I have a hotspot service for guests (wlan1) and AP running for a local usage, for users in office (wlan2 virtual AP), everything works fine, except that i dont want that hotspot users could access local resources, servers etc. , for now hotspot users can access local resources. What should i change in configuration that hotspot users can access everything except 192.168.10.0/24 network?
I made hotspot from this manual http://www.marlwifi.org.nz/projects/basic-mt-hotspot
My configuration:
Router: RB/433AHN-WKIT
ether1 ISP connection IP 158.149.X.X
ether2 local network 192.168.10.X
wlan1 hotspot 192.168.0.X
wlan2 virtual AP 192.168.10.X
Keep in mind that the Hotspot proxies HTTP requests so clients on the Hotspot may be able to access web servers within the 192.168.10.0/24 subnet even with that drop rule. If that is an issue post again and I’ll reply with configuration to lock that down, too.
You will no longer be able to use the advertising function of the Hotspot and inserts ads when users load web pages in their browser, but hey will also no longer be able to access web servers on the office subnet.