ER605 Access Control help

ER605 Access Control help

ER605 Access Control help
ER605 Access Control help
Saturday - last edited Saturday
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.5 Build 20240522 Rel.75860

Hi!

 

I have set up 2 VLANs; "LAN" which is my main one with all my PCs on it, and "IoT" for stuff like Alexa, FireTV etc.

 

I have an access control rule to block all from IoT to LAN, but I have a server (on LAN) running Jellyfin to stream my media library, and I want my FireTV device (on IoT) to be able to access only that service on LAN.

 

I have created a "Service Type" for Jellyfin (8096 TCP).

 

And added a second Access Control rule:

 

Unfortunately, I think the ALL rule is overriding the specific rule, and the order of the rules in the list doesn't seem to do anything. If I change the Block rule to Allow, the device can access the server, so I know that all devices are connected okay.

 

Is there some way to set a precedence or rule order, which allows me to easily configure the above scenario?

 

The only way I can think of is to create new Service Types for everything except Jellyfin, and block those, which is very laborious, especially if I might want to allow another service in the future.

 

Thanks!

  0      
  0      
#1
Options
1 Accepted Solution
Re:ER605 Access Control help-Solution
Saturday - last edited Saturday

  @Memran 

 

move the allow rule up above the deny rule, rules are read from the top down. you start with a deny and then it don't help with the allow below.

 

Recommended Solution
  1  
  1  
#2
Options
5 Reply
Re:ER605 Access Control help-Solution
Saturday - last edited Saturday

  @Memran 

 

move the allow rule up above the deny rule, rules are read from the top down. you start with a deny and then it don't help with the allow below.

 

Recommended Solution
  1  
  1  
#2
Options
Re:ER605 Access Control help
Saturday

  @MR.S 

 

Thanks for your reply!

 

I have done the following:

but unfortunately, it still seems to be blocked.

Additionally, I tried to update the Service Type to have source ports 0-65535, and destination ports 8096-8096:

but still blocked.

 

So far the only config I have succeeded with is using separate Service Types for everything before port 8096 and everything after:

however this will quickly become difficult to manage if/when I need to allow ports for other services.

  0  
  0  
#3
Options
Re:ER605 Access Control help
Saturday

  @Memran 

 

I'm not familiar with how it's done in stand alone, I use controllers and it's a bit of a different way to configure. But like I said, rules are read from top to bottom and are actually pretty simple, I don't know how to create service groups. I recommend you look in the router's user manual.

 

  0  
  0  
#4
Options
Re:ER605 Access Control help
Saturday

  @MR.S 

Actually, your solutiomn was correct! While I was playing around with my vlan tags (for a totally different reason) I misconfigured it, at the same time as doing what you suggested!

My appologies for the confision!

 

I've marked your first reply as a solution.

 

Thanks! smiley

  0  
  0  
#5
Options
Re:ER605 Access Control help
Saturday

  @Memran 

 

👍

  0  
  0  
#6
Options