I have a Fritz.Box that works as DHCP for 192.168.178.x. DNS is provided by a Pi-Hole using unbound recursive DNS. The Fritz.Box provides several wireless networks on 2.4g and 5.0g IPv4 and IPv6 are working.
A TP-Link WPA8630P is connected via powerline/dLAN to the Fritz.Box, it works with OpenWRT 21.02.05. It provides the IOT wireless network on 2.4g. DNS and DHCP are passed through from the Fritz.Box and Pi-Hole. IPv4 an IPv6 are working as well.
Goal
I want further segmentation for wireless IOT devices. They should not be allowed to access other network devices, but for configuration purposes and app support they need to have internet access.
Method
I tried to configure a VLAN on the WPA8630P that
uses the device bridging the wireless and the powerline port while
traffic from the Fritz.Box arrives at the IOT devices and
traffic from the IOT devices can reach the internet and
IOT devices can not reach other devices on the same network.
The problem
I found literally hundreds of guides, video tutorials and how-tos for configuring VLANs with and without OpenWRT, but not a single one fully answered my questions. All my attempts resulted in either locking myself out of the WPA8630p LuCI or in reverting configuration changes after applying these changes failed. By now, I am totally confused and completely lost, to be honest.
Why am I posting here?
What settings do I need to configure? Not on a theoretical level, more in the sense of "click here, check that box, add x, remove y". I really wanted to understand VLAN configuration on the WPA8630P beforehand, but right now I just want to have a working solution and understand what was configured afterwards. My head hurts from all the conflicting information, the Youtube-video-tutorials I followed and all the non-working solutions I already tried...
If needed I can provide further information about the OpenWRT configuration, of course, but please forgive me if I say it directly: I need a beginners guide to VLANs on the WPA8630P, as I seem to be not smart enough to understand the configuration steps myself.
That actually sounds like a way easier idea. I will check the recipe right away, thanks a lot! My IOT devices are all wifi at the moment, 2.4g only. That's why I needed a separate wifi network in the first place, as I could not drive 2.4g/5.0g separately on the Fritz.Box guest network. With 5.0g active, installing the devices always was a pain.
Edit: Nope. I already failed following the recipe in the first step. I just can't get my around this as soon as the interface view does not match my LuCI. Usually, I am not that dumb, but this drives me completely insane
So, regarding your network setup - is the folowng diagram more-or-less how your setup is:
pi hole
(provide DNS for entire network)
|
internet --------------- Fritz!Box --------------- TP-Link WPA8630P
(not openwrt) (openwrt)
| |
Gateway for non-IoT devices Gateway for IoT devices
(ethernet, 2.4g, 5g) (2.4g only)
If this is accurate, Im pretty sure your VLAN setups arent working because you need to set up VLANs on the Fritz!Box, not on the TP-Link WPA8630P. If the TP-Link WPA8630P is already only serving IoT devices there no real need for VLANs (unless you want to add another layer of separation between different IoT devices, though IDK how much security this adds over just using wifi isolation). From the TP-Link WPA8630P's point of view all the devices you dont want to communicate with it (i.e., the rest of your network) arent on LAN at all...theyre on WAN.
I started dumping the config files, maybe the initial setup of the device is part of the reason why my brain just stalls when trying to get this working...
That ist absolutely accurate. Amazing you were able to draw this from my description. And... you may have a good point there. I am able to ping the iot device IPs from non-iot devices, though. EDIT: And from Network/Diagnostics within LuCI I can't ping the non-iot devices.
It looks like I actually confused everything up - the setup right now already serves my needs, as it seems. There is no real need for another layer of segmentation.
I'm sorry... I gave you the wrong advice before. If your OpenWrt router is not the main router, you need to set it up as a dumb AP and then for the iot network, you'll setup the guest wifi on a dumb ap
I had a closer look at this solution tonight to further strengthen LAN/device-boundaries and implemented it with most of my original configuration. Turns out, this works a charm! Perfect solution, no need for VLAN segmentation (aka "overkill") anymore. The guide is super-awesome and easy to follow through AND in the end I got to learn the details - that's how I like it.
Thank you very much for your help, I am extremely pleased with the outcome!