Hi, I have an Asus RT-N66U with Tomato Firmware 1.28.0000 MIPSR2-115 K26AC USB AIO-64K. Here is what I am trying to achieve: 1. Have 2 SSIDs(one for office guests and one for myself) on separate network that don't talk to each other. SSID1(2.4): 10.254.253.0/24 on Vlan4 SSID1(5ghz): 10.254.253.0/24 on Vlan4 SSID2(2.4ghz): 10.254.254.0/24 on Vlan3 SSID2(5ghz): 10.254.254.0/24 on Vlan3 2. Ethernet traffic separated from all wireless traffic. so I have it on default VLAN1 3. I would like to connect two access points on VLAN4 and one access point on VLAN3 4. Captive portal with authentication on VLAN4 for guest access Now this is the setup I have: Br0(Vlan1)- DHCP - 192.168.1.0/24 DHCP:192.168.1.2-245 BR1(VLAN3) - DHCP - 10.254.254.0/24 DHCP:10.254.254.2-245 BR2(VLAN4) - DHCP - 10.254.253.0/24 DHCP:10.254.253.2-245 VLAN 3 - Port 1 - BR1 - SSID2(Port1 to connect to other APs) VLAN 4 - Port 4 - BR2 - SSID1(Port 4 to connect to other APs) So here is my issue: All VLANs can talk to each and see devices on each Vlan so pointless to have VLans. If need by I can paste my NVram results and screenshot of my config. Also, I can point captive portal go to a PHP page and authenticate on a company website we have? Thanks in Advance.