Use case: one router two dumb APs. dumb APs used as guest network both on WiFi and wired (4 ports).
I want any guest being isolated from each others.
From various post on this forum I understood I have to set up one separated VLan for each wired port and wifi interface and then tied them together in a bridge device forming the guest network structure. The interface attached to bridge device will be the common DHCP server of the guest network.
I've tried a basic exercise using v22.03 on the targetted router
2 Basic bridges br-lan port 1 and 2 on Lan interface for administration, and br-invite port 3 and 4 on Invite interface (proper FW zone and rule allow DHCP and internet connection of Invite network PC clients connected to port 3 and 4).
No Vlan yet, it works well, network config is as follow
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'xxxxxxxxxxxxxxx'
config device
option name 'br-lan'
option type 'bridge'
list ports 'lan1'
list ports 'lan2'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '192.168.1.1'
option netmask '255.255.255.0'
option ip6assign '60'
config interface 'wan'
option device 'wan'
option proto 'dhcp'
config interface 'wan6'
option device 'wan'
option proto 'dhcpv6'
config interface 'invite'
option proto 'static'
option device 'br-invite'
option ipaddr '172.16.19.1'
option netmask '255.255.255.0'
config device
option type 'bridge'
option name 'br-invite'
list ports 'lan3'
list ports 'lan4'
option bridge_empty '1'
Then I try to set up VLANs on the br-invite bridge. Going to Network->Devices->br-invite->Configure
tick enable VLAN
add 2 Vlans 13 and 14 respectivelly untagged* on port 3 and 4
save and apply
I was assuming to have no change except no more communication between PCs connected to port 3 and 4
unfortunatelly I no longer have connectivity to internet nor receiving DHCP (tcpdump show that bootp initial request get no answer while FW traffic monitor of invite zone show no reject)
network config is as follow
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'xxxxxxxxxxxxxxx'
config device
option name 'br-lan'
option type 'bridge'
list ports 'lan1'
list ports 'lan2'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '192.168.1.1'
option netmask '255.255.255.0'
option ip6assign '60'
config interface 'wan'
option device 'wan'
option proto 'dhcp'
config interface 'wan6'
option device 'wan'
option proto 'dhcpv6'
config interface 'invite'
option proto 'static'
option device 'br-invite'
option ipaddr '172.16.19.1'
option netmask '255.255.255.0'
config device
option type 'bridge'
option name 'br-invite'
list ports 'lan3'
list ports 'lan4'
option bridge_empty '1'
config bridge-vlan
option device 'br-invite'
option vlan '13'
list ports 'lan3:u*'
config bridge-vlan
option device 'br-invite'
option vlan '14'
list ports 'lan4:u*'
I've also tried to add network interfaces (proto 'none') to each VLan without success.
I donnot see what I'm missing. Can somebody tell me what I'm doing wrong?
THX