Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT

Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT

Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT
Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT
2025-05-03 07:21:02
Hardware Version:
Firmware Version: 5.15.20.20

Dear community,

I thought it would be something simple to set up very basic gateway ACL rules, however I cannot make it work although I followed various guides.

Here is my setup:

  • Router ER7206 connected to internet modem
  • Switch SG2210P (1) connected to router ER7206, profile is set to “All”
  • Two further switches SG2210P (2) and SG2218P (3) connected to switch SG2210P (1), profiles are set to “All”
  • AP EAP650 connected to switch 3, profiles are set to “All”
  • AP EAP683 connected to switch 1, profiles are set to “All”

I have three LANs:

  • Management VLAN 31, all LAN interfaces
  • Main VLAN 42, LAN interface WAN/LAN1
  • IoT VLAN 73, LAN interface WAN/LAN1; for this one I also have created a corresponding Wifi

Profiles on the switches are either set to “All” (in case of uplink port or AP port, or to the specific VLAN). Example: If an IoT device is connected via wire, the switch port would show profile “IoT”.

Here is my very simple requirement:

  • Let IoT VLAN not talk to the internet
  • Let IoT VLAN not reach the other VLANs, but let the other VLANs reach the IoT VLAN

What I did as a starter: Create an ACL gateway rule LAN->WAN, Deny, All protocols, source network IoT, destination IP Group:IPGroup_Any. When activating this rule, however internet access is blocked for ALL VLANs and all clients in the VLANs – and this is what I do not understand.

Is there anything completely wrong with my configuration? What am I missing?

Thanks for any input!

  0      
  0      
#1
Options
5 Reply
Re:Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT
2025-05-03 13:57:29

  @Betonmischer 

 

This rule should work, i have similar.  can you provide a screenshot of all your rules ?

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#2
Options
Re:Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT
2025-05-03 18:05:26 - last edited 2025-05-03 18:12:17

  @GRL 

Hello and thanks for your input. Here is the rule. Its currently the only rule I have active. Once activated, all devices in all other VLANs are cut from the internet.

 

This is the ONLY rule I have respectively this is the rule causing the issue. There is no other rule on either gateway, switch or EAP layer.

  0  
  0  
#3
Options
Re:Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT
2025-05-07 06:31:07

Hi  @Betonmischer 

 

Once activated, all devices in all other VLANs are cut from the internet.

>>> Does this mean, all clients in the network, no matter wired or wireless, no matter which VLAN will lose Internet?

How about the clients in the IoT VLAN?

 

One more thing I want to comfirm, will the clients in the VLANs get correct IP addresses as expected

  0  
  0  
#5
Options
Re:Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT
2025-05-09 06:53:51

  @Betonmischer 

 

I played around with similar rules last night and couldnt replicate, they worked as expected.  very strange.

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#6
Options
Re:Gateway ACL rule block internet for all VLANs instead of only for VLAN IoT
2025-05-18 06:36:55

Hello,

 

just wanted to provide an answer to how I proceeded: I decided to rework my entire network and more or less started from scratch again (it was also a bit "historically grown"). I am not sure what the true issue was, but now it is working as expected.

 

Thus: Issue resolved, but no clue what the root cause was. I did a total reset of all devices.

 

Best regards

  0  
  0  
#7
Options