Set up full-traffic rules (to start) on all four interfacesNow I have complete acces to the WiFi AP, but Not longer have any access to the outside !
now I have complete acces to the WiFi AP, but Not longer have any access to the outside !
I suggest start again and begin with a known good configuration. That is default selection of WAN and LAN will have the automatic rules that block all in unsolicited & allow all out, as if it was a consumer router.Because fromAs you are progressing in your learning and setup, may I suggest to start keeping a diagram of your setup. You can then share if you want when you ask and it'll be easier for you and everyone to figure out what needs to be done.P.S. the AP should be like any other device. It connects to a port on your router somehow; directly or via a switch, and then it becomes part of that network and subject to its rules.
Are you behind isp gateway? Is DHCP enabled? Are you getting arp from WAN side entities?Sent from my iPhone using Tapatalk
if you have static IPs do they all have fqdns and acme certs? If you are using your isp's static IP, maybe try and match their domain to yours and use dnsmasq with their servers if you have no need of nginx?Sent from my iPhone using Tapatalk