Access devices from other vlan

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Access devices from other vlan

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Access devices from other vlan
Access devices from other vlan
2023-11-15 22:42:34
Model: ER8411  
Hardware Version: V1
Firmware Version: 1.1.1

I have 3 vlans

 

1 - 192.168.0.1/23

40 - 10.40.0.1/24

41 - 10.51.0.1/23

 

In vlan 1 with ip 192.168.1.100-150 i have some static ip devices, my goal is to have connection to them from vlan 40 (10.40.0.2-254). I tryed acl, static routing but without any success.

 

Only sucess i do when i configure SSL VPN with some adresses from VLAN1 pool, but its not a proper solution.

 

What i have to configure in controler with er8411 (i have HP switches) to have acess from VLAN 40 (ex. 10.40.0.10) to vlan 1 devices (192.168.1.100-150) ?

  0      
  0      
#1
Options
4 Reply
Re:Access devices from other vlan
2023-11-16 02:39:38

Hi @8host 

Thanks for posting in our business forum.

Do you have ACL? If you have set up the VLAN-based ACL, of course, you don't have access to the VLANs.

You have to set up the GW ACL to allow the access. Not VPN, not Static Routing, use the GW ACL.

This link would be helpful in configuring that. ER8411 is a stateful ACL now. So, it applies to it as well. How to implement VLAN unidirectional access through ACL configuration of Business Router

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. Don't be a lazy asker. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#2
Options
Re:Access devices from other vlan
2023-11-16 08:27:15

Laptop conf:

 

Networks:

 

Ip groups:

 

 

 

ACL:

 

 

(I cannot do LAN-LAN based on Ipgroup)

 

Effect ;)

 

  0  
  0  
#3
Options
Re:Access devices from other vlan
2023-11-16 09:43:08

Hi @8host 

Thanks for posting in our business forum.

8host wrote

Laptop conf:

 

 

Networks:

 

 

Ip groups:

 

 

 

 

 

ACL:

 

 

 

(I cannot do LAN-LAN based on Ipgroup)

 

Effect ;)

 

 

OK. None of the ACLs is set to Deny.

So, can you run this for me? Ping your gateway IP that is in another VLAN. Don't ping the IP address of the hosts. Ping the gateway 10.40.0.1, 10.51.0.1, or 192.168.0.1.

Let me know the result.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting Manual ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. Don't be a lazy asker. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options
Re:Access devices from other vlan
2023-11-16 15:42:18

 Yes i can.

 

When i run VPN server with 192.168.0.X pool i have no ping as well, but when i run 192.168.1.X pool its works great.

 

 

  0  
  0  
#5
Options