Need help to set up and configure a Brume 3 home network

I'm looking to set up a home network for someone that will use the Brume 3 as the gateway/router. The access points will be a combination of Asus RT-AC86U with Merlin and TP-Link Archer C7 flashed to OpenWRT.

Since the Brume 3 doesn't have integrated Wi-Fi, will the Guest and IoT Network options appear under Wireless in the GUI?

Given that I'm using separate access points, how can I configure and set up a Guest and IoT network?

Given the lack of integration compared to the Flint series, how can I ensure privacy and security with this setup? How do I ensure all access points are secured, and that all data from the connected clients is securely routed and protected by Brume 3?

I'm aware that WiFi-related settings like passwords and security will be configured on the access point rather than on the Brume 3. How do I ensure there are no vulnerabilities compared to the tight integration that the Flint series enjoy?

Hi there,

I can only answer a couple of these as I’m just a new user like you (but have a similar setup).

The wifi networks will still need to be setup through your router, then setup your router as an access point and let the Brume 3 handle the routing. As far as privacy and security goes, that depends what you’re after, but I set up a VPN client on the Brume 3 and ensured that (mostly) everything goes through it. Your access points and their wifi networks will be protected via the VPN tunnel you’ve set up on the Brume 3. You can only change these by connecting to your router - they won’t appear on the Brume 3 GUI. You’ll in essence have two GUIs to access, but once your access points are setup you won’t really need to get in there for much going forward, just use the Brume 3 to monitor traffic etc.

Your wifi passwords stay the same as they’re setup on your router/access point.

With the access point, I don't see an option to use the password from the router. The admin page on the access point have an option to set a new password.

Hi,

Thank you for providing the details of your planned network setup.

Brume 3 is a wired VPN security gateway without built-in Wi-Fi. It can serve as the central gateway for managing routing, DHCP, firewall, DNS, VPN, and other security policies.

If you use only one WAN connection and configure the WAN/LAN port as LAN, the two available LAN ports can be connected directly to your ASUS RT-AC86U and TP-Link Archer C7.
Both downstream routers should be configured in AP or bridge mode, with their DHCP server, NAT, and routing functions disabled. Brume 3 should remain the main gateway and handle DHCP, routing, firewall, DNS, and VPN policies.

If you require separate Main, Guest, and IoT networks, Brume 3 can create separate VLAN interfaces, IP subnets, DHCP services, and firewall policies for them. Each access point should also support mapping different SSIDs to the corresponding VLAN IDs.

Please note that setting the ASUS and Archer C7 to AP mode does not make them inherit the Brume 3 administrator password. Each access point still has its own administrator password for accessing its management page.

1 Like

@charles2 is this something that's coming to v4.10 inside the main glinet gui? Or are you saying it's already available to do from within the glinet gui, not Luci. The reason I ask is because yes we can create the networks in Luci but we still can't see the clients in the clients list.

What I have done is created a br-guest vlan which then shows clients because although the guest page is removed it's still deeply integrated in the shared code. I have a IoT and Guest SSID on my access points but for now I tagged them with the one VLAN ID, in my case it's the br-guest and I then just apply ap isolation and have them have two different passwords, yes they are on the same vlan but it's the only real way I can see all the clients so I can rule block, see stats, easily reserve IPs etc.

I am hoping that 4.10 introduces (or maybe 4.9 already has) Guest and IoT network directly inside the gui with the option to easily apply a VLAN ID and the subnet ranges etc. Even better would be if we could rename the interfaces to whatever we want without being limited to hard coded text and interfaces.

Although the brume doesn't have wifi it should still be equipped with an easy way to make interfaces directly in the gui along with visible clients without having to dig inside Luci. Without this it becomes a pain to view or manage clients and leaves the mobile app less functional.

1 Like

Yes, this is exactly what I want to do. I want to use the Brume 3 to create Main, Guest, and IoT networks with the Asus and TP-Link access points. I'm aware that the Brume 3 doesn't have WiFi, but I want it to have the same Main, Guest, and IoT networks as the Flint series. How can I recreate as much of what the Flint series has, but with third-party access points?

