D-Link Forums
		The Graveyard - Products No Longer Supported => Routers / COVR => DIR-850L => Topic started by: JoeLansing on October 19, 2016, 03:23:11 PM
		
			
			- 
				I configured a guest zone, and don't have the check box clicked for Route Between Zones.  But I can still SSH, HTTP, and whatever between the zones.  
HW 1A 
FW 1.13WW
I'm trying to put a honeypot on the guest zone, and in the DMZ for security fun, but I sure want it far away from my internal network.
Any ideas?
- Joe
			 
			
			- 
				Link>Welcome! (http://forums.dlink.com/index.php?topic=48135.0)
- What region are you located?
 
Internet Service Provider and Modem Configurations
- What ISP Service do you have? Cable or DSL?
 - What ISP Modem Mfr. and model # do you have?
 
How is the honeypot configured on the router? Using a reserved IP address with in the default DHCP IP address pool? 
How are you determining the routes between zone? Please give details. 
DMZ should be WAN side route only.  ::)
			 
			
			- 
				I'm using a Zoom modem from Walmart on Comcast.  But that shouldn't matter.  My Normal to Guest traffic should be all internal if it is all using non-routable 192.168.11.* type addresses.
I'm in Michigan USA if that is a Region?  Is like my WW firmware hmmm  World Wide or just wrong?   I've been doing computer networks for over 20 years.  I love D-Link, but this silly thing has me stumped.  I can I just add a firewall rule in the router to say 192.168.11.100 isn't allowed to talk to any other 192.168.*.* addresses?  Roll my own Guest zone?
I want to put this Guest/DMZ honeypot on the outside so I can only reach it by like using a phone hotspot.  Right now it acts like a normal non-guest system.
- Joe
			 
			
			- 
				>>How is the honeypot configured on the router? Using a reserved IP address with in the default DHCP IP address pool? 
Yes.  
>>How are you determining the routes between zone? Please give details. 
I added it to the Guest zone.  I don't want any routing except to the outside for it.  This is my problem, it still routes to my internal in Guest Zone.
>>DMZ should be WAN side route only.  ::)
That is my goal.  So I can only reach it with like a phone hotspot on a different carrier.  
			 
			
			- 
				192.168.11.* is my wifi network
192.168.11.108 is placed into the DMZ.
192.168.11.108 connects to the Guest Zone SSID
192.168.11.108 can still talk to all my other 192.168.11.* internal home devices on another SSID.
This is a problem when 192.168.11.108 is running honeeepi on a Raspberry ":)
- Joe
			 
			
			- 
				Any status on this?  ???