Isolation of guests (wireless+wired) - MikroTik (2024)

Post Reply

  • Print view
remonboonstra

just joined

Topic Author

Posts: 17
Joined: Sun Aug 30, 2015 12:08 am

Isolation of guests (wireless+wired)

  • Quote
  • #1

Sun Jul 16, 2023 3:08 pm

Hi,

I've got the current setup being:
Internet (pppoe) -> (ETH1) Mikrotik (ETH5)-> TPlink TL-sg1016de -> Netgear Orbi (in Access Point mode: guest and normal)

The tp-link has wired clients:
- iptv settop boxes using vlan 4
- normal clients
- guest clients
The Orbi has two SSIDs:
- guest
- normal

the TPlink is on ETH5 of the Mikrotik.

My goal:
- have guests being able to join the network on the Guest SSID and on the TP-Link without accessing the Normal network.
- On the TP-link I just want to connect the Guest without thinking about what port.

I'm a little lost in what would be the best setup.

I thought about forwarding all 16 ports with separate VLAN's and let the mikrotik decide on what to do with the devices with rules. But I'm in doubt.
I also thought of buying mikrotik accesspoints to remove the Orbi...

Anyone willing to help think about a solution?
Thanks!

Top

anav

Forum Guru
Isolation of guests (wireless+wired) - MikroTik (3)

Posts: 20029
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Isolation of guests (wireless+wired)

  • Quote
  • #2

Sun Jul 16, 2023 3:23 pm

Dont worry about ports etc..
Thinks about it from the user perspective.
what user(s)/device(s), groups of users/devices do you have.
what traffic should they have.

Then draw a network diagram to illustrate what equipment you have ( no one here knows TP link models off the top of their head what is the device?) etc...
Assuming you are thinking vlans so put notes on the diagram as to what subnets you plan on using............

One last question, for now, when you say isolation, do you mean isolate by vlans for exaample or do you mean wifi clients and wired clients on the same subnet, think home users on pcs wired and then home users using smart phone............ no need to isolate that traffic. so what exactly are you trying to isolate..........

Top

remonboonstra

just joined

Topic Author

Posts: 17
Joined: Sun Aug 30, 2015 12:08 am

Re: Isolation of guests (wireless+wired)

  • Quote
  • #3

Sun Jul 16, 2023 10:10 pm

Thank you Anav,

I will try to think about it in another way.

The problem I see now is that I have evrything working, I just want guest wifi users isolated = not reaching my main network. And some pc’s isolated (kids game pc due to virus/hacking etc) from main network.

In the past I had guest wifi isolated and the pc’s in front of my main networks’ router (orbi at that point). Thus all guests were not on the main network.

By moving away from that setup, I now have all guests an my network!

Reason for mentioning the tp-link is that it is a (cheap) managed switch.

When looking at the future, I will buy 3x Cap Ax to replace the orbi, that setup allows at least wifi guests to be isolated (due to more control).

Then I still have the pc’s that are wired.

Is there a way to identify those, allowing me to put hem in a vlan or something else? The issue is that they go through the tplink and thus able to take a shortcut to main network machines.

Top

anav

Forum Guru
Isolation of guests (wireless+wired) - MikroTik (6)

Posts: 20029
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Contact anav

Re: Isolation of guests (wireless+wired)

  • Quote
  • #4

Mon Jul 17, 2023 12:50 am

Ahh cheap managed switches are our salvation. Miracles can happen.

In this case create a separate vlan for wired and wifi guests and a separate vlan for gaming/kids.

Done!

Top

jvanhambelgium

Forum Guru
Isolation of guests (wireless+wired) - MikroTik (8)

Posts: 1041
Joined: Thu Jul 14, 2016 9:29 pm
Location: Belgium

Re: Isolation of guests (wireless+wired)

  • Quote
  • #5

Mon Jul 17, 2023 7:25 am

This requirement ;

- have guests being able to join the network on the Guest SSID and on the TP-Link without accessing the Normal network.
- On the TP-link I just want to connect the Guest without thinking about what port.

This cannot be done without 802.1x implementation on the switch-side. Your TP-LINK switch-model does not support this, hence you will never have the (dynamic) option to plug something "without thinking" and have it end up as "Guest" or "Normal" (V)LAN.
For the "any port any service" approach, 802.1x comes into play.

Top

remonboonstra

just joined

Topic Author

Posts: 17
Joined: Sun Aug 30, 2015 12:08 am

Re: Isolation of guests (wireless+wired)

  • Quote
  • #6

Thu Jul 20, 2023 10:13 am

Thank you jvanhambelgium,

That clears that point. Then I'm back to creating a port-based VLAN for the kids machines on dedicated ports Isolation of guests (wireless+wired) - MikroTik (10)
Wireless should be solved by getting CAP AX Access Points, which do support VLAN for (Guest) SSID's, the Orbi really doesn't.

Will look into that Isolation of guests (wireless+wired) - MikroTik (11)

Top

anav

Forum Guru
Isolation of guests (wireless+wired) - MikroTik (13)

Posts: 20029
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Contact anav

Re: Isolation of guests (wireless+wired)

  • Quote
  • #7

Thu Jul 20, 2023 1:54 pm

Correct, consumer APs are frustrating in that regard. What they do is typically create a guest network on the same subnet but block traffic between the guest wifi and the house wifi and the guest wifi from the wired portion of the LAN............... Guest to internet only. So tis limited.

Top

Post Reply

  • Print view

Who is online

Users browsing this forum: Ahrefs [Bot], Amazon [Bot], Bing [Bot], Google [Bot], jampa25 and 31 guests

Isolation of guests (wireless+wired) - MikroTik (2024)

References

Top Articles
Latest Posts
Article information

Author: Trent Wehner

Last Updated:

Views: 5810

Rating: 4.6 / 5 (76 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Trent Wehner

Birthday: 1993-03-14

Address: 872 Kevin Squares, New Codyville, AK 01785-0416

Phone: +18698800304764

Job: Senior Farming Developer

Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.