewall zone.

1 Like

why would the firewall interefe here ? I do not have limitation set in firewall


I changed the zones. same result

This is the firewall now

You've been asked before, what are you trying to achieve?

1 Like

the AP is my internet access (can't configure nothing), and the box in on my lan (home, with about 20 devices around)

Why is it so un-obvious to let 2 interface communicate ? (whatever they are, and for whatever reason)

What does that mean ?

THe target is

You have the following options:

Both Ethernet ports can be bridged.


@vgaetera is spot on. You have the two options listed in the above response.

Based on your diagram, it appears that you want the "other devices" to be on the ame subnet as the upstream connection. This means that you should follow the wifi extender link.

As far as your router is configured: I guess this should work. At least your router is not blocking anything.
Your firewall zone "lan" has a default behavior of "Forward" set to "access" as of the third drop down field in your screenshot.

I guess the devices in the range on your WAN port simply don't have a route telling them traffic targeted at any device had to be routed through Why would they. There's really no reason for your ISP modem to even know anything about your range, not be available at all and especially not being available via
The situation is often called "there's no return route in place".

You can varify this by using tcpdump on your routers "phy0-sta0" port (as you called it in your second diagram). You will see packaes going out but not coming back.

Just as an example:

  • Your ISP router has
  • Your router has on its WAN port
  • Your router has on its LAN port
  • Your computer has as it is connected to your routers LAN port
  • Some other device, e.g. a printer, has as it is connected to your ISPs Wifi
  • Now go to and "ping".
  • The traffic will go from into, out of It will reach
  • Then tries to respond . The answer goes from into, leaving your ISP routers publc interfaces and off into the internet.

So your problem is with your network architecture in general.

My suggestion would be

  • to put the wifi uplink back into the WAN firwall zone,
  • to re-enable the "Masquerding" checkbox for the WAN firwal zone
  • and not to have any devices at all at the side of your network. Everything should go to the LAN side of your network and get IP addresses in the range.

Of course "routed client" or "wifi extender", as @vgaetera and @psherman suggested, will work, too. But that will render every other OpenWRT feature you might want to use in the future completely numb because it will reduce your OpenWRT device basically to a cable.

As a side note: Why are you using /16 networks? That's frankly insane.
Especially the doesn't seem right. It looks lik your ISP tried to somehow make shure none of its customers uses a personal router of its own and doesn't VPN into anouther network (e.g. from your employer) as well, because there's a great chance they overlap. That's basically what happened in your first post: You created two completely different networks, used overlapping IP ranges and wondered why they would not communicate.
If I were you, I'd have a chat with my ISP to not use but for customer links. See:

1 Like

You are confusing routed client and Wi-Fi extender scenarios.
The first half of your reply is what a routed client should be.

1 - I still have not solved the initial question (having 2 interfaces on OpenWrt with 2 IPs, communicating with each other)

2 - I resolved the wifi issue with relayd, putting a IP on my router , keeping the /16 mask so my box is visible from the lan, and the relayd make it communicate between the 192.168.1,1 of the ISP to the of my box, and further to any other device on the LAN side