vlan segregation with only dns allowed.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

vlan segregation with only dns allowed.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
vlan segregation with only dns allowed.
vlan segregation with only dns allowed.
2025-05-05 21:58:34 - last edited 2025-05-06 04:03:05
Model: ES205GP  
Hardware Version: V1
Firmware Version: 1.01

I have two vlans 1 and 10 where I would like to have 10 only able to access the dns servers on vlan 1.  I am unable to get the deny to work let alone the allow.  Here are the screenshots of some of my setup in my lab.  

  0      
  0      
#1
Options
1 Accepted Solution
Re:vlan segregation with only dns allowed. -Solution
2025-05-06 03:18:52 - last edited 2025-05-06 04:03:05

Hi @mushand 

Thanks for posting in our business forum.

This is not possible on this switch.

What you need is stateful ACL and VLAN interface.

Recommended Solution
  1  
  1  
#2
Options
9 Reply
Re:vlan segregation with only dns allowed. -Solution
2025-05-06 03:18:52 - last edited 2025-05-06 04:03:05

Hi @mushand 

Thanks for posting in our business forum.

This is not possible on this switch.

What you need is stateful ACL and VLAN interface.

Recommended Solution
  1  
  1  
#2
Options
Re:vlan segregation with only dns allowed.
2025-05-06 14:02:27

  @Clive_A 

Any Switches that will support this?

  0  
  0  
#3
Options
Re:vlan segregation with only dns allowed.
2025-05-07 01:01:48

Hi @mushand

mushand wrote

  @Clive_A 

Any Switches that will support this?

This has nothing to do with the switch. 

You need a router that supports VLAN interface. And stateful ACL.

  0  
  0  
#4
Options
Re:vlan segregation with only dns allowed.
2025-05-07 01:06:03

  @Clive_A 

I have ER605 gateway.  

  0  
  0  
#5
Options
Re:vlan segregation with only dns allowed.
2025-05-07 01:15:44
  0  
  0  
#6
Options
Re:vlan segregation with only dns allowed.
2025-05-07 02:32:13

  @Clive_A 

work the correct switch and this gateway filling these directions I will be able to do what I am setting out to do

  0  
  0  
#7
Options
Re:vlan segregation with only dns allowed.
2025-05-07 11:42:54

  @mushand @Clive_A sorry that didn't type out well.  With the correct switch and this gateway I can accomplish this.  

  0  
  0  
#8
Options
Re:vlan segregation with only dns allowed.
2025-05-08 01:04:17

Hi @mushand 

mushand wrote

  @mushand @Clive_A sorry that didn't type out well.  With the correct switch and this gateway I can accomplish this.  

Is this a question or a declarative sentence?

Not sure I understand you correctly.

 

DNS is a UDP protocol, which you can use a granular ACL to filter out.

VLAN segregation is based on the ACL.

Then you create another rule to allow DNS.

  0  
  0  
#9
Options
Re:vlan segregation with only dns allowed.
2025-05-08 01:16:22

@Clive_A 

That is a question.  If I have ES210GMP switch I can have a Vlan for 1 and vlan 10 where only traffic to vlan 1 from vlan 10 is dns traffic.  

  0  
  0  
#10
Options