VLAN and Firewall Rules

VLAN and Firewall Rules

VLAN and Firewall Rules
VLAN and Firewall Rules
2024-09-18 05:40:18 - last edited 2024-10-15 09:11:30
Hardware Version: V20
Firmware Version:

I'm having a hard time trying to get this working and some behavior that I cannot figure out anymore lol, so looking for help now.

 

I have 3 VLANs = default, guest and IoT.

I want to block from IoT to default and guest, but allow default to be able to access IoT.

I want default to be able to AirPlay to IoT.

 

So, as of now, I was able to get Block IoT to the 2 others and AirPlay, but I can't make that default to IoT working.

 

My setup is:

 

Router = Omada ER707-M2 Latest Firmware

EAP = 660 HD v2 latest firmware

Switch = Netgear (not omada/tp-link)

Linux Software Controller latest version

 

I have a firewall rule under EAP. First rule is to allow AirPlay and Second rule is to block IoT. mDNS is enabled, so with this I can do AirPlay, IoT can't access, but I can't access from default to IoT:

 

 

If I disable the second rule above, and go to Gateway ACL and enable the below rule, I can Block IoT to default and guest and I can ping from default to IoT, but AirPlay does not work:

 

 

So, why do I need to deal with that Gateway ACL? Because I don't have an Omada switch to manage the rules? Why doesn't the EAP ACL work as expected? Interesting that I have "block/deny" rules and when I enable them, things start to wok, lol - isn't that weird? what am I missing here? Of course I can't create the same AirPlay rule in the Gateway ACL since it does not allow me to do IP and Ports.

 

This is my routing table just in case

ID

DESTINATION IP/SUBNETS

NEXT HOP

INTERFACE

METRIC

1 0.0.0.0 / 0 192.168.3.1 2.5G WAN1 0
2 192.168.0.0 / 24 0.0.0.0 secure 0
3 192.168.3.0 / 24 0.0.0.0 2.5G WAN1 0
4 192.168.3.1 0.0.0.0 2.5G WAN1 0
5 192.168.50.0 / 27 0.0.0.0 Guest-Lan 0
6 192.168.100.0 / 25 0.0.0.0 IoT-Lan 0

 

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:VLAN and Firewall Rules-Solution
2024-09-20 07:00:44 - last edited 2024-10-15 09:11:30

Hi  @dimago 

 

EAP ACL is bidirectional. Only gateway ACL and switch ACL can do uni-direction. This is the reason.

We had forwarded feedback that add IP group for Gateway ACL. R&D are still working on it.

 

Currently, you may give the Airplay a separate VLAN network.

Recommended Solution
  0  
  0  
#3
Options
1 Reply
Re:VLAN and Firewall Rules-Solution
2024-09-20 07:00:44 - last edited 2024-10-15 09:11:30

Hi  @dimago 

 

EAP ACL is bidirectional. Only gateway ACL and switch ACL can do uni-direction. This is the reason.

We had forwarded feedback that add IP group for Gateway ACL. R&D are still working on it.

 

Currently, you may give the Airplay a separate VLAN network.

Recommended Solution
  0  
  0  
#3
Options