Mesh network over VLAN

Currently reading
Mesh network over VLAN

3
0
NAS
DS218+, DS420+
Router
  1. RT2600ac
  2. MR2200ac
Operating system
  1. macOS
Mobile operating system
  1. iOS
I have a mesh network with system default guest network activated. The problem is guests can connect to the ethernet port of any wifi point and be assigned an IP address from my main LAN so bypassing the guest network. Since SRM does not support 802.1x ethernet authentication (only wireless through radius server) I wonder if
I can deploy the mesh network on a separate VLAN so that my MR2200AC WIFI points broadcast only the VLAN SSID and connecting to the ethernet port of my MR2200AC WIFI points I get an IP address from the VLAN. Is this possible?

My set up: 1 RT2600AC and 3 MR2200AC with SRM 1.3

Thank you in advance for any suggestion.
 
Welcome to the forum.

From what I read you have your mesh setup and working. The question is: if people have physical access to any of the routers (primary or mesh AP) and plug an Ethernet cable from their device to one of the LAN ports (or WAN in the case of a mesh AP), is there a way to stop them getting assigned access to the primary network?

I don't think there is a way to configure the mesh AP LAN ports to use specific VLANs, or disable the LAN port completely. But I wonder if there are a couple of ways to do something.
  1. Configure the primary network to be useless: use the SRM firewall to block access to the Internet and other VLANs. This will force wired devices to have to use VLAN tags when connecting and most (devices and people) won't be capable of doing this.
  2. Use wired back haul from the mesh APs to a primary router's LAN port that has been specifically assigned to a different VLAN. Any devices connecting to the mesh AP's other LAN ports will get placed on this VLAN.
Something like that might work, I haven't tried it. But you have a good point about the need to have more configurability for the physical ports and have this stretch to the mesh APs, which are today treated as expensive, dumb devices.
 
Thank you. Yours are very good suggestions. I also thought of buying a second RT2600AC and have this manage the guest network as its primary network. And move all the mesh wifi points to this network. This second router would have an IP assigned by the primary network of the first router to its WAN. This seems to me th cleanest way to do it (albeit more expensive). I can have essentially two mesh networks (if I want).
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

  • Question
looking to setup adGuard home on a raspberry pi 4b to block ads for every client on LAN network. I use...
Replies
0
Views
1,240
  • Question
Sound advice by @Shoop above. Don’t use UPnP. A quick search showed the following (there’s something on...
Replies
2
Views
4,799
Dear Jeyare, Been in contact with PlusNet, the Plusnet Hub One can't support "Bridge Mode". This being...
Replies
8
Views
2,031
  • Question
Yes, Omada is TP-Link's management system. Have set a reserved IP range and have put the NAS into that -...
Replies
2
Views
377
  • Question
Hi. As a newbie I may be totally misunderstanding the concept of how Tailscale works but anyway here goes...
Replies
0
Views
527
  • Question
Mmm..., looks like the problem was that we were connected to a dead network port. When livened up, all...
Replies
4
Views
1,054
  • Solved
hi im having the same problem can you tell me what you changed? I only my router to a tplink router it was...
Replies
4
Views
3,893

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top