Er605 mac filtering dont work on 2.3.0 firmware

Hi, in standalone mode Firewall-mac filtering-allow only listed below and deny the rest dont work.
I have 30+ mac adresses in list, but every Not listed device can connect to whole network, successfully get dhcp and see all devices.
no dhcp server rejections in syslog
it worked in 2.2.6
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Took usb ethernet adapter that not in list - connected but no internet
Took phone with randomized mac - connected but no internet
- Copy Link
- Report Inappropriate Content
Thank you for your post. Could you please describe your current network topology?
Are all these devices connected directly behind the router, or is there a managed switch in between? If a switch is present, what settings have been applied on it? Is the ER605 router the only DHCP server in the entire network? Besides the Allow rule that isn’t working, have you tested whether Deny rules function correctly? Additionally, please reduce the MAC list to just one or two addresses for testing. This will help us determine whether the issue is caused by an incorrect or duplicate MAC address among the 30 entries. Finally, double-check that the MAC list contains no invalid or duplicate addresses.
- Copy Link
- Report Inappropriate Content
Hi, thanks for reply. I have 4 vlans, one managed switch, two routers and one EAP but it doesn't matter because
just now i connected simplified schema:
ER605
port3- EAP 653wifi (no dhcp server)
port4 lan cable pc connected
1.added my mobile to deny list and reboot AP it obtain dhcp ip from er605 and can wifi-device scan\xplore smb see\access all devices connected to this AP and this vlan, but has no access to other vlans and not bacuse of ACL rules! the only thing this mac filtering do - is block mac through vlans.
(previous 2.2.6 firmware deny mac couldn't connect and get IP adress, i've tested it before use)
changing direction ALL to LAN-WAN did no change. looks it always on LAN-WAN only..
pinging er605 timed out, no response.
2. connected pc direct to er605 port. no internet but can access smb shares and devices in its vlan. no access to othervlan.
pinging er605 timed out, no response.
changing direction ALL to LAN-WAN did no change. looks it always on LAN-WAN only..
- Copy Link
- Report Inappropriate Content
Yes, switching direction make no change.
I'm 100% sure it always stuck on LAN-WAN only and ALL setting just not work after update to 2.3.0.
- Copy Link
- Report Inappropriate Content
Based on tests from both PC and mobile phone, devices on the same LAN segment can ping each other successfully, but cross-segment pings fail and traffic toward the WAN is blocked. This appears to be the expected behavior.
- Copy Link
- Report Inappropriate Content
@Ethan-TP mac filtering must block unknown devices connect to router. it worked on every previous firmware.
but 2.3.0 allow devices to connect with every random mac.
you say this is expected behavior?
- Copy Link
- Report Inappropriate Content
UP
- Copy Link
- Report Inappropriate Content

Information
Helpful: 0
Views: 413
Replies: 7
Voters 0
No one has voted for it yet.