Temat: Sieć gościnna - brak komunikacji ze światem
Witam,
Skonfigurowałem kiedyś sieć gościnną zgodnie z poradnikiem na http://openrouter.info/forum/viewtopic. … &t=967 i kiedyś to działało.
Za jakiś czas sieć gościnna przestała być widoczna i skonfigurowałem wszystko jeszcze raz.
Klient połączony z siecią gościnną dostaje adres z DHCP ale nie może otworzyć google.pl ani żadnej innej strony.
Poniżej konfiguracja
root@Gargoyle:~# uci show wireless
wireless.radio0=wifi-device
wireless.radio0.type=mac80211
wireless.radio0.hwmode=11ng
wireless.radio0.path=platform/ath9k
wireless.radio0.htmode=HT20
wireless.radio0.ht_capab=SHORT-GI-40 DSSS_CCK-40
wireless.radio0.noscan=1
wireless.radio0.channel=1
wireless.ap_g=wifi-iface
wireless.ap_g.device=radio0
wireless.ap_g.mode=ap
wireless.ap_g.network=lan
wireless.ap_g.ssid=WiFi_PM
wireless.ap_g.encryption=psk
wireless.ap_g.key=**********
wireless.guest=wifi-iface
wireless.guest.device=radio0
wireless.guest.mode=ap
wireless.guest.network=guest
wireless.guest.ssid=WiFi_PM_Gosc
wireless.guest.encryption=psk
wireless.guest.key=**********
root@Gargoyle:~# uci show network
network.loopback=interface
network.loopback.ifname=lo
network.loopback.proto=static
network.loopback.ipaddr=127.0.0.1
network.loopback.netmask=255.0.0.0
network.lan=interface
network.lan.ifname=eth0.1
network.lan.type=bridge
network.lan.proto=static
network.lan.ipaddr=192.168.1.1
network.lan.netmask=255.255.255.0
network.lan.dns=208.67.222.222 208.67.220.220
network.wan=interface
network.wan.ifname=eth0.2
network.wan.proto=static
network.wan.ipaddr=192.168.100.2
network.wan.netmask=255.255.255.0
network.wan.gateway=192.168.100.1
network.wan.dns=208.67.222.222 208.67.220.220
network.wan.peerdns=0
network.@switch[0]=switch
network.@switch[0].name=rtl8366rb
network.@switch[0].reset=1
network.@switch[0].enable_vlan=1
network.@switch_vlan[0]=switch_vlan
network.@switch_vlan[0].device=rtl8366rb
network.@switch_vlan[0].vlan=1
network.@switch_vlan[0].ports=1 2 3 4 5t
network.@switch_vlan[1]=switch_vlan
network.@switch_vlan[1].device=rtl8366rb
network.@switch_vlan[1].vlan=2
network.@switch_vlan[1].ports=0 5t
network.vpn=interface
network.vpn.ifname=tun0
network.vpn.proto=none
network.vpn.defaultroute=0
network.vpn.peerdns=0
network.guest=interface
network.guest.proto=static
network.guest.netmask=255.255.255.0
network.guest.ipaddr=10.20.30.1
network.guest.type=bridge
root@Gargoyle:~# uci show dhcp
dhcp.@dnsmasq[0]=dnsmasq
dhcp.@dnsmasq[0].domainneeded=1
dhcp.@dnsmasq[0].boguspriv=1
dhcp.@dnsmasq[0].filterwin2k=0
dhcp.@dnsmasq[0].localise_queries=1
dhcp.@dnsmasq[0].rebind_protection=1
dhcp.@dnsmasq[0].rebind_localhost=1
dhcp.@dnsmasq[0].local=/lan/
dhcp.@dnsmasq[0].domain=lan
dhcp.@dnsmasq[0].expandhosts=1
dhcp.@dnsmasq[0].nonegcache=0
dhcp.@dnsmasq[0].authoritative=1
dhcp.@dnsmasq[0].readethers=1
dhcp.@dnsmasq[0].leasefile=/tmp/dhcp.leases
