EAP Guest Network functionality

EAP Guest Network functionality

EAP Guest Network functionality
EAP Guest Network functionality
2024-08-06 04:45:15 - last edited 2024-08-15 08:36:19
Tags: #guest mode
Model: EAP670  
Hardware Version: V1
Firmware Version:

EAP670 hw 1.0, fw, 1.0.14

NOT using controller

 

 

My network consists of multiple vlans and local dns server. Firewall handles routing dns traffic to dns server from different vlans.

 

One of the ssid's on the eap670 is defined with guestmode enabled. My understanding is this is support to block private ip traffic (ie rfc1918), allowing only internet bound traffic.

 

As such, it's still allowing traffic to pass to the local gateway ip assigned by dhcp to wireless client. 

 

In addition, it's also allowing rfc1918 udp port 53 traffic (dns).  Is this by design?  If so, is there a more detailed definition of what kind of traffic guest mode actually blocks? Is there other traffic it's allowing (ie NTP)?

 

Thanks!

 

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:EAP Guest Network functionality-Solution
2024-08-13 02:24:41 - last edited 2024-08-15 08:36:19

  @das1996 

 

If the DNS server is blocked, the guest clients won't be able to resolve domain names to IP addresses, which is a crucial part of accessing the internet.

 

To be more specific: The guest network SHOULD be able to access the DNS server in the private LAN, just like it can access the DHCP server.

 

To avoid it, you can configure a public DNS server for the guest network, such as 8.8.8.8.

Wish you a happy life and smooth network usage! 
Recommended Solution
  0  
  0  
#8
Options
7 Reply
Re:EAP Guest Network functionality
2024-08-07 02:17:38

Hi  @das1996 

 

With the guest network enabled, clients connecting to the guest wifi won't be able to access any private IP traffic.

But there is an exception: the guest network won't take effective if you are using IPv6 address.

Wish you a happy life and smooth network usage! 
  0  
  0  
#2
Options
Re:EAP Guest Network functionality
2024-08-07 02:56:14

  @Vincent-TP I beleive you're mistaken as traffic such as dns and arp does pass to rfc1918 subnets.

  0  
  0  
#3
Options
Re:EAP Guest Network functionality
2024-08-07 08:23:36

Hi  @das1996 

 

How did you notice that? If you have captured some packets, please send them to TP-Link support via email and please also include this forum link, as well as the settings  page of the guest wifi.

Wish you a happy life and smooth network usage! 
  0  
  0  
#4
Options
Re:EAP Guest Network functionality
2024-08-10 17:28:36

  @Vincent-TP I noticed this by the fact that clients on said SSID can access a DNS server residing on a private ip. If all private IP traffic is blocked, this should not be possible.

  0  
  0  
#5
Options
Re:EAP Guest Network functionality
2024-08-12 05:42:57

Hi  @das1996 

 

Did you configure the DNS server IP address as this private IP address when you configure DHCP server?

If yes, the clients connecting to the guest SSID will request a DNS server from this IP address.

That's it, it won't be able to access any private IP address.

Wish you a happy life and smooth network usage! 
  0  
  0  
#6
Options
Re:EAP Guest Network functionality
2024-08-12 11:32:44

  @Vincent-TP The dns server has an ip of 10.10.100.2 which falls within the range of rfc1918 - https://datatracker.ietf.org/doc/html/rfc1918#section-3

 

By all accounts, this (port 53 udp to private ip range) traffic SHOULD be blocked but isn't because I can see dns lookup requests on dns server coming from client connected to SSID with guest mode enabled. 

 

It is blocking tcp/443 traffic to private ip but NOT dns.

 

How can I make this more clearer?

 

 

  0  
  0  
#7
Options
Re:EAP Guest Network functionality-Solution
2024-08-13 02:24:41 - last edited 2024-08-15 08:36:19

  @das1996 

 

If the DNS server is blocked, the guest clients won't be able to resolve domain names to IP addresses, which is a crucial part of accessing the internet.

 

To be more specific: The guest network SHOULD be able to access the DNS server in the private LAN, just like it can access the DHCP server.

 

To avoid it, you can configure a public DNS server for the guest network, such as 8.8.8.8.

Wish you a happy life and smooth network usage! 
Recommended Solution
  0  
  0  
#8
Options