Unfortunately, this rule doesn't work, so my question is: does traffic between two devices on the same network even hit the firewall in the first place or does the traffic flow through directly?
I'm by no means an expert on Openwrt or networking but i think the firewall only works when the traffic crosses zones (like lan to wan).
You could put one of them in a separate zone.
No, zones are "seen" by the router. Well, not the zones on their own; you will make an additional VLAN and assign to it the LAN port that's connected to the PC you want to isolate, then you configure the firewall to block the traffic between the languest and lan.
A potentially simpler solution is to still use VLAN’s to create interfaces on each LAN port, put all interfaces into the same bridge, configure Netfilter to send all bridge traffic to Iptables, and then block cross-talk between the interfaces within the same bridge.
I think for the time being, I'll try using a host-level firewall on the PC as I'm reluctant to start tinkering with VLANs.
For my understanding though...can VLANs only be created for 'physical ports'? For example, if I have a router with 4 ethernet ports, does that mean I can create a VLAN per port?
What if I have two wifi devices, A and B. Can I put A in a VLAN of its own and B in a separate VLAN of its own and then a "main VLAN" for my regular wifi traffic?
i wish there is a way to do this
here is my problem
i have 2 samsung printers k2200
they have various consumable chips like toner chip and drum chip
since they are connected in same network they communicate with each other
and share there consumable information
i have never thaught this would be possible but after checking indeed there is sharing of consumable
information
a toner chip is a read only eeprom when i introduce a new chip to a printer it will always believe its a new chip buy here coz they talk to one and another, i cant use a used toner chip from one printer add it to new printer coz they keep track of all the consumable on the network
so i am loosing chips fast at an alarming rate, it would be so good if i could just block them from talking to each other on the same network