lan to lan firewall rule

lan to lan firewall rule

lan to lan firewall rule
lan to lan firewall rule
Sunday - last edited Monday
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version:

I have an ER605 router and I'm trying to configure firewall rules to allow communication between specific IP groups within my LAN. I've created IP groups for different devices on my network, but I'm unable to select these groups when creating LAN-to-LAN firewall rules. The interface only shows options for VLANs.

I would like to know if it's possible to create LAN-to-LAN firewall rules that allow communication based on IP groups instead of VLANs. If so, please provide instructions or guidance on how to build this.

 

End-game is, I have cameras that I blocked all internet access to as I’m using RTSP, but the cameras need access to their servers for daily firmware checks, so I need to give them very limited access to the internet at a set time range. I tried using static route which I created but need to create a new firewall rule for this but can’t cause source and destination on LAN to LAN only shows VLAN names.

any other options to sue. er60 is a great router by the way.

 

any suggestions would be great!!


 

  0      
  0      
#1
Options
6 Reply
Re:lan to lan firewall rule
Sunday

Hi @trekpluto,

 

Routers see traffic that it routs between two networks. Lan to Lan traffic doesn't go through the router (same network) and thus no firewall rules would apply. The solution is to put the cameras in a separate VLAN and then you should be able to create the firewall rules you need.

  1  
  1  
#2
Options
Re:lan to lan firewall rule
Sunday

  @D-C thanks, i get the lan part in its isolated segmented environment.

 

I see access control under firewall and want to restrict internet acccess to the cameras on its no internet access vlan, maybe create a "tunnel" where vlan30 (cameras) get access to limited internet, but i don't see those parameters in firewall as lan to wan is fully blocked but would like to do lan to lan but it doesn't give me options in source or destinaation to do this, only shows the names of my vlans.  

i tried to create static route for vlan30 (blocked vlan for cameras) but it doesn't show in firewall options (acccess control) again under source and destinations

any other preferences to i could use to create limited access for vlan30 without fully blocking it?

  0  
  0  
#3
Options
Re:lan to lan firewall rule
Sunday

  @trekpluto 

 

you cannot use ip port group or ip groups on router lan to lan acl, to achieve this you must use switch acl,

 

  1  
  1  
#4
Options
Re:lan to lan firewall rule
Monday

  @MR.S Thank you. Will give that a try, looks very detailed

  0  
  0  
#5
Options
Re:lan to lan firewall rule
Monday - last edited Yesterday

  @MR.S the web interface that i see for er605 is missing port statistics and rate control. Is there another interface that i should use? Don't see where inter vlan would be setup, any suggestions would be valuable

  0  
  0  
#6
Options
Re:lan to lan firewall rule
Yesterday

  @trekpluto 

 

Are you using the router in stand alone? Then I think it's acl lan to lan, but I don't know how to configure the router in stand alone. So then you almost just have to read the user manual for the router.

 

  0  
  0  
#7
Options