I just started using OpenWRT and been tinkering with it all day yesterday. First I got a wireguard tunnel for all traffic working, but don't seem to be able to get guest wifi working. I followed the guide provided (although zones are a bit 'more accepting' for testing atm). After many hours I read a wireguard connection can't be shared between zones, so decided to delete the wg for now. I expecting to get guest wifi working now, but no go. I deleted wireguard en guest wifi for a fresh start, but same same. I did read other topics with this problem, but this did not fix my problem. I spend to many hours chasing this already ![]()
Situation:
I got an existing network (192.168.178.0/24) to which OpenWRT (10.0.0.0/24) is connected until I get everything working and stable to replace my main router.
Problem:
Normal wifi is working, but guest wifi is not. I can ping 10.0.0.1 from guest wifi, but not 192.168.178.251 (pi-hole) (i can from normal wifi). I believe I got both zones and traffic rules set up the same way for both radios, but I guess not...
Really appreciate any help.
"kernel": "6.6.110",
"hostname": "OpenWrt",
"system": "ARMv8 Processor rev 4",
"model": "Zyxel EX5601-T0 ubootmod",
"board_name": "zyxel,ex5601-t0-ubootmod",
"rootfs_type": "squashfs",
"release": {
"distribution": "OpenWrt",
"version": "24.10.4",
"revision": "r28959-29397011cc",
"target": "mediatek/filogic",
"description": "OpenWrt 24.10.4 r28959-29397011cc",
"builddate": "1760891865"
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fd3a:8df8:660c::/48'
option packet_steering '1'
config device
option name 'br-lan'
option type 'bridge'
list ports 'lan1'
list ports 'lan2'
list ports 'lan3'
list ports 'lan4'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '10.0.0.1'
option netmask '255.255.255.0'
option ip6assign '60'
config interface 'wan'
option device 'eth1'
option proto 'dhcp'
config interface 'wan6'
option device 'eth1'
option proto 'dhcpv6'
config device
option type 'bridge'
option name 'br-guest'
option bridge_empty '1'
config interface 'guest'
option proto 'static'
option device 'br-guest'
option ipaddr '10.0.90.0'
option netmask '255.255.255.0'
option gateway '192.168.178.251'
config defaults
option input 'REJECT'
option output 'REJECT'
option forward 'REJECT'
option synflood_protect '1'
option drop_invalid '1'
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'lan'
config zone
option name 'wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'ACCEPT'
option masq '1'
option mtu_fix '1'
list network 'wan'
list network 'wan6'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option src 'lan'
option name 'Allow_DNS_IN'
option family 'ipv4'
option target 'ACCEPT'
option src_port '53'
option dest_port '53'
list proto 'tcp'
list proto 'udp'
option enabled '0'
config rule
option name 'Allow_DNS_OUT'
option family 'ipv4'
option target 'ACCEPT'
option src_port '53'
option dest_port '53'
list proto 'tcp'
list proto 'udp'
option dest 'wg_proton'
option enabled '0'
config rule
option dest 'lan'
option name 'Allow_SSH_OUT'
list proto 'tcp'
option src_port '22'
option target 'ACCEPT'
option enabled '0'
config rule
option dest 'wg_proton'
option name 'Allow_HTTP(S)_OUT'
list proto 'tcp'
option dest_port '80 443'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config zone
option name 'wg_proton'
option input 'DROP'
option output 'DROP'
option forward 'DROP'
option masq '1'
config forwarding
option src 'lan'
option dest 'wan'
config zone
option name 'guest'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
list network 'guest'
config forwarding
option src 'guest'
option dest 'wan'
config rule
option src 'guest'
option name 'Guest-DNS'
option dest_port '53'
option target 'ACCEPT'
config rule
option src 'guest'
option name 'Guest-DHCP'
list proto 'udp'
option dest_port '67'
option target 'ACCEPT'
