Thanks for the awesome response! What do you use to create those layouts? They’re great!
So, the WAN ports on the Balance go to the Internet.
To make sure we’re definitely on the same page:
Port 1 on the Balance is 10.0.0.0/22, which goes to a switch with hosts 10.0.0.1, 10.0.0.2 and so on.
Port 4 has a wifi router. It has an ip of 10.0.1.1, which unless I’m mistaken is also part of the 10.0.0.0/22 subnet, correct?
When 10.0.1.1. assigns DHCP to what connects to it, it’s in the 192.168.100.x range. (Yes, I set up a static route showing 10.0.1.1 as the next hop for 192.168.100.x)
Given that both segments are connected only to the Peplink’s LAN ports, am I understanding correctly that it’s not ‘between’ it still? I’m obviously very ignorant here.
To restate and make sure I understand this correctly, the internal network firewall can’t apply any rules at all to any packets going through the LAN ports?
To simplify, if I had 10.0.0.1 on port 1 and 10.0.0.2 on port 2, and I wanted no communication possible between them, this would not be possible, without creating separate VLANs?
And, if I change it, so i have 10.0.0.0/22 on port 1, and 192.168.100.0/24 on port 2, the balance will still route all traffic between these without any filtering, at all?
If so, that seems very non-intuitive, especially that it’s impossible to filter MAC addresses between adjacent LAN ports.
Does the Balance only act as a switch? You said this is one of the ways to do this; perhaps a better question might be, what’s the most correct way of doing this?
(And it’s naivete that informed me in the first place: I thought I needed the second router on the same subnet, so I could reach its configuration interface.) This second router is a cheap thing solely to provide internet access to some IoT and other low priority devices. I want to make sure nothing at all coming from it can access any of the machines on the LAN.
Anyway, thank you so much for the helpful response – at least I know nothing’s wrong with the Peplink! (I only just updated to the current FW).