dhcp.@dnsmasq[0].resolvfile=/tmp/resolv.conf.auto
dhcp.lan=dhcp
dhcp.lan.interface=lan
dhcp.lan.start=100
dhcp.lan.limit=150
dhcp.lan.leasetime=12h
dhcp.wan=dhcp
dhcp.wan.interface=wan
dhcp.wan.ignore=1
dhcp.guest=dhcp
dhcp.guest.start=100
dhcp.guest.interface=guest
dhcp.guest.limit=120
dhcp.guest.leasetime=1h
root@Gargoyle:~#
root@Gargoyle:~# uci show firewall
firewall.@defaults[0]=defaults
firewall.@defaults[0].syn_flood=1
firewall.@defaults[0].input=ACCEPT
firewall.@defaults[0].output=ACCEPT
firewall.@defaults[0].forward=REJECT
firewall.@zone[0]=zone
firewall.@zone[0].name=lan
firewall.@zone[0].network=lan
firewall.@zone[0].input=ACCEPT
firewall.@zone[0].output=ACCEPT
firewall.@zone[0].forward=REJECT
firewall.@zone[1]=zone
firewall.@zone[1].name=wan
firewall.@zone[1].network=wan wan6
firewall.@zone[1].input=REJECT
firewall.@zone[1].output=ACCEPT
firewall.@zone[1].forward=REJECT
firewall.@zone[1].masq=1
firewall.@zone[1].mtu_fix=1
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src=lan
firewall.@forwarding[0].dest=wan
firewall.@rule[0]=rule
firewall.@rule[0].name=Allow-DHCP-Renew
firewall.@rule[0].src=wan
firewall.@rule[0].proto=udp
firewall.@rule[0].dest_port=68
firewall.@rule[0].target=ACCEPT
firewall.@rule[0].family=ipv4
firewall.@rule[1]=rule
firewall.@rule[1].name=Allow-Ping
firewall.@rule[1].src=wan
firewall.@rule[1].proto=icmp
firewall.@rule[1].icmp_type=echo-request
firewall.@rule[1].family=ipv4
firewall.@rule[1].target=ACCEPT
firewall.@rule[2]=rule
firewall.@rule[2].name=Allow-DHCPv6
firewall.@rule[2].src=wan
firewall.@rule[2].proto=udp
firewall.@rule[2].src_ip=fe80::/10
firewall.@rule[2].src_port=547
firewall.@rule[2].dest_ip=fe80::/10
firewall.@rule[2].dest_port=546
firewall.@rule[2].family=ipv6
firewall.@rule[2].target=ACCEPT
firewall.@rule[3]=rule
firewall.@rule[3].name=Allow-ICMPv6-Input
firewall.@rule[3].src=wan
firewall.@rule[3].proto=icmp
firewall.@rule[3].icmp_type=echo-request echo-reply destination-unreachable pacet-too-big time-exceeded bad-header unknown-header-type router-solicitation neihbour-solicitation router-advertisement neighbour-advertisement
firewall.@rule[3].limit=1000/sec
firewall.@rule[3].family=ipv6
firewall.@rule[3].target=ACCEPT
firewall.@rule[4]=rule
firewall.@rule[4].name=Allow-ICMPv6-Forward
firewall.@rule[4].src=wan
firewall.@rule[4].dest=*
firewall.@rule[4].proto=icmp
firewall.@rule[4].icmp_type=echo-request echo-reply destination-unreachable pacet-too-big time-exceeded bad-header unknown-header-type
firewall.@rule[4].limit=1000/sec
firewall.@rule[4].family=ipv6
firewall.@rule[4].target=ACCEPT
firewall.@include[0]=include
firewall.@include[0].path=/etc/firewall.user
firewall.@include[0].reload=1
firewall.@include[1]=include
firewall.@include[1].type=script
firewall.@include[1].path=/usr/lib/gargoyle_firewall_util/gargoyle_additions.fiewall
firewall.@include[1].family=IPv4
