1
General Discussion / Re: How do we use a second interface for a second network?
« on: May 10, 2024, 02:25:26 am »
Firewalls and Networking are new to me; I am still learning. Bridge and VLAN are the next level. I am starting with a simple method by separating both networks from two of the ports that the PC has. Once I am more familiar with it, then I can start working on bridge and VLAN stuff. Thank you for your suggestion.
The first thing you have to decide is if you really want the second port to be on a separate network. That is not clear by itself just because you want to attach your WiFi access point to it.
That is a question of network design. Know your options:
1. Go on like you started and have two separate networks for your LAN and your WiFi. In this case, both networks can have WAN access but are otherwise completely separated (e.g. your WiFi clients cannot access machines on LAN) until you create rules to allow for certain services.
2. Use the second ethernet port as a bridge (like a lite-weight switch) to just connect your WiFi AP to your LAN. In that case, you have to create a LAN bridge and set some tuneables (consult the docucomentation on how to do this).
3. Do the perfect job and create multiple VLANs to be able to create respective WiFi SSIDs for different classes of WiFi clients (i.e. some IoT clients could be in a separated network whilst your smartphones are in/on another network/SSID bridged to the LAN). This will only be possible if your WiFi APs can handle that, like e.g. Unifi equipment does.