Jump to content

Recommended Posts

Posted

Hi,

 

I currently have my ISP issued modem/router and use the Wifi off that and the network ports at the back.

 

I then have a Ubiquiti Edge router plugged into the ISP router and that is setup for two more seperate networks with their own IP ranges.

 

All networks have access to the web via the first router which is fine and is needed. The two networks on the Edge router can't see each other which is intended.

 

The issue I have is that since the networks on the Edge router have intenret access via the first router, they can see that router and other clients on it.

 

I only want the clients that are on the Edge routers networks to see the internet and not have access to any of the clients on the first router. I see this might be an issue since they need to see the router to get intenret access but is there a way?

Can I limit the Edge routers traffic to only see the Internet?

 

 

I know in an ideal world I'd forget the ISP router and just go the route of the two seperate networks on the Edge router but that is not the case right now.

 

 

Anyone point me in the right direction?

 

 

Many thanks.

Posted (edited)

On the edge router block client traffic to everything but the gateway on the ISP router, would that work for you. I've got no experience with the edge router however.

 

i.e.

permit any traffic to [LAN default gateway address on ISP Modem]

deny any any

 

When I was with Virgin I used the cable modem in modem only mode then used enterprise grade firewall behind it. Now I am with BT and have allocated addresses and a DrayTek with vDSL passing the ISP subnet through to the enterprise grade firewall and dealing with the NAT and all the rules there.

Edited by Davit2005
  • Thanks 1
Posted

That would work. I will have a play around with it tonight and see if I can do that.

 

In an ideal world I'd have my ISP router in modem only mode (unfortunately cant do that with current setup), then have my Edge Router that is split into several networks off that way. But I dont want to be adding more wifi access points for more networks / guest networks when I can use the wifi on the ISP issued router and have a million things already attached to it.

 

Isolating the things on the Edge router from the first router's clients is my only option at the moment.

Posted (edited)
That would work. I will have a play around with it tonight and see if I can do that.

 

In an ideal world I'd have my ISP router in modem only mode (unfortunately cant do that with current setup), then have my Edge Router that is split into several networks off that way. But I dont want to be adding more wifi access points for more networks / guest networks when I can use the wifi on the ISP issued router and have a million things already attached to it.

 

Isolating the things on the Edge router from the first router's clients is my only option at the moment.

 

If that does not work (I'm now thinking it may not) the other option may be to

deny any traffic to an IP range i.e. the DHCP range given to the clients on the ISP router

permit everything else

Edited by Davit2005
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...