This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| advanced-access [2023/09/12 17:16] – [LAN Access Notes] -add note that table entries only permit traffic in one direction hogwild | advanced-access [2026/01/08 23:03] (current) – [LAN Access Notes and Troubleshooting] hogwild | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== LAN Access ====== | ====== LAN Access ====== | ||
| - | This page allows you to define LAN-to-LAN traffic where it otherwise would be blocked. | + | This menu allows you to define LAN-to-LAN traffic where it otherwise would be blocked. |
| \\ | \\ | ||
| - | For example, let's say we have two LANs, one primary (LAN0/br0) and one secondary | + | For example, let's say we have two LANs, a primary |
| - | + | ||
| - | If you want devices on LAN0 to be able to communicate with devices on LAN1 (and vice versa), you might use these settings: | + | |
| \\ | \\ | ||
| Line 13: | Line 11: | ||
| {{: | {{: | ||
| - | **On: | + | **On:** enables the rule defined on this row of the table. |
| - | **Src:** This displays/ | + | \\ |
| - | **Src Address:** This (optional) field narrows | + | **Src: |
| - | **Dst:** Here, you specify the (logical) Destination LAN for the rule on this row of the table. | + | \\ |
| - | **Dst Address: **(optional) narrows | + | **Src Address: |
| - | **Description:** This is a free text field in which to enter whatever you wish as a reminder, note etcetera. | + | \\ |
| + | |||
| + | **Dst:** here, specify the logical Destination LAN for the rule on this row of the table. | ||
| \\ | \\ | ||
| - | \\ | + | **Dst Address: **(optionally), |
| + | |||
| + | \\ | ||
| + | |||
| + | **Description: | ||
| + | |||
| + | \\ | ||
| + | |||
| + | \\ | ||
| + | |||
| + | |||
| + | ===== LAN Access Notes and Troubleshooting ===== | ||
| + | * On releases r2025.4 and earlier, regardless of LAN Access rules, a LANx device was able to reach (e.g. ping) all the router' | ||
| - | ===== LAN Access Notes ===== | + | * On r2025.5 and later: FreshTomato |
| - | Regardless of LAN Access rules, by default a LANx device is able to reach (e.g. ping) all the router' | + | * All entries in this menu are one-way only. If you want hosts on LAN0 to communicate with hosts on LAN1, and vice versa, you'll need two entries in the table for that. |
| - | All entries in the LAN Access table are one-way only. So, if you want hosts on LAN0 to be able to communicate with hosts on LAN1, | + | * LAN Access is an IP-level access control. |
| - | you must create have entries in the table to achieve that. One allowing traffic from LAN0 to LAN1 and another allowing traffic from LAN1 to LAN0. | + | |
| - | + | ||
| - | LAN Access is an IP-level access control. | + | |
| \\ | \\ | ||