Omada Switch ACLs for established state

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Omada Switch ACLs for established state

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
38 Reply
Re:Omada Switch ACLs for established state
2022-11-23 23:31:15

  @Alex6457 

 

Switch and EAP ACLs don't have the features for preserving states. It's only on Gateway which means if you block traffic on EAP or switch and your device is directly connected to either eap or switch your request won't even reach the gateway. At least that's how I understand it. 

 

You would need to have rules on Gateway lvl

 

Permit secured_network -> IoT_network (match related/established state)

Deny IoT -> Other networks 

 

It's also worth turning on the mDns feature which allows easily discover cast devices on IoT networks like Chromecast or Google Home etc. Without this enabled you won't see the cast option even though you might have the correct ACL settings 

 

 

 

  1  
  1  
#32
Options
Re:Omada Switch ACLs for established state
2022-11-24 17:16:41

  @chrisro I suspected something like that but still wasn't sure. Just thought that SDN is smart enough to figure that out by itself.  Thanks a lot for advice. Have reworked my ACLs on the switch side and it works now as expected

  0  
  0  
#33
Options
Re:Omada Switch ACLs for established state
2022-12-14 02:00:54

  @chrisro - how did you get the states options? I haven't been able to find them anywhere and have trawled the internet with no success. I have the same screen but no state options. I'm using an ER605 with the controller software installed on a Raspberry Pi, I presume that as it's software defined then it doesn't make much of a difference.

  0  
  0  
#34
Options
Re:Omada Switch ACLs for established state
2022-12-14 12:47:06

  @Mr_Tom_S It's not released for the ER605 yet. 

  0  
  0  
#35
Options
Re:Omada Switch ACLs for established state
2022-12-15 01:58:50

  @supermarkert - thank you, at least I'm not going mad! Do you know when/if it's being released on the ER605, is it on the ER7206? I had presumed that being software defined that it would be available on both.

  0  
  0  
#36
Options
Re:Omada Switch ACLs for established state
2022-12-15 16:11:58 - last edited 2022-12-15 16:12:05

  @Mr_Tom_S It appears to have been released for the ER7206, according to previous posts within this very topic.

  0  
  0  
#37
Options
Re:Omada Switch ACLs for established state
2022-12-21 04:34:11

I just found this thread much to my dismay after spending good money on Omada Router, Switch and EAP

I cannot believe there is not native functionality to allow established connections but deny connections initiated from vlans .. it beggars belief.

Wish I could send this all back now.

 

  0  
  0  
#38
Options
Re:Omada Switch ACLs for established state
2023-01-21 15:37:58

I'm running a V2.0 ER-605 with Firmware Version: 2.1.0 Build 20221230 Rel.55248.

 

The ER-7206 functionality noted in post #28 by @chrisro is available in the ER-605. Was added in the latest firmware update.

 

It would be great to hear what others think about application of this new functionality.

 

 

 

  0  
  0  
#40
Options