Packets leaking across VLAN on firewall configuration change?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Packets leaking across VLAN on firewall configuration change?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Packets leaking across VLAN on firewall configuration change?
Packets leaking across VLAN on firewall configuration change?
2022-02-15 22:35:41
Model: TL-SG3210XHP-M2  
Hardware Version: V1
Firmware Version: 1.0.3

Hi,

 

I'm no networker so apologies if this is a misguided query.

 

I bought a TP-Link switch and configured it to use Omada. I have also created a separate VLAN for my IOT devices.

 

Background: I have been tinkering to try and get Sonos Controllers (the App) and the Sonos Speakers to work across the VLAN. I have managed to be almost completely successful in this by using Avahi and Pimd on a Raspberry Pi to provide a proxy for multicast traffic. Avahi seems to get the Spotify Connect stuff working however I am still having issues getting the Sonos App to work.

 

Question: I have been tinkering with the firewall rules to get SSDP to work across VLANs while using Pimd on the Raspberry Pi and have not managed to get it. If I disable all the rules it works but I cannot seem to create the rule that makes this work properly.

 

I noticed however when I go to save an ACL rule, the switch appears to momentarily fully open access across VLANs with enough time for the IGMP proxy to send the packets across the VLAN and make the Sonos App work. Is this normal for this to happen on changes to ACLs? It seems a bit sloppy to me.

 

I noticed this as every time I edited the ACL it started working briefly which led me to several false assumptions that I had configured it correctly.

 

Also, if anyone has any experience in using IgmpProxy/PIMD and getting that working, would be appreciated :)

  0      
  0      
#1
Options
3 Reply
Re:Packets leaking across VLAN on firewall configuration change?
2022-02-16 09:03:53

Dear @Utmstgsn,

 

Utmstgsn wrote

Question: I have been tinkering with the firewall rules to get SSDP to work across VLANs while using Pimd on the Raspberry Pi and have not managed to get it. If I disable all the rules it works but I cannot seem to create the rule that makes this work properly.

I noticed however when I go to save an ACL rule, the switch appears to momentarily fully open access across VLANs with enough time for the IGMP proxy to send the packets across the VLAN and make the Sonos App work. Is this normal for this to happen on changes to ACLs? It seems a bit sloppy to me.

I noticed this as every time I edited the ACL it started working briefly which led me to several false assumptions that I had configured it correctly.

 

To better assist you, may I know the version of your controller?

Please try to upgrade the switch's firmware version to the latest to test.

 

Here is the link you can refer:

https://www.tp-link.com/en/support/download/tl-sg3210xhp-m2/#Firmware

 

Best Regards!

 

 

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#2
Options
Re:Packets leaking across VLAN on firewall configuration change?
2022-02-16 10:24:01
I am using the latest firmware for my region, Australia. It does say specifically to use the correct region otherwise I may void warranty. My controller version is 4.4.6 Thank you.
  0  
  0  
#3
Options
Re:Packets leaking across VLAN on firewall configuration change?
2022-02-18 06:47:53

Dear @Utmstgsn ,

 

Utmstgsn wrote

I am using the latest firmware for my region, Australia. It does say specifically to use the correct region otherwise I may void warranty. My controller version is 4.4.6 Thank you.

 

1. Please don't worry, the switch‘s firmware version is universal, you can upgrade to the 1.0.6 firmware on the en website like I mentioned in the last message.


2. What's the physical connection(current topology) of your devices?(You can draw a diagram of Network Topology simply if you don't mind.)
What is the relationship between raspberry pi and switch in your network? How are they connected?


3. Is the Firewall setting set on the switch or on the Raspberry Pi? How did you set it?


4. What is your specific requirement by setting up ACLs?


5. Could you please elaborate the spesific problem phenomenon?

 

Best Regards!

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#4
Options