Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

0
A little help with Rules please?
Post Body

Hey, friends. Got a bit of an interesting use case here, and am hoping someone can help me figure out the appropriate rule(s).

tl;dr - how can I block known devices from everything if they connect to a different vlan?

Background:

I have a FWG . Very happy with it.

Have created a User for each of my children and assigned each of their devices to a Group accordingly. Using Family Protect and have also created a rule per child which blocks all internet access from an hour before bedtime until breakfast the next day.

A separate rule per kid for staggered bedtimes. Devices include things like iPads, fire sticks in bedrooms and the oldest has an iPhone.

The FWG is connected to a cheap Chinese managed switch and all household / family stuff is on a flat network (vlan 1).

We have a guest network (vlan 66) which is set as a sub-interface on the Firewalla and trunked from the switch as tagged traffic.

Ruckus Unleashed APs assign the tag to guest devices when they join the SSID we share. Guest rules in the Firewalla throttle internet speed and prevent access to our family / household devices.

Now, My eldest child has the guest WiFi details to give to friends when they come over - how do I set things so that she canā€™t use it herself? Iā€™m fed up of ā€œDad, I canā€™t printā€, ā€œDad, the internet is shitā€, ā€œDad, why donā€™t my lights work?ā€, etc. demands when sheā€™s connected to the wrong network.

Essentially, I want to set things such that if a family device connects to the guest network it is treated like the quarantine setup and completely black-holed - but I donā€™t want to set the built-in Quarantine option as non-family devices should connect (subject to the rules set) without any admin intervention from me. And mac-randomisation is a bitch.

Iā€™ve had a good poke around in the settings and scratched my head trying to figure this out - has anyone done similar? Any pointers?

Thanks!

Author
Account Strength
50%
Account Age
1 year
Verified Email
Yes
Verified Flair
No
Total Karma
547
Link Karma
46
Comment Karma
501
Profile updated: 1 day ago
Posts updated: 3 hours ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
2 months ago