ACL Rules

ACL Rules

ACL Rules
ACL Rules
3 weeks ago - last edited 2 weeks ago
Tags: #ACL

Hi,

 

I really do not understand how the acl rules works.

I have 4 VLANS setup. 2 of them are Home and IoT.

I have rule under Switch ACL which Deny (all protocals) IoT Network to Home Network.

Under IoT VLAN I have nvidia shield with moonlight app (game streaming)

Under Home VLAN my PC with Sunshine app (game streaming)

Both devices are connected to the same switch. PC to port with Home VLAN Profile and Shield to port with IoT VLAN Profile.

 

If the rule is disabled I can establish connection and all is working fine.

When rule is enabled there is no connection which is expected becouse Home can talk with IoT Network, but IoT can't answer to Home (that is how I understand this).

I have created 2 Profiles:

IP Port Group profile with all needed ports and Shield IP Subnet 192.168.0.43 / 32

and second profile IP Group with IP Subnet 192.168.20.10 / 32 which is my PC.

New Allow Rule which is above of deny rule: Allow IP Port Group (Shield with specific ports) to IP Group (PC)

I still cant establish connection so I was thinking maybe I do not have all ports included in profile so I opened a full range 0-65535, but still no luck.

I created new profile IP Group with Shield IP address 192.168.0.43 / 32 and I changed ACL rule to Allow IP Group (Shield) to IP Group (PC) and is working fine.

 

I do not understand why rule IP Port Group to IP Group is not working.

I have another situation like that between my Home Assistant and PC where IP Port Group to IP Group desent work.

  0      
  0      
#1
Options
1 Accepted Solution
Re:ACL Rules-Solution
2 weeks ago - last edited 2 weeks ago

Hi @Sly01 

Thanks for posting in our business forum.

Start with the basic ACL guide:

ACL Guide Compilation

 

As for the switch, you have to have ACL to allow. It is a stateless ACL unlike the stateful.
The FAQ on the official website also explains how to config ACL on the switch.

 

/24 is different from /32. I think you need a lot of readings before starting with the config. /32 defines a single IP address if you want a single device IP.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
2 Reply
Re:ACL Rules-Solution
2 weeks ago - last edited 2 weeks ago

Hi @Sly01 

Thanks for posting in our business forum.

Start with the basic ACL guide:

ACL Guide Compilation

 

As for the switch, you have to have ACL to allow. It is a stateless ACL unlike the stateful.
The FAQ on the official website also explains how to config ACL on the switch.

 

/24 is different from /32. I think you need a lot of readings before starting with the config. /32 defines a single IP address if you want a single device IP.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#2
Options
Re:ACL Rules
2 weeks ago

Hi  @Clive_A 

 

My bad. Typing error. In all cases I meant /32 single IP.

  1  
  1  
#3
Options