firewall.@include[1].reload=1
firewall.miniupnpd=include
firewall.miniupnpd.type=script
firewall.miniupnpd.path=/usr/share/miniupnpd/firewall.include
firewall.miniupnpd.family=IPv4
firewall.miniupnpd.reload=1
firewall.openvpn_include_file=include
firewall.openvpn_include_file.path=/etc/openvpn.firewall
firewall.openvpn_include_file.reload=1
firewall.ra_443_444=remote_accept
firewall.ra_443_444.local_port=443
firewall.ra_443_444.remote_port=444
firewall.ra_443_444.proto=tcp
firewall.ra_443_444.zone=wan
firewall.ra_22_2200=remote_accept
firewall.ra_22_2200.local_port=22
firewall.ra_22_2200.remote_port=2200
firewall.ra_22_2200.proto=tcp
firewall.ra_22_2200.zone=wan
firewall.@rule[5]=rule
firewall.@rule[5].name=wwwmeteo
firewall.@rule[5].src=wan
firewall.@rule[5].target=ACCEPT
firewall.@rule[5].proto=tcp
firewall.@rule[5].dest_port=81
firewall.vpn_zone=zone
firewall.vpn_zone.name=vpn
firewall.vpn_zone.network=vpn
firewall.vpn_zone.input=ACCEPT
firewall.vpn_zone.output=ACCEPT
firewall.vpn_zone.forward=ACCEPT
firewall.vpn_zone.mtu_fix=1
firewall.vpn_zone.masq=1
firewall.vpn_lan_forwarding=forwarding
firewall.vpn_lan_forwarding.src=lan
firewall.vpn_lan_forwarding.dest=vpn
firewall.ra_openvpn=remote_accept
firewall.ra_openvpn.zone=wan
firewall.ra_openvpn.local_port=1194
firewall.ra_openvpn.remote_port=1194
firewall.ra_openvpn.proto=udp
firewall.vpn_wan_forwarding=forwarding
firewall.vpn_wan_forwarding.src=vpn
firewall.vpn_wan_forwarding.dest=wan
firewall.@zone[2]=zone
firewall.@zone[2].name=guest
firewall.@zone[2].network=guest
firewall.@zone[2].output=ACCEPT
firewall.@zone[2].forward=REJECT
firewall.@zone[2].input=REJECT
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].src=guest
firewall.@forwarding[1].dest=wan
firewall.@rule[6]=rule
firewall.@rule[6].src=guest
firewall.@rule[6].proto=udp
firewall.@rule[6].src_port=67-68
firewall.@rule[6].dest_port=67-68
firewall.@rule[6].target=ACCEPT
firewall.@rule[6].family=ipv4
firewall.@rule[7]=rule
firewall.@rule[7].src=guest
firewall.@rule[7].dest_port=53
firewall.@rule[7].target=ACCEPT
firewall.@rule[7].family=ipv4
firewall.@rule[7].proto=tcpudp
firewall.@zone[3]=zone
firewall.@zone[3].name=guest
firewall.@zone[3].network=guest
firewall.@zone[3].input=REJECT
firewall.@zone[3].output=ACCEPT
firewall.@zone[3].forward=REJECT
firewall.@forwarding[2]=forwarding
firewall.@forwarding[2].src=guest
firewall.@forwarding[2].dest=wan
firewall.@rule[8]=rule
firewall.@rule[8].src=guest
firewall.@rule[8].proto=udp
firewall.@rule[8].src_port=67-68
firewall.@rule[8].dest_port=67-68
firewall.@rule[8].target=ACCEPT
firewall.@rule[8].family=ipv4
firewall.@rule[9]=rule
firewall.@rule[9].src=guest
firewall.@rule[9].dest_port=53
firewall.@rule[9].target=ACCEPT
firewall.@rule[9].family=ipv4
firewall.@rule[9].proto=tcpudp
root@Gargoyle:~#Może coś w firewall mam źle skonfigurowane?
Proszę o wskazówki.
Pozdr.