Do you mean that you can access the OpenWrt administration (i.e. ssh/LuCI web)?
That's right, ssh and LuCI web are accessible. Changing the vlan zone to input=reject or drop makes OpenWrt inaccessible.
Keep in mind that it will also prevent the use of DHCP and DNS on that network (unless you create some additional firewall rules to allow this). If you're not using the OpenWrt Pi as DNS, and if you're setting the WAN2 address as static on the USG, you don't need to do anything more.
Great, the plan is to use OpenWrt as a VPN secured WWAN without DHCP or DNS (except the 'management' eth0
DHCP client).
try putting another computer directly onto VLAN 101 (via your switch) with a static IP, then see what happens if you google "what's my IP"
I've configured port 3 on the switch to be with the profile of the VLAN-only network. Attached a computer with a static 192.168.101.50
IP and can only see the Pi on 192.168.101.1
. Nothing else seems to be accessible.
The switch port connecting to the Pi needs to be a trunk with VLAN 101 tagged and whatever VLAN you've got for management set as native/untagged.
I'm not sure if this is correct, but the Pi switch port is set to Profile: All. There doesn't seem to be a lot more in the port settings through the UI as far as I can see.
The switch port connecting to the Pi needs to be a trunk with VLAN 101 tagged and whatever VLAN you've got for management set as native/untagged.
Assuming that the current configuration is as described, because I can see the Pi on via port 3 using another computer, and can see it as a client to the router's DHCP.
I'm pretty sure that you need to set VLAN101 should be set as a VLAN only network because the USG isn't "in control" of it, but maybe that is not the case since the USG is actually a client on that VLAN for WAN2.
VLAN 101 is set to VLAN-only network in the Unifi settings.
But you need to make sure that the switch port that connects to USG eth2/WAN2 is set to VLAN 101 (tagged) and no other VLANs on that port.
What I find strange is that the USG can only see the Pi if port 9 is set to Profile: All. Right now I have an identical switch port configuration for port 3 that I just tested with another computer and port 9 that goes to the USG. Not getting an answer from the Pi:
ubnt@ubnt:~$ sudo ping 192.168.101.1 -I eth2.101
PING 192.168.101.1 (192.168.101.1) from 192.168.101.2 eth2.101: 56(84) bytes of data.
The other way to handle this situation would be to set the switchport that connects to the USG WAN2 port to native/untagged VLAN101, and then set WAN2 on the USG such that it is not using a VLAN. That will, for sure, make it possible to make VLAN 101 a "VLAN only" network from the perspective of Unifi.
Maybe that is the way to go, considering the Pi can route traffic, although the Unifi forums thread suggests that the configuration there has all ports set to VLAN 200 as far as I understand.