ACLs for network segmentation sometimes inactive
Hello,
I have a question about network segmentation and wanted to find out if other users have also noticed this behavior.
I use the ER605 V2.2 in controller mode, so the configuration is carried out by an OC200.
I have created several VLANs (interfaces) and would like to separate them.
I create a total of 4 LAN > LAN ACLs, one for each VLAN. It is a DENY rule from one source VLAN to all other destination VLANs.
I run a test ping from a device on one VLAN to a device on another VLAN.
The ping is basically possible and remains possible even after the deny rules have been applied until I reboot the gateway or terminate the connection myself for a longer period of time.
After the reboot, the segmentation works as desired. If I then adjust the rules and change any ACL, the update is transmitted to the gateway and at that moment the ping goes through and the connection remains open again. Could it be that the rules are temporarily inactive when changes are applied?
Best Regards!