Inter-VLAN Communication on Specific Ports with Gateway but no Omada Switch
I just put in my ER7206 alongside my Netgear Managed switches and my 2x EAP245 APs.
With the latest firmware, I'm happy that I can now restrict access from the IOT VLAN to the LAN without restricting the inverse. This is good and I am pleased.
One gap that I have that I'm hoping people can sort out for me is... allowing access to specific hosts on the LAN from the IOT VLAN on specific ports. Here's the Use Case:
- IOT devices leveraging my 2 Pihole instances that sit on my LAN.
The research I've done points to creating an IP-Port group and then creating a Switch ACL to permit that traffic. This doesn't work, presumably because I don't have a TP-Link Omada switch.
When I go to create a Gateway ACL and set the direction to "LAN to LAN", the option for referencing an IP Group or IP-Port Group goes away and I can only go "Network" to "Network".
I have set the direction type to "LAN to WAN" for giggles and it does then allow the IP-Port Group on the right side but it doesn't appear to work.
Is this just not possible when you don't have an Omada switch? Any guidance would be appreciated.
Thank you!