EN
17
Note that all VAPs are LAN members by default. In order the new configuration
works remove VAP interfaces from LAN network where are added by default
on system.
Go To
Network > Interfaces > LAN > Edit > Physical Interfaces
and remove Wireless
Network VAPS from LAN. Now VAPs only are associated with VLAN10.
Configure Firewall
Go to
Network > Firewall
to configure Firewall.
Every zone has three types of traffic:
Input
: Traffic received from a interface with destination to CPU. Access to
local services like SSH or Web.
Output
: Traffic send to a interface from internal CPU. For example traffic
sent by CPU when connect to Web interface.
Forward
: Traffic is routed from one zone to another. For example traffic
from LAN to WAN.
Create VLAN to tag traffic from Wi-Fi
User can add more VLANs according to the needs of the network. The following
example shows how to add VLAN10 tag to traffic coming from Wi-Fi interfaces
before bridge traffic through WAN.
Capture shows how to create VLAN 10 on WAN port and forward tagged traffic
to CPU.
Click on
Add
button to add a new VLAN on Switch. This creates new VLAN
interface eth0.10 on system.
To manage new VLAN interface eth0.10, you need to create a new interface on
system, named VLAN10, as a bridge.
Go to
Network > Interfaces
and click on Add button.
Check ‘Create bridge over multiple interfaces’ and Add VLAN Interface
eth0.10 and Wi-Fi VAPa as members of new network VLAN10.
VLAN10 network propagates Wi-Fi traffic from VAPs to WAN with VLAN10 tag.
On
Network
>
Interfaces
you can see new VLAN10 interface.
VLAN10
interface bridge traffic from Wi-Fi VAPs to WAN port and insert VLAN10
tag.