Use IP Group in Lan-Lan ACL on Omada

Use IP Group in Lan-Lan ACL on Omada

13 Reply
Re:Use IP Group in Lan-Lan ACL on Omada
Yesterday

So how does one use Switch ACL to allow one IP to go through? I have a SG2008 switch

 

I created a Gateway ACL with Deny from IoT to Main

I then created a Switch ACL with Permit for IoT:IP/32 to Main:IP/32 

 

I can't ping Main:IP from IoT:IP

 

Or would I need to nix the Gateway ACL and think of what devices I want from IoT to be able to communicate with Main (e.g., like my hubs) ... or just hope that LAN-LAN IP Groups are coming to the Gatway at some point....

  0  
  0  
#12
Options
Re:Use IP Group in Lan-Lan ACL on Omada
23 hours ago

  @GoodOmens I have a feeling that in order to achieve that you may need to do intra-vlan routing on the switch rather that on the gateway :(

  0  
  0  
#13
Options
Re:Use IP Group in Lan-Lan ACL on Omada
12 minutes ago

  @theradioguy It seems my pleads were answered. Controller 6.1 just released has Gateway level IP Groups, ports etc. My above scenario works as intended - I can whitelist specific IoT VLAN IPs (and I guess ports if I wanted) to override the blanket IoT->Main deny.

  0  
  0  
#14
Options