I'm a newbie at this and hope someone can help me out with my home network design. I would like to create multiple network segments (Internal, IoT and Guests) spanning both wired and wireless interfaces. I created a simple network diagram which hopefully does provide sufficient information:
I am struggling with the interface and VLAN configurations. I checked several guides, but they did not help me out. I assume the main difference between my setup and the ones that I found in the guides is that my OpenWRT router will not be operating as a modem (no ISP connection). It will only act as a router, provide WiFi and separate network flows.
Any help is much appreciated!
In the last part of the OpenWrt it is quite clear. You'll have 3 interfaces for lan, iot, and guest, bridged with the wifi ssid.
But how is the uplink to the isp modem? Is there a wan interface or are you going to extend the lan?
Is there going to be any host on the managed switch too? If yes on which vlan?
Thanks for your reply Trendy! To answer your questions:
The uplink to the ISP is handled by the ISP modem, which is a separate DSL modem. The OpenWRT router will be added to my current network.
The managed switch will have some devices connected as well. One of these devices is an IoT device, all the other ones are internal devices. I have not decided on the exact VLAN configuration yet. I assume I need three: one for my internal network, one for the IoT devices and one for the Guest network?
Thanks Wulfy23, your feedback is much appreciated!
I will check the VLAN configurations as suggested. My concerns for now are on how to create the interfaces, how to get DHCP for the different subnets working etc. I'm not very familiar with the LuCi GUI yet.
Anyone else that can help me out? I'm stuck here and have no idea where to look further.
I've created the interfaces, wireless SSID's and VLANs. Here's what I experience:
connecting to the wireless SSID Home works fine, I can surf the internet.
connecting to the wireless SSID IoT is possible, however I can't reach the internet.
connecting to the wireless SSID Guest does not give me an IP address at all.
Hi Trendy, thanks for the feedback!
I did the following modifications:
removed the 2nd dhcp instcance for guests
changed the fw zone
changed the wireless interface name
got rid of the uppercases
DHCP on the Guest WiFi network now works fine.. so that's great. But I still do not have internet acces on both IoT and Guest WiFi networks. I did connect with my laptop and noticed that I can ping all the IP's on the OpenWrt but no IP's outside of the OpenWrt.
Could this be a routing issue?
Add static routes in the ISP modem for the iot and guest networks via the R7800.
Or enable masquerade on home zone (I presume this is the uplink to the ISP modem).
I'd encourage you to put the openwrt device immediately after the isp modem and do all your routing in the openwrt device. You can put the managed switch downstream of the openwrt device to get more wired ports... This is both more secure and easier to manage
I assume you got the managed switch for WAN tagging, right? I have the same setup with the same router and here is the switch config you can use. It tags WAN with VLAN 35 and creates three VLAN's (11, 22, 33) on three LAN ports while keeping one LAN port for LAN.
The next step is to create Interfaces on eth1.11, eth1.22, and eth1.33. Then you switch your WAN interface to use eth0.35 (or some other tag you need to use).
The switch between the modem and router is not needed.
I got the managed switch as I needed more physical ports and also wanted to be able to separate networks by means of VLANs.
The ISP modem is a simple ADSL modem, which just delivers the internet connection. It has not many possibilities, therefore I added the OpenWrt router. This router will need to provide multiple wireless networks and separate networks. So far I managed to configure the interfaces, wireless networks, DHCP and VLANs. But somehow I only have internet access on the home (wired and wireless) connection. I do get correct IP addresses in the IoT and Guests networks, but am not able to reach to internet.
I disabled the firewall as I do not need it (the firewall on my ISP modem is already enabled) and therefore have not configured firewall rules.
Apart from that, it's pretty straightforward