Use IP Group in Lan-Lan ACL on Omada
I have inherited a TP Link Omada setup and am trying to setup segregation between VLANs. I've started by creating firewall rules to deny traffic between the different VLANs, however, I need to be able to allow certain management devices access to specific IPs on other VLANs, but when I try to create an ACL of type 'LAN-to-LAN' the only 'source' option is to choose a network, not an IP Group or a single IP.
So, my question is - how do I allow one or two specific devices on a VLAN access to either an entire VLAN, or access to another specific device?
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
the short answer is that you can't, you can manage it with switch ACL if you have Omada Switch connected to the router, easy managed switch does not have ACL
- Copy Link
- Report Inappropriate Content
In the lastest batches of router firmwares (with controller 5.15 adaptations) there is a new option in DNS proxy - it enables a forceful ovverride of ALL dns requests to the LANs you specify to go to the dns address you specify

I believe you can set the DNS address to anything you want, even an internal IP, then have the clients DNS set to the router IP for each vlan, and the proxy will take effect
- Copy Link
- Report Inappropriate Content
the short answer is that you can't, you can manage it with switch ACL if you have Omada Switch connected to the router, easy managed switch does not have ACL
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
yes i agree that it is a significant problem when router acl lacks this option. it will probably come but i don't know when. emergency solution is to use switch acl or eap acl. it works but is not optimal
- Copy Link
- Report Inappropriate Content
@theradioguy it's such a shame .. i want to use a single adguard dns server for all vlans but as im not allowing any type of communication between vlans in gateway acl i cant , i had to create an adguard server for each vlan .. , its annoying to use swtich acl specially if you have lots of devices in each vlan .. i hope they add this feature asap ... it is a basic feature to have.. block the whole traffic but except to that specific IP group .
- Copy Link
- Report Inappropriate Content
Yes, it's unfortunate that groups aren't in place in LAN-LAN yet, rumors say that it will come in the 5.16.x version, but it could easily take another year, in the meantime you can create your own VLAN that you have the Adguard server in, then you block all networks except the VLAN that the Adguard server is in.
in this VLAN you can also have other shared resources
- Copy Link
- Report Inappropriate Content
In the lastest batches of router firmwares (with controller 5.15 adaptations) there is a new option in DNS proxy - it enables a forceful ovverride of ALL dns requests to the LANs you specify to go to the dns address you specify

I believe you can set the DNS address to anything you want, even an internal IP, then have the clients DNS set to the router IP for each vlan, and the proxy will take effect
- Copy Link
- Report Inappropriate Content
Can't believe such basic feature was not implemented right from the beginning. Hell, it is not even a "feature", it is the most basic thing.
Omada is supposed to be a "business" grade solution yet they have so many misses - this one and proper QOS (like how it is done in Cisco) are the most painful
P.S. A stupid idea but if this is allowed on a switch ACL only - what if I put a small 4 ports Omada switch between my ER Omada gateway and other (non-Omada) switch?
- Copy Link
- Report Inappropriate Content
SG2008 and higher switches will allow you use use the ACLs in the way you want. ES series switches do not support ACLs.
- Copy Link
- Report Inappropriate Content
@GRL It looks like TP-Link deliberately moving part of gateway (routing!) functions to switches? But you need L3 switch to do that which may be an overkill for a home setup.
BTW, Thank you VERY much for mentioning that, you literally saved me from buying a useless ES switch!!
Is there any feature matrix where we could see what feature is supported on what device?
- Copy Link
- Report Inappropriate Content
Here are two links that may help you with your switch questions:
https://community.tp-link.com/en/business/forum/topic/845926
https://community.tp-link.com/en/business/forum/topic/847024
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 1633
Replies: 10
Voters 0
No one has voted for it yet.