I asked @will.qiu, but he didn't elaborate. Are you able to tell me what the differences are between the Guest and IoT networks in terms of performance and security? If there is no difference, then what's the point of differentiating the two isolated networks?

Thanks for explaining how you're doing it. Hopefully, our discussion with @charles2 will help determine the best path forward.

There's a few differences and reasons to have two more interfaces, Guest and IoT.

For example you can enable AP isolation on the guest so each client isnt able to communicate where on your IoT you may want devices within that subnet access to communicate to each other. I also have two different SSIDs for Guest and IoT for a few reasons.

Let's say I had guests over and I wanted to change the password on the Guest SSID, I would then need to setup my IoT devices to the new password because I originally just put them on the Guest network.

For my guest I give them redirected bandwidth but not fully throttled, I also allow them on all the radios, 2.4, 5ghz and 6ghz (I have a 6e access point) For my IoT I only want to broadcast on 2.4ghz and I want control over the radios / settings.

I personally use the Brume 3 as my main router, connected to a switch which then sends VLANs to my VLAN aware access points.

Can you give me more specifics about your Brume 3 setup? Which switch and access point are you using?

I think AP isolation is enabled by default on both the guest and IoT networks.

What kind of IoT devices will need to talk to each other?

I am using my ISP ONT fibre modem connected to the WAN of the brume 3. From the brume 3 I have 2 switches, both are managed which are VLAN aware, one is a 8 port 2.5gb with 10gbe SFP+ port switch and the other is a 4 port 2.5gbe 2x 10gb SFP+ My switches are connected together with a DAC cable via SFP+

From the there the main 8 port switch is used for local clients (wired) and the PoE switch servers for my Access points. I have two grandstream access points (had unifi but changed to grandstream (GWN access points) and prefer them as I can dedicate the controller on the access point instead of relying on another hardware key or a docker like unifi / omada.

The two access points are connected to trunk ports which have my VLAN IDs tagged directly to the Access points. On the master access point that is set as the controller I make my wireless changes / settings (it then applies to my other access point as it's part of the same controller - adopted) I create my wireless SSIDs along with their password and configs and also tag each SSID on the access point controller with the same VLAN ID I created on the Brume 3 so that they match. Now if say a guest connects to the guest SSID with VLAN20 for example they will then go to the brume 3 VLAN20 DHCP etc.

I use dedicated access points like the grandstream because they connect via PoE which means I can place them anywhere without the need of a traditional power supply, up high, centrally where a traditional power cable couldn't reach. Because they are PoE it serves as both the power and the ethernet connection back to the switch.

You can look here for a script that will help with your VLAN creations.

There is also this guide which is more manual

Maybe you have a hub and a light for example.

To be honest I keep thinking of just going back to a flat network, no VLANs due to the hassle (hence hoping newer firmware is more accessible for VLAN and interface creation) of setting up every time there's a new firmware etc and the fact I don't really have anything IoT related or even many guests that wish to connect to my WiFi lol. One reason I keep doing it is mainly to learn but also I do self host things so I dont want certain things visible to guest if they ever stumble across things.

1 Like

Who's your ISP? Which model of switch do you have?

I think you have brought up a good example with the hub and bulb. I am now thinking AP isolation makes more sense for the guest network. I'll disable AP isolation for every other network.

My ISP is just a UK provider which uses the openreach network - FTTP. DHCP for the connection

The switches I got from AliExpress typically they are unbranded as such but they are managed 2.5gbe and SFP+ work great and a fraction of the price compared to UK market places. There's loads on there, all pretty much rebadged so I just grabbed the cheapest at the time mainly. I believe they are horaco and poeplus brands (from the gui, the units themselves are just plain)

Just make sure you select the correct ones from the selection boxes / little tooltip over the product photo so you get the managed ones.

