bottleneck
Choose style:

Author Topic: LAN Segmentation in OpenWRT  (Read 3235 times)

0 Members and 1 Guest are viewing this topic.

Offline clinton

  • Newbie
  • Posts: 3
  • Thanks: 0
  • Registered : 28/04/2016
    YearsYearsYearsYearsYearsYearsYearsYears
LAN Segmentation in OpenWRT
« on: May 08, 2016, 05:22:16 pm »
I thought I'd seen information about this in the past, but I've been unable to dig it up in the last hour.

I'm looking at different options for segmenting a small office network to support payment card compliance concerns. Nothing fancy, but I need to be able to isolate one of the ethernet LAN ports on it's own segment. I was under the impression based on something I've read in the past that the LAN ports are all switched to a single internal interface and not separately routable. Since I can't find the reference, I'll assume I might be thinking about another device.

However, within OpenWRT settings all LAN interfaces seem to be aliased under eth1 and are bridged with wireless under the LAN network. Will creating a new network with eth2 (shows disconnected even though all ports are physically occupied) or custom port (eth3/4) move the corresponding physical port out of the LAN network? I was also considering whether the interfaces could be addressed as eth1.0, eth1.1, ..., though I haven't had an opportunity to take the network down long enough to test.


Offline Ashok

  • Securifi Staff
  • *
  • Posts: 2770
  • Thanks: 3
  • Registered : 25/07/2014
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Re: LAN Segmentation in OpenWRT
« Reply #1 on: May 09, 2016, 08:35:52 am »
@ clinton,

As of now it won't be possible to separate the LAN segment.
« Last Edit: May 09, 2016, 08:51:42 am by Ashok »

Offline clinton

  • Newbie
  • Posts: 3
  • Thanks: 0
  • Registered : 28/04/2016
    YearsYearsYearsYearsYearsYearsYearsYears
Re: LAN Segmentation in OpenWRT
« Reply #2 on: May 09, 2016, 08:10:06 pm »
Thanks for confirming my suspicion. I'm still interested in the VLAN beta software since I'm not really using any other capabilities except PPPoE connection management, basic WAN firewall, and switch. I'm hoping this will be sufficient to solve my need.

 

Page created in 0.086 seconds with 22 queries.