Issue with IPGroup ACL

Issue with IPGroup ACL

13 Reply
Re:Issue with IPGroup ACL
2024-08-26 07:56:29

  @Hank21 

 

sorry for the confusing explanation. The essence is, that the issue is still there, means, if I set up a time schedule based ACL to a subgroup (/28) of a complete /24 VLAN, whenever the ACL schedule controls the access (either disabling the connectivity to IPGroup_Any, or even re-enabling it), the clients of the /24 are controlled fine by ACL, but every other clients of the /24 disconnects from the internet for short time. MS Teams sessions are broken, online connections are broken for few seconds, and even some streaming is glitching as well. What I have noticed, wireless devices are not disconnecting ie from the WLAN, but the existing sessions towards the internet got broken and they need to be re-established. This re-establishment happens in different way, depending on the OS of the device (android or windows), or even the application (online games/VPN clients/apps), of which internet sessions are broken.

Another fresh finding is, that the issue not necessarily related to the time based control of an ACL. If it is disabled for the given ACL rule, and I disable/enable the ACL manually from the OMADA UI, issue is there too.

Please try to reproduce it in your env, hope, You will experience the same and then can advise, how to mitigate it.

 

gZoma

 

  0  
  0  
#12
Options
Re:Issue with IPGroup ACL
2024-08-28 20:13:00 - last edited 2024-08-28 20:38:03

  @Hank21 

 

as I shared earlier, I had ER605 V1 earlier only, it had 1.3.1. firmware, with exactly the same issue. Recently its replaced with ER7212PC V1 running on 1.2.0 Build 20240716 Rel.80083.

For the replacement I preferred ER7212PC to ER605V2 (brand new model with more hw capabilities like POE ports and built-in Omada controller) with the hope, it will have newer or at least more stable features. Since then experineced, that the firmware of ER7212PC (inclusive Omada version) has more generation of late, compared to the old device.

Hoped its only delayed in the versioning, not in the features and bug remediations, but it doesnt really seem so.

Any near future plans for ER7212PCV1 firmware, where this basic issue will be fixed? Or any other suggestion, with which configuration I can differentiate groups of devices in the same VLAN in an ACL rule? Of course without having the reported impact on the other devices of the VLAN.

 

regards

gZoma

 

  1  
  1  
#14
Options
Re:Issue with IPGroup ACL-Solution
2024-08-29 02:31:19 - last edited 2024-08-29 02:46:40

  @gZoma 

I confirmed with the R&D department that the ER7212PC V1.2.0 does not yet include the remedy to this issue. Please wait for the next firmware release. This is an issue that we will address. This problem has already been resolved with the latest firmware on our ER605 V2.

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
Recommended Solution
  0  
  0  
#15
Options