Temat: Odciecie Guest Wifi
Czesc
Mam problem z guest wifi: Chcialbym aby goscie nie mogli sie dostac do routera bedac podpieci do wifi(chcialbym zablokowac nawet pingi od strony guesta do routera nie mowiac juz o ssh i https). Chcialem skonfigurowac w firewallu cos w stylu deny any any a pozniej wykluczac poszczegolne uslugi. Jednak cos robie zle i nie moge osiagnac nawet czegos tak prostego. Prosze o pomoc.
Moj konfig:
/etc/config/firewall
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option src 'WLAN_GUEST'
option dest_port '53'
option proto 'tcpudp'
option target 'ACCEPT'
option name 'Allow_dhcp'
config rule
option src 'WLAN_GUEST'
option src_port '67-68'
option dest_port '67-68'
option proto 'udp'
option target 'ACCEPT'
option name 'Allow_DNS'
config rule
option name 'Disable_any_input192'
option src 'WLAN_GUEST'
option target 'DROP'
option src_ip '192.168.0.0/24'
option dest_ip '192.168.0.1'
option proto 'all'
config rule
option name 'Disable_any_input10'
option src 'WLAN_GUEST'
option target 'DROP'
option src_ip '192.168.0.0/24'
option dest_ip '10.10.10.1'
option proto 'all'
config rule
option name 'Disable_any_forward'
option proto 'all'
option src 'WLAN_GUEST'
option target 'DROP'
list icmp_type 'host-unreachable'
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option disable_ipv6 '1'
option drop_invalid '1'
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option network 'lan'
config zone
option name 'wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
option network 'wan'
config forwarding
option src 'lan'
option dest 'wan'
config include
option path '/etc/firewall.user'
config zone
option name 'WLAN_GUEST'
option output 'ACCEPT'
option forward 'REJECT'
option input 'ACCEPT'
option network 'wlan_guest'
config forwarding
option dest 'wan'
option src 'WLAN_GUEST'/etc/config/dhcp
config dnsmasq
option domainneeded '1'
option boguspriv '1'
option localise_queries '1'
option rebind_protection '1'
option rebind_localhost '1'
option local '/lan/'
option domain 'lan'
option expandhosts '1'
option authoritative '1'
option readethers '1'
option leasefile '/tmp/dhcp.leases'
option resolvfile '/tmp/resolv.conf.auto'
config dhcp 'lan'
option interface 'lan'
option start '100'
option limit '120'
option leasetime '2h'
config dhcp 'wan'
option interface 'wan'
option ignore '1'
config dhcp
option start '100'
option limit '150'
option interface 'wlan_guest'
option leasetime '2h'/etc/config/wireless
config wifi-device 'radio0'
option type 'mac80211'
option macaddr 'XXX'
list ht_capab 'SHORT-GI-40'
list ht_capab 'TX-STBC'
list ht_capab 'RX-STBC1'
list ht_capab 'DSSS_CCK-40'
option hwmode '11g'
option country 'PL'
option txpower '5'
option channel '3'
config wifi-device 'radio1'
option type 'mac80211'
option channel '36'
option macaddr 'XXX'
option hwmode '11na'
option htmode 'HT40'
list ht_capab 'SHORT-GI-40'
list ht_capab 'TX-STBC'
list ht_capab 'RX-STBC1'
list ht_capab 'DSSS_CCK-40'
option disabled '1'
option country 'PL'
option txpower '0'
config wifi-iface
option device 'radio0'
option mode 'ap'
option ssid 'wifi0'
option encryption 'psk2+ccmp'
option key 'XXX'
option network 'wlan_guest'
config wifi-iface
option device 'radio0'
option mode 'ap'
option ssid 'wifi1'
option network 'lan'
option macfilter 'allow'
list maclist 'XXX'
option encryption 'psk2+ccmp'
option key 'XXX'/etc/config/network
config interface 'loopback'
option ifname 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config interface 'lan'
option ifname 'eth0'
option type 'bridge'
option proto 'static'
option netmask '255.255.255.128'
option ipaddr '10.10.10.1'
config interface 'wan'
option ifname 'eth1'
option proto 'dhcp'
config switch
option name 'eth0'
option reset '1'
option enable_vlan '0'
config switch_vlan
option device 'eth0'
option vlan '1'
option ports '0 1 2 3 4'
config interface 'wlan_guest'
option _orig_ifname 'wlan0'
option _orig_bridge 'false'
option proto 'static'
option ipaddr '192.168.0.1'
option netmask '255.255.255.0'