You could in theory use a dumb PoE switch as most allow you to pass the VLAN but a managed switch is much better and not much more expense. I bought 2x 2.5gbe switches. One is non PoE and the other is PoE I was looking at a 8 port PoE switch but they only seem to have 1 SFP+ (10gbe) Ideally you are best trying to find 2x SFP+ on both switches then you can use one port as the uplink to each switch so there's no bottleneck and also you could then add a 10gbe NAS and a dedicated PC with a 10gbe pcie card for example, my “PC” actually resides on my NAS anyway as it's a virtual machine so technically I don't need to transfer files via LAN as the drives are local on the machine. I may just get a 5 port SFP+ switch to sit in the middle so I can have a 10gbe network but I don't really need it. Cheaper and less power than 10gbe RJ45

I am hoping in the future that glinet make a little eco system, a bit like unifi and omada (switch, access point etc managed / adopted together). They seem to have released AstroMesh which might be the answer but I'm unsure. @bruce is AstroMesh the answer to a unified product where we can adopt / deploy like unifi, omada, grandstream etc. I know there's no switches on offer yet.

AstroMesh does not strictly qualify as a centralized management solution, these two concepts are fundamentally distinct.

1 Like

Thanks for clearing that up. One day I hope of a glinet ecosystem :wink:

Any more ideas and suggestions to harden the privacy and security of my setup?

@charles2 @will.qiu @bruce

Can you guys help because @charles2 didn't follow up with my post tagging him.

With the Flint, when I use policy-based routing, I can select individual connected devices and then route them to the appropriate VPN. With the Brume 3, I'm guessing this won't be possible since the Brume can't directly manage the devices connected to the Asus router. When I use policy-based routing, I can only move the Asus router to the appropriate VPN, but the problem is that all the devices connected to the Asus router are dragged into a VPN I may not want to use for all the connected devices. Is there a way to address this?

The way I'm setting things up at the moment is that the Asus is the main network and the TP-Link is the IoT network. I don't know how to configure a more advanced setup. I'm open to ideas on how to make this setup better. How do I ensure that the Asus is totally isolated from the TP-Link? For privacy and security reasons, I want to ensure that devices connected to either access point don't see each other. I want to ensure that traffic from the Asus network doesn't ever leak into the TP-Link network. Then, using policy-based routing, I'll ensure that the Asus doesn't use a VPN while the TP-Link uses a VPN. I'm looking for something more specific and advanced as described in the paragraph above, but I'm also somewhat okay with this plan.

Any more ideas or suggestions to harden the privacy and security of my setup?

Hi,

Thank you for the additional information.

Based on your requirements, you can separate the two LAN ports of Brume 3 into two independent networks through LuCI, and then connect the ASUS and TP-Link routers to these ports in AP mode.

For example, you can keep one port on the default LAN for the ASUS main network and create a second subnet for the TP-Link IoT network.
A possible topology is:

Internet
   |
Brume 3
   |
   +-- LAN1 / Main network --> ASUS AP
   |       192.168.8.0/24
   |
   +-- LAN2 / IoT network  --> TP-Link AP
           192.168.10.0/24
  1. Please log in to Brume 3 and go to SYSTEM → Advanced Settings → Go to LuCI → Network → Switch.
    image
  2. Go to Network → Interfaces → Devices, create a bridge device, and add eth0.20 as its bridge port.

    Note: Please use br-guest as the bridge device here.
    Then go to Network → Interfaces → Add new interface and create a static interface for this network.

  3. Create a separate firewall zone for the IOT interface.

    Then save and apply.
  4. After completing the Brume 3 configuration, configure both the ASUS and TP-Link routers in AP/Bridge mode, and connect them to the corresponding Brume 3 LAN ports.

Once the clients are connected through the two APs and receive their IP addresses from Brume 3, they can be displayed individually on the Brume 3 Clients page.
You can then go to VPN → VPN Dashboard, edit the required VPN tunnel, select Specified Devices, and choose the individual clients by their MAC addresses.

1 Like