Hello Everyone,
I am currently setting up a guest network on my OpenWRT Router on a CM4. But one issue with it is that my guest network can access my management LuCI and SSH, which is a major security risk. I have my wireless handled through a Cisco 5508 WLC, So that’s not a issue. The only thing is preventing the guest VLAN from accessing LuCI or SSH.
My guest VLAN is tagged with 802.1q (Guest is 963, Mgmt is 71) and I tried implementing Traffic Rules to prevent HTTP, HTTPS, SSH, and permitting DNS and DHCP, and I have my LuCI only accessible through the Management IP. Wireless and wired versions of the guest network are able to bypass the firewalls rules preventing the guest VLAN IP Range from talking to the Management VLAN IP Range, so I had to try to resort to traffic rules.
If someone could help me out that would be very apricated. And if anyone has questions about the setup to try to help me resolve this I will try to answer as fast as possible, but these photos should help you out.
