LAN not reachable from virtual wlan

Hi all,

I’ve got the following setup on a hap ac2:

  • wlan1: main network
  • wlan2: main 5ghz network
  • wlan3: virtual network (of wlan2) meant for guests
  • wlan4: virtual network (of wlan4) meant for guests

Unlike many other people, I actually want my guests to be able to reach my LAN network. This isn’t working for me though…

When connected to wlan4, I get an IP address in my LAN network, I can ping the LAN IP of the mikrotik router, I can reach stuff on the internet, but I cannot reach other hosts located in my LAN network. ‘Default Forward’ is checked though, I was under the impression that it was this option that did client isolation. What am I doing wrong?

Most probably it’s firewall blocking the connections. And most probably it’s the matter of adding wlan3 and wlan4 to LAN interface list. If this doesn’t solve the problem, post complete configuration (/export hide-sensitive … and redact public IP address if it’s in config export).

Beware that by adding guest wireles interfaces to LAN interface list you will allow guests to manage your router as well …

Figured it out!

  • So wlan3/wlan4 were in the bridge, so that wasn’t the issue
  • Firewall rules were not in place

I did notice there were some bridge filter rules set that dropped forward to/from wlan3/wlan4. I’ve disabled those and all works as expected now.

Why have a separate WIFI if they are accessing the LAN as well?
The only reason I have guest wifi is to block persons from the router and the LAN, internet only.
Once allowed on the LAn, you have no say in where they go or what they do…