Why the Gateway web interface reveals the controller IP?

Why the Gateway web interface reveals the controller IP?

Why the Gateway web interface reveals the controller IP?
Why the Gateway web interface reveals the controller IP?
Yesterday - last edited 18 hours ago
Tags: #Controller #INFORMIP
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version:

gatewaySS

 

the Gateway when managed by controller is revealing the controller IP how to hide the controller IP or make it so only after login we can see the controller IP

  0      
  0      
#1
Options
1 Accepted Solution
Re:Why the Gateway web interface reveals the controller IP?-Solution
18 hours ago - last edited 18 hours ago

  @Yesrab 

Thank you for your post. When an Omada Gateway is currently managed by an Omada Controller, any attempt to log in to its standalone Web GUI will be rejected, and the page will display the IP address of the managing Controller. A Gateway under Controller management cannot be simultaneously administered through its own Web GUI. Regarding your suggestion to hide the Controller’s IP in this prompt, I will forward your feedback to the relevant team.

Recommended Solution
  0  
  0  
#3
Options
5 Reply
Re:Why the Gateway web interface reveals the controller IP?
23 hours ago - last edited 23 hours ago

  @Yesrab 

 

If you are accessing the gateway GUI on the default network (or management VLAN), the message is simply reminding you that you should be using the controller and is telling you where to find it.


If you are accessing the gateway GUI from another VLAN where you don’t want clients to have access to the GUI (or see the controller information), then there are several steps you can do to prevent that. The first is to create an ACL that prevents the undesired VLAN from accessing the controller subnet. That prevents the client from accessing the controller even if the client knows the controller’s IP address. Then you need to create another ACL to prevent the undesired VLAN from accessing the Gateway Management Page. That prevents the client from accessing the gateway GUI.


Note:  Only deny the TCP protocol in the Gateway Management Page ACL.  Some gateways will deny internet access to the VLAN if all protocols are selected.

 

1x ER706W 1x OC300 4x SG2008 1x EAP610 2x EAP650
  0  
  0  
#2
Options
Re:Why the Gateway web interface reveals the controller IP?-Solution
18 hours ago - last edited 18 hours ago

  @Yesrab 

Thank you for your post. When an Omada Gateway is currently managed by an Omada Controller, any attempt to log in to its standalone Web GUI will be rejected, and the page will display the IP address of the managing Controller. A Gateway under Controller management cannot be simultaneously administered through its own Web GUI. Regarding your suggestion to hide the Controller’s IP in this prompt, I will forward your feedback to the relevant team.

Recommended Solution
  0  
  0  
#3
Options
Re:Why the Gateway web interface reveals the controller IP?
14 hours ago

  @jra11500 

 

This is the way to prevent access to it

 

However, i think it would be better if the gateways acted like the switches do with a page like this - it doesnt even allow a login box, nor display the controller IP.  When the controller is disconnected, the switches then allow a login, which is fine.

 

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#4
Options
Re:Why the Gateway web interface reveals the controller IP?
13 hours ago
this looks better but in gateway u can login even if the controller is conneted to it, it just shows a page to reset it disabling the login screen is much better because gateway can be reset via the button too revealing the controller ip is not good imo
  0  
  0  
#5
Options
Re:Why the Gateway web interface reveals the controller IP?
13 hours ago - last edited 13 hours ago

  @Yesrab 

 

not quite - if the gateway is currently under control (as in, in a "connected state" in controller) - you can still log in to it but there are no options to do anything at all (not even factory reset).  Factory reset only shows up if the gateway is in a "disconnected" state.

 

Being able to log in but do nothing is absolutely pointless.

 

The switches handle it much better - no login at all if its properly connected.

Main: ER8411 x1, SG3428X x1, SG3452 x1, SG2428LP x1, SG3210 x1, SG2218P x1, SG2008P x3, ES208G x1, EAP650 x6 Remote: ER7206 v2 x1, ER605 v2 x3, SG2008P x2, EAP650 x2, ES205G x1 Controller: OC300
  0  
  0  
#6
Options