I thoroughly followed this thread (which is already closed) for troubleshooting, but with no success:
It does however work over the WAN port though, yet I need to make it work over the LAN port
Appreciate creative ideas on how to troubleshoot and make it work.
Please copy the output of the following commands and post it here using the "Preformatted text </> " button:
Remember to redact passwords, MAC addresses and any public IP addresses you may have:
Your assumption about another router upstream is correct.
I’m not certain what is the procedure in the forum to send a nice cold beer, you indeed deserve a big one.
Few things:
This guide which is the prevailing reference one is simply misleading, while ignoring those two rules which made me and so many others spend hours until you came up with the solution, saving plentiful additional hours.
If any moderator is listening, that is the time to step in and revise it.
On another issue: I do not see subnet 192.168.1.0 from the guest 192.168.2.0 network using my windows client, however, I’m able to access it with my android phone.
If I block all the traffic from the Guest network to the LAN as suggested in the last step of the guide, then I lose the internet connection as well.
The wiki article can be fixed, but let's figure out what specificially is misleading.
I do see masquerading being enabled on the lan zone at the end of step 3.
I don't see any reference to ensuring that the lan has a gateway defined <---- this seems like a needed update.
Anything else that caused issues for you??
I happen to be a moderator, but actually, the wiki can be edited by anyone once access is granted (see this page for more info).
But you are the second person to say that there are some issues, so I'll see if I can take some time to fix the errors in that article.
This suggests that Windows Firewall may be the reason for this.
if you look more carefully at the guide, you'll see that it isn't blocking all guest > lan, but rather blocking traffic that is going from guest > lan with destination address 192.168.1.0/24. Make sure you have the address in there and it should fix that part.
But note that once you do that, your comment earlier about the windows client not being able to see the 192.168.1.0/24 network (but your android client can) all becomes moot because this will block that by a specific firewall rule.
If your problem is solved, please consider marking this topic as [Solved]. See How to mark a topic as [Solved] for a short how-to.
Thanks again for the profound support, I’m fairly new here and indeed not used to such prompt and effective solutions.
[psherman]: I do see masquerading being enabled on the lan zone at the [end of step 3]
You are right, easy to miss and I did, probably since those are the interfaces that we did not add and aim to configure. I suggest highlighting all the key elements in the graphic with red circles
[psherman]: if you look more carefully at the guide, you'll see that it isn't blocking all guest > lan, but rather blocking traffic that is going from guest > lan with destination address 192.168.1.0/24. Make sure you have the address in there and it should fix that part.
It is there and solving the problem. Also easy to miss, I suggest highlighting it with a red circle as well.