Quote from: Dieter Bosli on Today at 10:04:55 AMEspecially when a device can communicate via different interfaces and should be assigned different IP addresses for the same MAC address.IMHO that's a matter of configuring Static IP Addresses on the Host and not a task for your DHCP Server :)
Quote from: Netlearn on Today at 01:53:44 AMI haven´t tried, but it's not an easy workaround for a medium network, because one would have to connect the new machine to the "no-leases" VLAN and then to the device's destination VLAN, which is not always feasible. Plus the existence of that "no-leases" VLAN in all the infrastructure (wired and wireless).I would imagine it to work a bit like a RADIUS 802.11r Enabled network but with the difference that you manually do the move to the right VLAN :)
Quote from: Greg_E on February 27, 2026, 10:58:19 PMI've generally found that blocking anything related to outlook.com will break stuff your users need.Blocking the "Is Windows Online ?" Service/Pinger URL or disabling it via regedit is known for causing Office related software like Word and Excel to become extremely slow/sluggish in the past, so yeah : Don't play with all that stuff too much if you don't want weird unexpected issues !!
Quote from: Tobanja on Today at 10:39:52 AMCan I just confirm, you made it work with the RT6600AX as AP?I made it work for a Wired VLAN but if I would add a SSID to that VLAN then it would work too for sure!
QuoteFrom what I can tell in many places, people in general have problems with the VLAN tagging for this AP.What is so special about it ?!
QuoteAnd maybe I should add, I only want VLAN for wireless devices, anything wired goes to my main LAN. So I guess I need to tag the VLAN 10 and have VLAN 1 untagged from the AP through the switch to opnsense, according to my logic (so I can use the "standard" LAN wirelessly as well)?To be honest : I don't know if ANY Wireless Accesspoint works like that ?!
Quote from: Tobanja on Today at 12:22:31 PMAfter a few more hours of testing, I'm pretty sure everything inside opnsense is correctly configured. However, the VLAN 10 network still has full access to my primary LAN, since I can ping anything from the phone on this network, so my tests have failed. Anyway, thanks for trying to help me out here.Then your Firewall Rules are not configured properly :)
QuoteThe RT6600AX as AP doesn't have much settings, just a name and a VLAN, and of course an SSID for the network.FYI Side note : DTIM for 2.4 GHz should be either 1 or 3 for compatibility so 4 is a weird value IMHO.
And some "advanced settings" as seen in the picture, probably not relevant to my problems.