1
Votes

ER706W Gateway ACL, LAN->LAN, IP-Port

 
1
Votes

ER706W Gateway ACL, LAN->LAN, IP-Port

15 Reply
Re:ER706W Gateway ACL, LAN->LAN, IP-Port
2025-06-14 18:46:20

  @Pink_Waters 

 

If you arent using the switch interfaces as the gateway for the vlans, then you are not switch routing.

 

Yes, you are correct taht switches need an interface to DHCP relay for any given vlan, but if that interface IP isnt set as the clients gateway (and the router IP for that vlan is) then the swith wont get involved with any routing at all - it will still all be done directly on the gateway, and then the hybrid gateway+switch rules will still work

 

Switches will only route if the SVI is the actual gateway for any given vlan.  

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
#12
Options
Re:ER706W Gateway ACL, LAN->LAN, IP-Port
2025-06-14 20:46:52 - last edited 2025-06-14 21:16:44

  @GRL 

Ok so yes basically, if i have a vlan interface with x.x.x.2 enabled then then I am switch routing if i am using x.x.x.2 as gateway on the client. Am I understanding you correctly ?

#13
Options
Re:ER706W Gateway ACL, LAN->LAN, IP-Port
2025-06-14 23:26:29

  @Pink_Waters 

 

yes!  if the switch IP per vlan is NOT the clients gateway (as set by dhcp or static) then the router will be the first hop for that clients traffic (ie, its gateway) and then the router takes precedence, the switch simply exists as a device on that vlan as far as anything else is concerned.

 

DHCP relay will still take effect though as that works independandy of gateway or routing functions on the switch.

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
#14
Options
Re:ER706W Gateway ACL, LAN->LAN, IP-Port
2025-06-15 01:49:52

  @GRL 

Yeah that sounds good, but unfortunately it comes at a cost of bandwidth as you know which I am not too worried about for now. the other thing I would like to pick your brain with, I have been trying to see if i can make a bi-directional group like your example, but instead of being an IP group, how can you incorporate an ip-port group for same result of one way ACL while preserving return ?

#15
Options
Re:ER706W Gateway ACL, LAN->LAN, IP-Port
2025-06-16 01:13:54

  @Pink_Waters 

Pink_Waters wrote

  @Clive_A 

If the dev team is aware of the request, why the feature request was closed ? and why there are no updates about this?

A thread can be closed by the mod, poster, or after 6 months of no activity. I did not close it. 

 

The forum team does not provide information in reply about the development progress or details. 
Neither do we provide the estimated time for this feature, nor details and explanations for the roadmap. 

As this is an ongoing request and was previously replied to, your request is already known to the dev team.
Please refer to the final firmware release notes for this feature. 
Thanks for your understanding. 

#16
Options