I have split the br network in two networks
config interface 'lan1'
option device 'lan1'
option proto 'static'
option ipaddr '192.168.0.1'
option netmask '255.255.255.0'
option ip6assign '60'
config interface 'lan2'
option device 'lan2'
option proto 'static'
option ipaddr '192.168.178.1'
option netmask '255.255.255.0'
option ip6assign '60'
On Network “lan2” I have connected another pc (address 192.168.178.2)
The ping works from router to 192.168.178.2
root@router:~# ping 192.168.178.2
PING 192.168.178.2 (192.168.178.2): 56 data bytes
64 bytes from 192.168.178.2: seq=0 ttl=64 time=1.276 ms
64 bytes from 192.168.178.2: seq=1 ttl=64 time=0.744 ms
but from pc of lan (192.168.0.0/24) is drop!
I have tried this configuration
config zone
option name lan
list network 'lan'
option input ACCEPT
option output ACCEPT
option forward ACCEPT
list network 'br-lan'
list network 'lan1'
config zone
option name lan2
option input ACCEPT
option output ACCEPT
option forward ACCEPT
list network 'lan2'
config zone
option name wan
list network 'wan'
list network 'wan6'
option input REJECT
option output ACCEPT
option forward REJECT
option masq 1
option mtu_fix 1
config forwarding
option src lan
option dest wan
config forwarding
option src lan2
option dest lan
config forwarding
option src lan
option dest lan2
and result is drop
With this one
config zone
option name lan
list network 'lan'
option input ACCEPT
option output ACCEPT
option forward ACCEPT
list network 'br-lan'
list network 'lan1'
list network 'lan2'
config zone
option name wan
list network 'wan'
list network 'wan6'
option input REJECT
option output ACCEPT
option forward REJECT
option masq 1
option mtu_fix 1
config forwarding
option src lan
option dest wan
the result is same (drop)
Very strange thing happen if I remove the “lan2” from firewall config
config zone
option name lan
list network 'lan'
option input ACCEPT
option output ACCEPT
option forward ACCEPT
list network 'br-lan'
list network 'lan1'
list network 'lan2'
became
config zone
option name lan
list network 'lan'
option input ACCEPT
option output ACCEPT
option forward ACCEPT
list network 'br-lan'
list network 'lan1'
The packets are not more dropped..but rejected
ping 192.168.178.2
PING 192.168.178.2 (192.168.178.2) 56(84) bytes of data.
From 192.168.0.1 icmp_seq=382 Destination Port Unreachable
From 192.168.0.1 icmp_seq=383 Destination Port Unreachable
From 192.168.0.1 icmp_seq=384 Destination Port Unreachable
From 192.168.0.1 icmp_seq=385 Destination Port Unreachable
From 192.168.0.1 icmp_seq=386 Destination Port Unreachable
From 192.168.0.1 icmp_seq=387 Destination Port Unreachable
From 192.168.0.1 icmp_seq=388 Destination Port Unreachable
From 192.168.0.1 icmp_seq=389 Destination Port Unreachable
How to solve?