Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Temporarily restricted guest access

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 3 Posters 657 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      Optimus Prime
      last edited by

      I have a pfsense router for my home. My WiFi is an Orbi mesh coming through one port on a managed switch.

      My neighbor’s internet is out and Frontier says they won’t be out to fix for a few days. In the interim I thought about giving them one of my mesh APs for a few days. Orbi has no controls. I tested the “guest” WiFi function and can still access all my local shares.

      Is there an EASY way to allow him access to my internet for a few days and keep him out of my local shares? With IoT I probably have 60 devices on DHCP. Not certain how I could write a firewall rule allowing access for all current leases while only directing traffic for the few he’d connect for a few days.

      Thanks for your feedback.

      JKnottJ V 2 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @Optimus Prime
        last edited by

        @optimus-prime

        Can you provide WiFi on a separate subnet? You could then use the rules and routing to allow him only access to the Internet. Here are my rules for guest WiFi.

        f349d4a8-d830-4943-aa84-dea20a1978a6-image.png

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • O
          Optimus Prime
          last edited by

          Unfortunately it’s my only WiFi. So if I restrict him, I restrict myself, my wife, and all our current devices connected via WiFi.

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @Optimus Prime
            last edited by

            @optimus-prime

            Then there's nothing you can do. If they're on your WiFi, they're on the same subnet as your stuff and pfSense won't affect anything within that subnet.

            Does that mesh device support VLANs and multiple SSIDs? If so, you could set up another subnet that way. My guest WiFi uses a 2nd SSID & VLAN.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • O
              Optimus Prime
              last edited by

              Unfortunately, the ORBI devices have no meaningful settings adjust for this.

              1 Reply Last reply Reply Quote 0
              • V
                viragomann @Optimus Prime
                last edited by

                @optimus-prime
                If he has an wifi AP you could connect it to your switch and configure a separate subnet for the guest wifi.

                1 Reply Last reply Reply Quote 1
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.