Firewall zone and VPN wiregard settup

Hello ,

I am a new user.

I am not a pro but I try to setup the next architecture with my rutx14 :

  • LAN Interfaces : ==> 1 lan
    ==> 2 guest
    ==> 3 wiregard

  • Wireless SSIDs : ==> 1 RUT_BA56_2G
    ==> 2 RUT_BA56_5G
    ==> 3 Guest
    ==> 4 Wireg

  • Firewall Zone :

I cannot deleted some rule test that I made maybe this come from the issu…

My goal is to have differents wifi isolate :

  1. RUT 2G & 5 G are for my computer
  2. Guest is for guest
  3. Wireg is use full when needed a other IP

And my goal is to have an isolation with the principal (RUT) for the guest and the wireg.

Many thanks for you help.

Is my first setup

Josh

Greetings,

Apologies for the delayed response.

I recommend performing a factory reset before following the steps below, as it is difficult to determine which settings have been configured and what is preventing the rules from being deleted
You can find the factory reset instructions here: RUTX14 Device Recovery Options - Teltonika Networks Wiki

After resetting the device, create two additional LAN interfaces under Network → LAN, so you have a total of three interfaces: LAN, GUEST_LAN, WIREGUARD_LAN

Your configuration should look similar to the example below. USE the IP addresses you want:

Next, configure your SSIDs under Network → Wireless → SSIDs
Ensure that the RUT_BA56_2G and RUT_BA56_5G SSIDs are assigned to the lan network:

Create a new SSID for the guest network, configure its name and password, and assign it to the GUEST_LAN network.

Under Additional Settings, you may also enable the Isolate Clients option:

Next, create the WireGuard SSID and make sure it is assigned to the WIREGUARD_LAN network.

Once the wireless configuration is complete, navigate to Network → Firewall → Zones to isolate the networks.
For the default LAN zone, ensure that:

Next, create a new firewall zone for the guest network and configure it as shown below:

After that, create a firewall zone for the WireGuard network and configure it as shown in the following screenshot:


For the Allow forward to destination zones option, select the default wireguard zone that is automatically created when you

And in the default wireguard zone, the allowed zone should be only the new wireg_zone

Best Regards,
Justinas