Allowing VLAN access to shared resources

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Allowing VLAN access to shared resources

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Allowing VLAN access to shared resources
Allowing VLAN access to shared resources
2023-07-23 22:45:59
Tags: #ACL
Model: OC200  
Hardware Version: V1
Firmware Version: 1.24.0

I have a set-up with 3 VLANs:

  • Secure

  • IoT

  • Guest

 

I have Gateway ACLs (since I need them to be stateful) to:

  • Block IoT access to Secure and Guest

  • Block Guest access to Secure and IoT

 

I'm now wondering how best to grant IoT and Guest access to certain shared resources (DNS servers and a NAS) that exist on the Secure network.

 

It looks like LAN->LAN Gateway ACLs only allow Network->Network mappings, so it seems that I can't add these exceptions via a Network->IP-Port-Group mapping at the Gateway ACL level.

 

Given that I assume ACLs are hierarchical (AP -> Switch -> Gateway), I don't think I can solve this by just adding a Switch ACL (which does allow Network->IP-Port-Group mappings) as even if the Switch allowed it, the Gateway would block it?

 

The only solution I can currently think of is to create an additional Shared VLAN and have that host the DNS servers and NAS. That VLAN would be allowed at the Gateway level which means I should be able to use Switch ACL rules to manage access from the other VLANs.

 

Does that sound reasonable, or is there a better way to do this?

  1      
  1      
#1
Options
2 Reply
Re:Allowing VLAN access to shared resources
2023-07-24 05:24:02 - last edited 2023-07-24 05:27:39

  @TalkiToaster 

 

yes I want the same, put this post under request and suggestion and I will vote for it.
sometimes I wonder what TP-Link is thinking when they create such a solution. can block all port on vlan but not open up any ports. 

 

this you have to fix TP-Link

 

  0  
  0  
#2
Options
Re:Allowing VLAN access to shared resources
2023-07-24 13:02:00

  @MR.S It does seem like a glaring omission.

 

I found and upvoted this feature request for the ER7207 (though I have the ER605):

ER7206 Gateway ACL LAN-LAN IPGroup

  0  
  0  
#3
Options