On 2/23/2018 5:44 AM, Spyros Stathopoulos wrote:

So would it make sense to put the device in a different subnetwork (say, create a VLAN (eg. eth1:0) and a new zone out of eth1:0
and do SNAT into the new subnetwork? I have done that to access me PPP
modem on the WAN interface and it works but it is connected to a
physical interface (eth0). Would such a similar approach work with VLANs?


Yes, a VLAN should work.  You won't need to SNAT unless the device won't
respond to other subnets.  I have two local interfaces:

Devices can reach each other.  However, my wifi router (on wifi interface) won't
let me access its configuration menu from lan4 unless I masq:
?COMMENT access point
$WIFI_IF:$ap_SFN       $lan4_net


