Site with 3 VLAN's and multiple switches

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Site with 3 VLAN's and multiple switches

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Site with 3 VLAN's and multiple switches
Site with 3 VLAN's and multiple switches
2024-04-28 14:11:46

I have a site which already runs 5 Omada access points and a controller, but switching is done on Netgear and firewalling /routing with Sophs XG.
The goal is to consolidate on 1 platform, and I think Omada would be a great solution.Altough I still have some questions...

The site internet connection is 1GBps, so this should be supported with IDS enabled.

 

There is a main VLAN, a guest VLAN and an IoT VLAN :

  • The guest VLAN is isolated and has internet access.
  • From the main VLAN, there is internet access and some protocols should be opened towards the IoT VLAN.
  • From the IoT VLAN some protocols need to be opened to the main VLAN and to the internet.
  • mDNS should be possible between main and IoT VLAN
  • DNS server is running on main VLAN (so should be accessible from IoT as well)

 

Logically there are switches on 3 locations, interconnected by 802.1Q trunks.

 

My question is: is this fine-grained statefull firewalling supported and if yes on which platforms taken the bandwidth in consideration ?

I've seen a lot of articles, but it stays very unclear on the classif statefull firewalling as there are different ACL types ?
Are all switches supported in this setup ?

  0      
  0      
#1
Options
6 Reply
Re:Site with 3 VLAN's and multiple switches
2024-04-29 02:46:24 - last edited 2024-04-29 02:47:07

Hi @Geert_V 

Thanks for posting in our business forum.

IDS or DPI would take a toll on the Internet speed as they require hardware resources to process.

VLAN interface and mDNS are supported. Stateful ACL is supported on the router. Switch and AP are stateless ACLs. But not sure if that's what you are looking for.

https://emulator.tp-link.com/5.11-605v2/index.html

Think you can do all you described but still need you to verify this yourself.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#2
Options
Re:Site with 3 VLAN's and multiple switches
2024-04-29 07:47:02

  @Clive_A thanks for your reply.
Concerning hardware, would this be possible with ER7206 or referably ER8411 ?
What I would like to do, and this isn't clear, is to have fine-grained firewalling between the VLAN's.
E.g. :

Allow SSH from standard to IoT VLAN, but not the other way around.

Allow MQTT from IoT to standard VLAN.

 

Preferably only for specific hosts.

 

What I see when using GW ACL:

- In service type, I cannot create specific services (non standard ports) ?

- When using LAN --> LAN, source and destination are networks and not hosts

 

So from this perspecive, it seems not possible

  0  
  0  
#3
Options
Re:Site with 3 VLAN's and multiple switches
2024-04-29 07:58:16 - last edited 2024-04-29 08:06:37

  @Geert_V 

 

Router LAN to LAN ACL has two options, either close everything or open everything. so what you are trying will not work. it is strange that TP-Link has not prioritized getting this in place, it is perhaps one of the most important things a router should do, but it maybe come sometime in the future,

 

 

  1  
  1  
#4
Options
Re:Site with 3 VLAN's and multiple switches
2024-05-02 06:33:13 - last edited 2024-05-02 06:33:45

  @MR.S and is there an alternative in this situation ? Or is the TP-Link solution useless for more corporate oriented networks ?

  0  
  0  
#5
Options
Re:Site with 3 VLAN's and multiple switches
2024-05-02 08:44:07

  @Geert_V 

 

There is a solution but it is not very good, if you have an Omada switch you can do some LAN to LAN ACL on the switch.
Omada is a network for the SMB market, I would almost say SOHO/SMB, so if your company requires advanced ACL at router level, find something else.

 

But if I have to guess, router ACL will come with more functions. but no one knows how long it will take, now it has probably been 5 years since the first routers came to Omada and it is still not in place.

 

I'm not entirely sure about this, but I think you have more options with the router ACL if you run the router in stand alone. I haven't tested it since I only run in controller mode.

 

 

  0  
  0  
#6
Options
Re:Site with 3 VLAN's and multiple switches
2024-05-06 11:59:23

Hi  @Geert_V 

Geert_V wrote

  @MR.S and is there an alternative in this situation ? Or is the TP-Link solution useless for more corporate oriented networks ?

IP-Port ACL for the GW has been considered and entered the evaluation. Team's aware of this. I was asked by the dev about this feature once before. It is promising to see this feature in the future. But this does not make up a concrete guarantee yet.

You may wait and review this in the future.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#7
Options

Information

Helpful: 0

Views: 490

Replies: 6

Related Articles