Hello,
I have tried these on my side.
Rutx11:
Interface>LAN:
Protocol :Static
IPv4 address :192.168.100.1
IPv4 netmask :255.255.255.0
IPv4 gateway :blank
IPv4 broadcast :blank
DNS servers :blank
DHCP Server: Enabled
Start 192.168.100.100 , End 192.168.100.249
Interface>WAN:
Protocol :Static
IPv4 address :10.10.30.66
IPv4 netmask :255.255.255.0
IPv4 gateway :10.10.30.254
IPv4 broadcast :blank
DNS servers :10.10.30.15
DHCP : Disable
Firewall>Traffic Rules:
( I created a new rule ) To restrict Rutx10 or LAN devices of Rutx10 like wifi users etc from using Internet .
Enable: Yes
Name : NoInternet (Any)
Restrict to address family : IPV4 and IPV6
Protocol : Any
Source Zone: LAN
Source MAC : blank
Source Address: 192.168.100.221 ( i.e Rutx10 )
Destination zone: WAN
Destination Address : blank
Action:Drop
Keep all other configurations as blank/default.
Rutx10:
Interface : LAN
Protocol :Static
IPv4 address :192.168.100.221 (That is assigned by Rutx11)
IPv4 netmask :255.255.255.0
IPv4 gateway :192.168.100.1 (That is of Rutx11)
IPv4 broadcast :blank
DNS servers :Blank
DHCP : Disable
Interface :WWAN
Protocol : DHCP
I was able to achieve following by applying the above configurations :
1) Ping from Rutx11 to Rutx10 and Rutx10 to rutx11 including LAN devices and from LAN devices to LAN devices.
2)No Internet on Rutx10 and the LAN devices connected with Rutx10.
Everything worked smoothly without any issues.
You can replicate it on your side .
Also i am sharing some links to make things more clearer :-)
https://wiki.teltonika-networks.com/view/RUTX11_Interfaces
https://wiki.teltonika-networks.com/view/RUTX11_Firewall#Traffic_Rule_Configuration
I shared example/configurations as per your scenario for better understanding as i thought explaining will not help as example will do.
Thank you.
Have a nice day.
Regards,
Ahmed .