Hi everyone. This is my first post. I do not see an introduction area, so I will do it briefly before my question(s).
My name is Tom, 53 years old and living in South Africa. I run a small guesthouse and my interest is computers, programming and networking. All self taught, so no great knowledge. Just enough to help myself in most situations. I am linking two sites wirelessly, about a kilometer apart.
I run a wired local lan with 4 PC’s, 3x W7 and 1 x XP. Then I have an IP printer on the lan as well as an IPCorder with a few IP Cameras.
This wired lan network run on 192.168.0.0 network
Then I have my ADSL Modem on 192.168.11.0 network
and my wireless link on 192.168.3.0 network
I have the RB450G and these networks on ether 1, 2, 3 respectively with Ether 4, 5 empty.
I configured the RB450G so that all three networks run and I have internet. Everything runs smooth and no hiccups or delays. I successfully does IPScan on all three networks via Winbox and all devices ping. All devices on the wired lan have static IP, as well as the wireless link and AP’s.
But, I want to run a Hotspot on the 192.168.3.0 network, ether 3.
I also need to isolate the wired lan from the wireless network, as all my private PC’s is on the ether 1 interface and all the wireless stuff and AP’s on ether 3, where my customers will log onto the hotspot. So my guests should not be able to see my PC’s or printer or IP Cameras. (If I allow them to look at the cameras, it will deplete their allocated bandwith very quickly)
I have no idea how to do this isolation, although I suspect it is very easy. I know I can do it on the AP’s, so clients do not see each other, but want to block them from my private network as well with Mikrotik.
As far as the hotspot goes, I have it going and clients can log on with either HTTP or Mac. (Actually I allowed all methods, except Trial) My guests I give username and password and my family logon with their device’s Mac address. So, all good and well, they all have internet access on the hotspot.
However!
The moment I activate this hotspot, I get DNS problems with my IP Corder ((NVR), Network printer and general hiccups and delays on my wired network. I have setup my DNS correctly and allowed remote requests, obviously, otherwise I will not get internet on all networks. DHCP server gives IP’s to devices connecting via access points. Only devices connecting via AP get DHCP IP’s. The DNS on the hotspot server is the culprit.
DNS servers on the hotspot is the same as on my DNS setup and is filled in automatically.
DNS name of local hotspot server I gave as hotspot.dns as apparently this can be anything as long as you have a . in the name.
The problem manifest in the form of browser access. As soon as I go to 192.168.0.222 (IP Corder) I get a message about hotspot.dns in the browser address bar and then a redirect and the IP Corder does weird things like going into setup mode and I can not access the view mode for cameras.
Also, the network printer (192.168.0.15) become unreachable(also with message about hotspot.dns) and Windows network becomes unstable, not reaching all pc’s intermittently.
What I do not understand, is why does the hotspot on ether 3 (192.168.3.0) and a completely different network, interfere with my lan network on ether 1 (192.168.0.0) ?
BTW, I then still have internet on both networks.
So, it is the two problems.
- Isolation
- DNS on Hotspot
Thanks for your time,
Tom