NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
kgeoffrey
Jan 09, 2022Guide
Guest Network on WAX160 / AX1800
Hi there. I am trying to set up a guest network on my new WAX160 where guests can only access the internet, and not be able to see or access other devices connected to the network. I tried enabling W...
schumaku
Jan 10, 2022Guru - Experienced User
Talking of the WAX610 here?
kgeoffrey
Jan 10, 2022Guide
Yes
- schumakuJan 10, 2022Guru - Experienced User
Based on an earlier report, the SSID Client Isolation seems to have a flaw, probably related to the intro of the mid 2021 "option to specify network devices that are exempt from WiFi client isolation" - this is probably what you are experiencing now. This flaw seems to exist on other WAX6xx APs with current firmware as of writing, too.
Intended is that some kind of (undisclosed details) L2 isolation does take care of blocking the WiFi clients by SSID from any local network, while retaining Internet access as documented in the Insight Managed WiFi 6 AX1800 Dual Band Access Point Models WAX610 and WAX610Y User Manual
===
Enable or disable client isolation for a WiFi network
By default, client isolation is disabled for a WiFi network (SSID or VAP), allowing
communication between WiFi clients that are associated with the same or different WiFi
networks on the access point. For additional security, you can enable client isolation so
that clients that are associated with the same or different WiFi networks cannot
communicate with each other, except for communication over the Internet, which remains
possible.===
Don't blame the writer - we're implementing guest networks using the much stricter dedicated VLAN and appropriately configured security zones (like many other) - that's why many of us [especially those with strict Insight managed VLAN environments] never experienced the issue.
RaghuHR please let engineering to look into this issue, and inform your customers about intended fixes.
- kgeoffreyJan 10, 2022GuideThank you, schumaku. When I chatted with Netgear, after doing some troubleshooting, they suggested downgrading the firmware.
Is there a way to make a second VLAN with my current setup? WAX160 > WNDR3400 Router (Wifi disabled for now) > CM400 Modem
I also noticed the Guest1 option under MAC ACL. Is this something I can use for my purposes?
I’m inexperienced in advanced networking, but I’m capable of learning. Thanks for your reply and any additional assistance.- schumakuJan 11, 2022Guru - Experienced User
Wait until Netgear does address this issue. No workarounds for the moment.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!