Forums

Home Forums General Configuration Any way to configure access control for all devices on a specific VLAN

Any way to configure access control for all devices on a specific VLAN

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #7362
    Rocket88
    Participant

    I am working on a small business scenario where I think the PCWRT router could work rather well. Basically, a subset of the equipment, which will all be on it’s own VLAN at the office needs, to be on a VPN to a second site. At the office non of this equipment needs internet access (other than the VPN tunnel). It would be terribly convenient if there was a switch “Allow Internet access” that applied at the VLAN level.

    If this works out as I expect, I will be recommending it to others for this specialized application. Ideally I want to keep my configuration instructions as simple as possible as I will not be the one configuring the various sites out there.

    While I haven’t looked at the specifics I am fairly certain I can do this as part of an access control group that I assign each of the devices to, but hoping there might be a simpler way as I would love to be able to write up an Ap Note to share with various colleagues out there.

    #7363
    support
    Keymaster

    Yes there’s an easy way to do this. In this guide I outlined how to establish a site-to-site VPN with both sides retaining Internet access from the local network: https://portal.pcwrt.com/blog/2026/08/05/pcwrt-vpn-router-business-site-to-site-wireguard/

    You can adjust this setup slightly to achieve what you want. On the WireGuard client side (Router B in the guide), check the box:
    Tunnel everything through WireGuard VPN except for the domains and IP ranges listed below, which will be sent through the alternative route.

    Then, leave the text box below empty.

    After this change, all traffic for devices connected to LAN on Router B will be routed through the VPN. However, on Router A, incoming VPN connections are allowed to destination LAN only. Internet bound traffic will be dropped.

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.