Mon Nov 19, 2018 10:11 pm
I only know the pre 6.43 ways of VLAN ( I heard it changed recently):
Create two bridges: Bob and Alice
Create Virtual WLAN AP-Bridge for 2.4G and 5G for Alice and Bob (you can use same SSID for 2.4G and 5G to make it seamless)
Create 1 VLAN per Wifi AP (one for 2.4G and one for 5G) , put it into the corresponding bridge (via PORT).
Add also to the bridge the ETH port you would like to add for Bob and the one for Alice.
Create DHCP server with different IP range for each bridge.
Now these devices can't see/discover each other on L2 anymore.
But then as said, even with VLAN, the router will still route from VLAN Bob to VLAN Alice at L3.
To disable this you need to drop all cross VLAN communication (action drop chain forward from in interface bridge BoB to out interface bridge Alice
and another one in the other way).
That way you get them completely separated but each one has a complete Wifi network and ETH network for himself...
You can add as much of these separated networks as you want (for control, IOT, guests etc.).
Hope this helps.