Picked up a unifi switch today. Since I already had the guest VLAN setup for the wifi, it was pretty quick to configure. It seems like it has cleared up the guest network leak.
Thanks for everyone's help!
Thanks for everyone's help!
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: Patrick M. Hausen on August 30, 2025, 02:58:54 PMTagged an untagged is a property of a link between two devices, not your entire network. You can have e.g.Right, this is essentially how I have it now after reading the suggestions in this thread. My firewall has one port WAN, one for LAN (untagged), and another port as a VLAN tagged trunk, but that only consists of the guest VLAN.
...
Thus you get the "do not mix tagged and untagged" for OPNsense - all other devices simply do not need to care.
Quote from: meyergru on August 30, 2025, 03:09:48 PMActually, that is not a strict requirement...I'm already using the client isolation feature on the guest WLAN already, but I suppose I wanted to get myself into trouble using VLANs. But also, I was thinking about the option to hardwire "guest" clients. I was doing that for a little while with my work laptop though an old router running openwrt, but decided to just connect it to the guest WLAN and simplify my office setup.