How can I create a guest VLAN network without allowing clients access to LAN-connected devices on a QHora-301W router?


Last modified date: 2023-05-17

Applicable Products

QHora-301W


Solution

I. Create a new VLAN ID in QuRouter.

  1. Log in to QuRouter.
  2. Go to Network > VLAN & DHCP Server Service Settings.
  3. Click Add VLAN.
  4. Configure the IPv4 VLAN settings.
    1. Specify a VLAN ID.
    2. Specify a VLAN description that contains a maximum of 256 characters.
    3. Specify a fixed IP address.
    4. Specify the subnet mask.
    5. Specify an MTU value.
    6. Select Enable Spanning Tree Protocol (STP) to prevent bridge loops.
    7. Select Enable DHCP server service.
      FieldDescription
      Start IP AddressSpecify the starting IP address in a range allocated to DHCP clients.
      End IP AddressSpecify the ending IP address in a range allocated to DHCP clients.
      Lease TimeSpecify the length of time that an IP address is reserved for a DHCP client. The IP address is made available to other clients when the lease expires.
      DNS ServerSpecify a DNS server for the DHCP server.
      Reserved IP Table
      1. Click Add to configure a reserved IP table.
      2. Specify the following:
        • Device name
        • IP address
        • MAC address
      3. Click.
  5. Configure the IPv6 VLAN settings.
    1. Click IPv6.
    2. Click Enable IPv6 VLAN
    3. Select the outgoing WAN interface from the drop-down list.
    4. Specify the IPv6 IP address prefix.
    5. Select the prefix length from the drop-down list.
    6. Select the interface identifier to identify interfaces on a link.
      SettingUser Action
      Interface identifierSelect from the following:
      • EUI-64: Select Extended Unique Identifier (EUI-64) to automatically configure IPv6 host address.
      • Manually: Specify an interface ID to configure the IPv6 host address.
    7. Assign a client IPv6 addressing mode from the drop-down list.
      SettingDescription
      IPv6 addressing modeSelect from the following:
      • Stateful: The stateful DHCPv6 or managed mode enables you to manually assign a unique IPv6 address to each client.
      • Stateless: The stateless DHCPv6 mode enables users to manually enter additional IPv6 information including the lease time, but automatically assigns a unique IPv6 address to each client.
      • SLAAC+RDNSS: Stateless Address Auto-Configuration (SLAAC) along with Recursive DNS Server (RDNSS) enables users to manually assign an IP address based on the IPv6 prefix and uses recursive queries to resolve the domain name.
      • Disabled: Disables IPv6 client addressing.
    8. Click Apply.

II. Assign the VLAN ID to virtual access point 2 or 3.

  1. Go to Wireless/Virtual Access Point.
  2. Under Virtual Access Point 2, click.
  3. Select the newly created VLAN ID.
  4. Specify an SSID, security encryption, and password.
  5. Click Apply.
  6. Click to enable the virtual access point.

III. Create a firewall rule for the virtual access point.

  1. Go to NAT/Firewall.
  2. Click Firewall Rule.
  3. Click Add.
  4. Configure the firewall settings.
    SettingUser Action
    Rule NameSpecify the firewall rule name.
    ProtocolSpecify the IP protocol.
    SourceSpecify the connection source for this rule.
    • Selecting Any applies this rule to all connections.
    • Selecting Define applies this rule to traffic coming from the sources defined for this rule.
      • Selecting None allows you to apply the rule to traffic coming from the client operating system.
      • Selecting Interface allows you to apply the rule to traffic originating from all the IP addresses from the selected WAN, LAN, or VLAN interface.
      • Selecting IP allows you to apply the rule to connections from a single IP, a specific subnet, or every IP within a specific range.
    DestinationSpecify the connection destination for this rule.
    • Selecting Any applies this rule to all connections.
    • Selecting Define applies this rule to traffic directed to all destinations defined for this rule.
      • Selecting IP allows you to apply the rule to connections going to a single IP, a specific subnet, or every IP within a specific range.
      • Selecting Domain name allows you to apply the rule to traffic going to all the IP address associated with the specified domain name.
    PortSpecify the IP protocol type for this rule. This field is available only if you select the TCP or UDP protocol.
    ActionSpecify whether this rule allows or blocks matching connections.
  5. Click Apply.

Users can now connect to the guest network without being able to access the devices connected through LAN on the router.


Further Reading

How to set up a DHCP server in the QHora-301W router?

Was this article helpful?

80% of people think it helps.
Thank you for your feedback.

Please tell us how this article can be improved:

If you want to provide additional feedback, please include it below.

เลือกสเปค

      ดูเพิ่มเติม น้อยลง

      This site in other countries/regions:

      open menu
      back to top