Community discussions

MikroTik App
 
nagyg640
just joined
Topic Author
Posts: 1
Joined: Sun Jul 04, 2021 4:36 pm

Separating an AP from the LAN

Sun Jul 04, 2021 4:45 pm

Hi,

I'm new to Mikrotik and I'd like to ask for some help. My setup: Mikrotik HAPac2 router with ether1 as WAN and a wireless AP (Ubiquity) with a wired connection on ether2 through DHCP. The whole network is running fine however I would like to isolate the AP from the rest of the network. Since there is nothing else on ether2 but the AP itself it made sense to me to set the firewall rules for the ether2 interface itself in order to drop everything on the LAN but allow WAN (web) access. Unfortunately I'm receiving an error message saying that the ether2 is a 'slave' so setting the firewall rules is not possible. I understand that it is related to the bridge (bridge setup attached) however I'm fully lost as honestly this whole bridge concept is something I dont really understand. Could someone please explain how should I make the LAN isolation happen and let the AP clients reaching only the internet? Thanks :)
You do not have the required permissions to view the files attached to this post.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19321
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Separating an AP from the LAN

Mon Jul 05, 2021 12:37 pm

Please
/export hide-sensitive file=anynameyouwish

to see what is going on.
 
tdw
Forum Guru
Forum Guru
Posts: 1845
Joined: Sat May 05, 2018 11:55 am

Re: Separating an AP from the LAN

Mon Jul 05, 2021 1:30 pm

I'm fully lost as honestly this whole bridge concept is something I dont really understand. Could someone please explain how should I make the LAN isolation happen and let the AP clients reaching only the internet? Thanks :)
A bridge is effectively a network switch, and in its basic form traffic can pass between all ports/interfaces.

There are various ways of separating the traffic - separate networks / VLANs, port isolation, bridge filtering. If you have a single LAN the simplest way with UniFi APs to prevent access to the LAN is to tick the Guest Policy box when editing the network under Settings > Wireless Networks, even with no guest portal configured the setting prevents wireless clients communicating with devices on the LAN. If you configured the AP with the UniFi app rather than through a UniFi controller I don't know if this option is available.

Who is online

Users browsing this forum: Ahrefs [Bot], Amazon [Bot], intania, michael00, raiser, sinaaram and 38 guests