Gateway ACL, LAN->LAN, IP-Port Needed.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Gateway ACL, LAN->LAN, IP-Port Needed.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Gateway ACL, LAN->LAN, IP-Port Needed.
Gateway ACL, LAN->LAN, IP-Port Needed.
2024-01-21 12:48:23
Tags: #ACL
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.3

Currently its not possible to define IP-Port or any other group in Gateway ACL rules.

 

 

This is crucial I think for allowing communication between isolated VLANs, for use-cases such as Internal DNS server etc..

It's currently only possible to define entire Network(s).

 

 

Or can you please advice, how to allow communication from isolated IoT VLAN to main VLAN DNS server ? Is there some other way ?

 

EDIT: By "Isolated" I mean I have a Gateway ACL rule to disallow communication between IoT VLAN -> All other VLANs, thus making communication to DNS server in main VLAN impossible.

  4      
  4      
#1
Options
8 Reply
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-01-21 13:05:09

  @pdu_ 

 

Your observation is completely correct, I thought at first it was a bug but then it turned out that it wasn't. with tp-link you can close all the doors but not open any individual doors. so what the idea is at tp-link, I don't know

 

  3  
  3  
#2
Options
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-01-22 04:03:06

Hi @pdu_ 

Thank you for your feedback and post. We have forwarded your request to our developer team for evaluation.

To stay updated on firmware releases, we recommend subscribing to the pinned thread on the related page or regularly checking our official website where new releases are typically announced promptly.

Please note that all requests undergo thorough evaluation by our developer team before being added to the roadmap. This process may take some time, so please be patient if you don't see immediate results. Features with lower priority or fewer user reports might experience delays in implementation as we gather more feedback.

It is important to understand that submitting a request does not guarantee its implementation; only requests that pass the evaluation will be considered for inclusion in future updates.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  4  
  4  
#3
Options
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-02-08 02:16:23
Same issue with the 707-M2 router. The ability of having LAN-LAN IP-Port Group rules is a must. Any news about future support? Thank you!
  2  
  2  
#4
Options
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-02-08 02:34:15

  @ManoloTech 

Take a look at the posts from Clive, I think he said it's been recorded.

ScReW yOu gUyS. I aM GOinG hoMe. —————————————————————— For heaven's sake, can you write and describe your issue based on plain fact, common logic and a methodologic approach? Appreciate it.
  1  
  1  
#5
Options
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-02-12 09:49:35

Hi @Tedd404 , that's why I was asking, since the original thread is about the ER605 (TL-R605) but it also affects the ER707-M2. @Clive_A mentions he have forwarded the initial request to the developer team for evaluation, but I wanted to know if there were any updates from the developer team about implementing this feature or not. For me it is a basic feature and a blocker for my current setup. 

 

Thank you!

 

 

  2  
  2  
#6
Options
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-02-14 08:13:25

Hi @ManoloTech 

ManoloTech wrote

Hi @Tedd404 , that's why I was asking, since the original thread is about the ER605 (TL-R605) but it also affects the ER707-M2. @Clive_A mentions he have forwarded the initial request to the developer team for evaluation, but I wanted to know if there were any updates from the developer team about implementing this feature or not. For me it is a basic feature and a blocker for my current setup. 

 

Thank you!

 

 

https://community.tp-link.com/en/business/forum/topic/606980?replyId=1320472

Refer to this comment. Cannot give you a specific time about it but it should be available soon.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  3  
  3  
#7
Options
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-02-15 08:32:58 - last edited 2024-02-15 08:37:25

  @Clive_A @pdu_  @Tedd404 

 

Thanks for the update @Clive_A , really waiting for it to be implemented as this is preventing me to segregate my network properly. 

  1  
  1  
#8
Options
Re:Gateway ACL, LAN->LAN, IP-Port Needed.
2024-02-15 20:09:49

  @pdu_ 

 

It's "ACL, LAN->LAN, IP-Port" in the topic, so I guess it's really about Port ACLs. The other one is "ACL LAN-LAN IPGroup." That's not quite the same. Actually, I would be really surprised seeing Port ACLs on these routers.

Kris K
  0  
  0  
#9
Options