Er605 mac filtering dont work on 2.3.0 firmware

Er605 mac filtering dont work on 2.3.0 firmware

Er605 mac filtering dont work on 2.3.0 firmware
Er605 mac filtering dont work on 2.3.0 firmware
a week ago - last edited a week ago
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0

Hi, in standalone mode Firewall-mac filtering-allow only listed below and deny the rest dont work.

I have 30+ mac adresses in list, but every Not listed device can connect to whole network, successfully get dhcp and see all devices.

 

no dhcp server rejections in syslog

 

it worked in 2.2.6

  0      
  0      
#1
Options
7 Reply
Re:Er605 mac filtering dont work on 2.3.0 firmware
a week ago

Took usb ethernet adapter that not in list - connected but no internet

Took phone with randomized mac - connected but no internet

 

  0  
  0  
#2
Options
Re:Er605 mac filtering dont work on 2.3.0 firmware
a week ago

  @YuriyB 

Thank you for your post. Could you please describe your current network topology?
Are all these devices connected directly behind the router, or is there a managed switch in between? If a switch is present, what settings have been applied on it? Is the ER605 router the only DHCP server in the entire network? Besides the Allow rule that isn’t working, have you tested whether Deny rules function correctly? Additionally, please reduce the MAC list to just one or two addresses for testing. This will help us determine whether the issue is caused by an incorrect or duplicate MAC address among the 30 entries. Finally, double-check that the MAC list contains no invalid or duplicate addresses.

  0  
  0  
#3
Options
Re:Er605 mac filtering dont work on 2.3.0 firmware
a week ago - last edited a week ago

 Hi, thanks for reply. I have 4 vlans, one managed switch, two routers and one EAP but it doesn't matter because

just now i connected simplified schema:

 

ER605

port3- EAP 653wifi (no dhcp server)

port4 lan cable pc connected

 

1.added my mobile to deny list and reboot AP it obtain dhcp ip from er605 and can  wifi-device scan\xplore smb see\access all devices  connected to this AP and this vlan, but has no access to other vlans and not bacuse of ACL rules! the only thing this mac filtering do - is block mac through vlans.

 (previous 2.2.6 firmware deny mac couldn't connect and get IP adress, i've tested it before use)

changing direction ALL to LAN-WAN did no change. looks it always on LAN-WAN only..

pinging er605 timed out, no response.

 

 

2. connected pc direct to er605 port. no internet but can access smb shares and devices in its vlan. no access to othervlan.

pinging er605 timed out, no response.

changing direction ALL to LAN-WAN did no change. looks it always on LAN-WAN only..

 

  0  
  0  
#4
Options
Re:Er605 mac filtering dont work on 2.3.0 firmware
a week ago

Yes, switching direction make no change.

I'm 100% sure it always stuck on LAN-WAN only and ALL setting just not work after update to 2.3.0.

 

  0  
  0  
#5
Options
Re:Er605 mac filtering dont work on 2.3.0 firmware
Tuesday

  @YuriyB 

Based on tests from both PC and mobile phone, devices on the same LAN segment can ping each other successfully, but cross-segment pings fail and traffic toward the WAN is blocked. This appears to be the expected behavior.

  0  
  0  
#6
Options
Re:Er605 mac filtering dont work on 2.3.0 firmware
Tuesday

  @Ethan-TP mac filtering must block unknown devices connect to router. it worked on every previous firmware. 

but  2.3.0 allow devices to connect with every random mac.

you say this is expected behavior?

  0  
  0  
#7
Options
Re:Er605 mac filtering dont work on 2.3.0 firmware
6 hours ago

UP

  0  
  0  
#8
Options