Create a network segment
create_segmentCreates an isolated network segment on a Keenetic router with VLAN, bridge, NAT, DHCP, optional Wi-Fi and routing policy, rolling back on failure.
Instructions
Creates an isolated network that the web interface actually lists as a segment: a VLAN subinterface trunked over every switch port, a bridge, an address, NAT, a DHCP pool, and optionally a Wi-Fi network and a routing policy. Free identifiers are chosen automatically. The result is verified against the router-computed iseg block, and a failure anywhere rolls the whole thing back. Nothing is saved; call save_config once the user confirms.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| psk | No | Wi-Fi password, at least 8 characters. Required with ssid. | |
| name | Yes | Segment name, shown in the web interface. One word works best. | |
| ssid | No | Wi-Fi network name. Omit for wired only. | |
| subnet | No | Third octet of 192.168.x.0/24. Allocated when omitted. | |
| permit_interfaces | No | Create a routing policy allowing only these interfaces, for example ["Wireguard1"]. Omit to leave the segment on the default route. | |
| policy_description | No | Description for the created policy. |