Because i have several IoT devices in my house and i recently read several articles about the risk involved i wanted to harden the LAN and put IoT devices on their own vlan/subnets. I came pretty far but are getting stuck on one thing; the intercommunication between the subnets (for example some devices still need to be able to talk to each other but anything IoT should never be able to reach my server/NAS etc.) Setup: Router 1 Asus RT-AC56U running latest Tomato: WAN: Connected to ISP using PPPoE LAN: br0 192.168.1.0/24 - main IP 192.168.1.1 br1: 192.168.2.1 with DHCP enabled and VLAN 10 untagged on port 3 Router 2 Netgear R7800, unfortunately there is no Tomtato for this so i have tried this setup with OpenWRT but got stuck with unresponsive webgui several times so i went back to stock firmware. Everything related to firewall on this router is swtiched off on the WAN settings page since it's not listening directly to the internet and has the 192.168.1.1 device as a gateway. WAN: static set to 192.168.2.1 connect to port 3 of the Asus router LAN: DHCP enabled 10.10.1.0/24 main IP 10.10.1.1 What does work: ping from client on router 1 to 192.168.2.1 and 192.168.2.2 even. ping from 10.10.2.1 to 192.168.1.x What does not work: ping from any client on 192.168.1.x network to the 10.10.1.0 network I have added routes in tomato through the GUI tried several of them but somehow i can still not ping anything from 192.168.1.x to 10.10.1.x I am sure i am doing something very wrong but even with going through several threads and trying different things i can't figure out what it is. Anyone able to help out?