2
Votes

Prevent an ACL being created that blocks management VLAN from itself

 
2
Votes

Prevent an ACL being created that blocks management VLAN from itself

Prevent an ACL being created that blocks management VLAN from itself
Prevent an ACL being created that blocks management VLAN from itself
2024-08-05 19:41:01 - last edited 2024-08-15 08:35:48
Model: OC200  
Hardware Version: V1
Firmware Version: latest

OK, So this is mostly my fault, and a lesson learned.  But i also feel there should be a built in check to prevent the very thing i did.

 

I was modifying a switch ACL and accidentally blocked management vlan from itself, killing all omada functionality network wide once it populated to all switches before i could stop it.

 

I had to disconnect my OC200 from lan, set a static IP on my laptop to connect to management vlan without any switches blocking traffic, correct the ACL mistake.  I hoped that was the end of it, but evidently whatever method Omada uses to provision equipment doesnt bypass ACLs on the management vlan, so my change didnt make it to any of the switches.

 

I had no choice but to do a hardware reset over putty (they are all L3 switches without a reset pinhole) on each switch, having to unscrew some from some racks to access the power cord.  Once all were factory reset I had to manually connect to my controller again to start the adoption process.

 

Thankfully, i didnt have to reset my ER8411 gateway with its super slow boot times.

 

What a pain in the behind.

 

Anyway, i really feel there should be a simple check in the controller GUI that prevents this from hapenning.

#1
Options
1 Accepted Solution
Re:Prevent an ACL being created that blocks management VLAN from itself-Solution
2024-08-06 03:34:14 - last edited 2024-08-15 08:35:48

Hi  @GRL 

 

I can totally understand the situation and your feelings. But the controller already gave notice when we configured the management VLAN:

 

Recommended Solution
#2
Options
2 Reply
Re:Prevent an ACL being created that blocks management VLAN from itself-Solution
2024-08-06 03:34:14 - last edited 2024-08-15 08:35:48

Hi  @GRL 

 

I can totally understand the situation and your feelings. But the controller already gave notice when we configured the management VLAN:

 

Recommended Solution
#2
Options
RE:Prevent an ACL being created that blocks management VLAN from itself
2024-09-19 15:21:01
failsafe
#3
Options