ports only internet not LAN connection

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

ports only internet not LAN connection

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
ports only internet not LAN connection
ports only internet not LAN connection
2022-01-30 19:10:22
Model: TL-SG3428  
Hardware Version:
Firmware Version:

Is possible with the TP-LINK SG-3428 switch to use ACL's for placing a few ports in a kind of isolation so that they cannot connect to the other devices on the switch?. I would like to put 2 ports in a kind of isolation that is they must connect to the internet but not connect to other devices on the lan. All ports on the switch are connecting to a tp-link Archer C7 router and that router does not supprt vlan's.

 

The reason that i am doubting this is that ACL's are based on ingress traffic and not traffic to deny from specific ports.

I have looked at it but when making an ACL and binding the vlan to it where ports 5 and 7 are in then this does not work correct because the mindset is wrong, the mindset is set to egress from ports 5 and 7 and not ingress from router to ports 5 and 7.

 

Is it possible, or even with another method?

 

 

  0      
  0      
#1
Options
5 Reply
Re:ports only internet not LAN connection
2022-01-31 02:36:12

@surfer1 

I'm not sure if this will achieve what you want.
1. In standalone mode, keep the default VLAN 1.
2. Create 2 new (or more) VLAN, I'll use VLAN 2 and VLAN 3 here, and put the two devices you want to isolate into VLAN 1&2, and add the others to VLAN 1&3, the port connected to Archer belongs to VLAN 1&2&3 and then set the corresponding PVID values. This way your two devices will be isolated from other devices and at the same time have access to the network.

 

  0  
  0  
#2
Options
Re:ports only internet not LAN connection
2022-01-31 08:21:26

@Yannie 

 

Yannie,

 

You mean like this?

 

5 and 7 in vlan 1-2 and PVID 2??

otherports in vlan 1-3 except uplink port in vlan 1,2,3 and PVID 3 for all ports accept uplink port PVID 1?

I have tried this but then ports 5 and 7 have no internet access at all.

 

On this forum there is another post from me with the answers in it. I do not know why but i think PVID's are the one thats causing that.

  0  
  0  
#3
Options
Re:ports only internet not LAN connection
2022-01-31 08:50:57

@surfer1 Other ports not in vlan2, only in vlan1 and 3.

Suppose port 1 is connected to the router, port 5&7 are the specific devices and then suppose port 2&3&4&6&8 for other devices. Try to use this 

VLAN 1 : all ports

VLAN 2 : port 1&5&7

VLAN 3 : port 1&2&3&4&6&8

port 1 : untagged,PVID 1

port 5&7 : untagged, PVID 2

port 2&3&4&6&8 : untagged, PVID 3

  0  
  0  
#4
Options
Re:ports only internet not LAN connection
2022-02-12 18:18:57
Hi Yannie, This configuration is not what i had in mind. It does the trick that devices in ports 5 and 7 cannot reach devices on the other ports and can go to the internet however: 1. I cannot ping the switch ip anymore from whatever port, so the switch becomes unreachable to monitor. 2. Devices on other ports can also not reach to devices on ports 5 and 7, that is not so bad but i would like to do ping to the devices on ports 5 and 7. The cause of this must be the PVID setting. whenever i put a port on a different PVID it cannot reach the switch anymore from that port.
  0  
  0  
#5
Options
Re:ports only internet not LAN connection
2022-02-28 08:21:50
do uo have a suggestion for this to solve?
  0  
  0  
#6
Options