this post was submitted on 27 Nov 2023
1 points (100.0% liked)

Homelab

371 readers
3 users here now

Rules

founded 1 year ago
MODERATORS
 

I have a router running asuswrt-merlin so I have access to ssh/iptable rules. Is there a way to make a device not able to access an external network or only allow the IP to connect to another IP e.g. 192.168.0.2 -> 192.168.0.3?

I don't have a router/switch with custom vlan capability, so I was wondering is there another way to do this?

you are viewing a single comment's thread
view the rest of the comments
[–] Sindef@alien.top 1 points 11 months ago (1 children)

I'm not familiar with that OS in particular, but yes, IPTables can restrict egress to certain IP space very simply.

[–] Clawkikker@alien.top 1 points 11 months ago (1 children)

It's like openwrt or freshtomato firmware but specifically for asus routers. Do you happen to know how to do this? I've tried normal rules, but that seems to only apply the router itself rather than the network traffic routing through it.

[–] Sindef@alien.top 1 points 11 months ago

Ah. I'm not sure on that specific setup sorry, but sounds like you may need to check what chains already exist and see if there are ones for the right network interfaces. I'm familiar with IPTables itself only, not the Asus openwrt!