Commit d3b540f
committed
openwrt: isolate vaplan in a guest zone instead of lan
Hotspot clients were placed in the OpenWrt 'lan' zone (input/forward
ACCEPT), giving them reach to the router's services and any other
container bridged into lan - effectively a backdoor into the whole LAN.
Move vaplan into a dedicated 'guest' zone: input REJECT, intra-zone
forward DROP (client isolation), forwarded only out the masqueraded wan
zone. Add traffic rules allowing the access guests actually need:
DHCP (67-68), DNS (53), and LuCI (80/443, password-protected).
Signed-off-by: ravindu644 <droidcasts@protonmail.com>1 parent 22fc1aa commit d3b540f
1 file changed
Lines changed: 38 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
51 | 54 | | |
52 | 55 | | |
53 | 56 | | |
| |||
57 | 60 | | |
58 | 61 | | |
59 | 62 | | |
60 | | - | |
61 | 63 | | |
62 | 64 | | |
63 | 65 | | |
64 | 66 | | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
65 | 74 | | |
66 | 75 | | |
67 | 76 | | |
| |||
75 | 84 | | |
76 | 85 | | |
77 | 86 | | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
78 | 114 | | |
79 | 115 | | |
80 | 116 | | |
| |||
0 commit comments