Jeff, I think our definitions of "straightforward" are quite different and you're way ahead of me.
Intent is:
two internal firewall zones "lan" and "guest"
"lan" firewall zone includes 3 ports of the switch and the "home" SSID on both wifi bands
"guest" zone includes 1 port and the "guest" SSID
traffic is allowed from guest to wan, from lan to guest but not from guest to lan
This way I can segregate a fussy wired client in the guest segment when needed.
I gave your settings a spin and, touch wood, it looks like what I wanted: the key insight is "away from vid 1 and 2". Other than that, even configuring via LUCI gives the expected result. Thanks
EDIT, adding key parts of the config to help others:
Good evening everyone, I was wondering if you could help me with a problem very similar to the one discussed here? I've read through the thread but still can't quite grasp what I'm doing wrong.
What I'm trying to do:
PPPoE on eth1
VLAN 42: 0 tagged. 1, 2, 3 untagged (lan)
VLAN 99: 0 tagged. 4 untagged (guest - I wanna run an old OpenWRT router for guest wifi here).
Now as soon as I Save & Apply this, my PPPoE on eth1 stops working.
The error said something along the lines Timeout waiting for PADO packets Unable to complete PPPoE Discovery
I don't get how changing anything on eth0 would effect eth1?
Any help would be greatly appreciated
[EDIT fixed screenshot as error pointed out by @aboaboit]
"it" in the context of this last few posts in this discussion means "pppoe" wan.
Again, I have two VLANs numbered 101 and 102, no port 5 and I'm obviously online.
I think the 4040 does indeed have a separate eth device for wan, while the local ports are part of the switch.
Unlike my older devices, which used a switch port for wan.
As soon as I commit this, PPPoE on WAN dies with "PEER DEAD" followed by "Connection attempt failed"
This is from syslog at that moment:
Sun Aug 11 10:58:55 2019 daemon.notice netifd: Interface 'wan' is now down
Sun Aug 11 10:58:55 2019 daemon.notice netifd: Interface 'wan' is setting up now
Sun Aug 11 10:58:55 2019 daemon.err insmod: module is already loaded - slhc
Sun Aug 11 10:58:55 2019 daemon.err insmod: module is already loaded - ppp_generic
Sun Aug 11 10:58:55 2019 daemon.err insmod: module is already loaded - pppox
Sun Aug 11 10:58:55 2019 daemon.err insmod: module is already loaded - pppoe
Sun Aug 11 10:58:56 2019 daemon.info pppd[6192]: Plugin rp-pppoe.so loaded.
Sun Aug 11 10:58:56 2019 daemon.info pppd[6192]: RP-PPPoE plugin version 3.8p compiled against pppd 2.4.7
Sun Aug 11 10:58:56 2019 daemon.notice pppd[6192]: pppd 2.4.7 started by root, uid 0
Sun Aug 11 10:59:11 2019 daemon.warn pppd[6192]: Timeout waiting for PADO packets
Sun Aug 11 10:59:11 2019 daemon.err pppd[6192]: Unable to complete PPPoE Discovery
And here's /etc/config/network
config interface 'lan'
option type 'bridge'
option proto 'static'
option netmask '255.255.255.0'
option ip6assign '60'
option ipaddr '192.168.42.1'
option dns '1.1.1.1'
option ifname 'eth0.42'
Thanks. I'm not entirely sure why you'd even have both vlan and vid. It sounds to me like one's the actual VLAN and the other is a name, a label for it?
Anyway, I'm seeing the config for the first time, didn't realize LuCI only sets vid, not vlan. I'll try changing vlan next.