LAN firewall rules on Omada controlled TL-R605 or TL-ER7206

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

LAN firewall rules on Omada controlled TL-R605 or TL-ER7206

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
LAN firewall rules on Omada controlled TL-R605 or TL-ER7206
LAN firewall rules on Omada controlled TL-R605 or TL-ER7206
2021-07-02 13:27:20

My current LAN has VLANs for different purposes:

- Main LAN has access to internet, guest and IoT VLANs

- Guest VLAN has a access to internet, but not to main LAN or IoT VLAN

- IoT VLAN has no access to internet and only to MQTT broker on the main LAN

 

These VLANs are "carried" with EAP WLAN access points as different SSIDs.

 

Additionally, there are targeted firewall rules:

- IPv6 traffic is allowed between internet and main LAN

- IPv6 traffic is disabled on Guest and IoT VLANs

- IPv4 SSH and HTTPS are targeted to certain IP in main LAN

- From main LAN, IPv6 traffic to internet is disabled for certain MACs

 

IPv4 SSH and HTTPS forwarding support was found in the Omada SDN Software Controller 4.3.5 User guide, but I did not find instructions to other traffic rules.

 

Question: Is is possible to create these kind of traffic rules under Omada SDN controlled network?

 

  0      
  0      
#1
Options
1 Reply
Re:LAN firewall rules on Omada controlled TL-R605 or TL-ER7206
2021-07-03 08:24:24

@KTuulos 

 

- Main LAN has access to internet, guest and IoT VLANs

- Guest VLAN has a access to internet, but not to main LAN or IoT VLAN

 

The first two is feasible. Just create Deny ACL rules on Guest VLAN.

 

- IoT VLAN has no access to internet and only to MQTT broker on the main LAN

 

Not sure if this one will work or not, you could try to use allow ACL rules and make it higher priority than the deny rules.

 

- IPv6 traffic is allowed between internet and main LAN

- IPv6 traffic is disabled on Guest and IoT VLANs

- IPv4 SSH and HTTPS are targeted to certain IP in main LAN

- From main LAN, IPv6 traffic to internet is disabled for certain MACs

 

I don't think there is somewhere to set IPv6 traffic rules on SDN Controller....

Just striving to develop myself while helping others.
  0  
  0  
#2
Options