OC200 and ER8411 vlan to device ACL
Hi there.
I have an Omada setup with an OC200 with a ER8411 as the gateway.
Sorry if this has been covered before, I'm guessing it may have been, but I'm trying to get my IoT vlan to communicate with a single device on my main vlan.
I have set up and ACL to deny all traffic from the IoT vlan, and above this rule I've added an ACL to allow IoT to traffic to access a single device (Home assistant NUC), via an IPGroup (192.xx.xx.xx/32) which sits in my main vlan. The only way I can do this is to use a LAN->WAN rule, which I'm guessing isn't correct as it doesn't seem to work.
When trying to create a LAN->LAN rule, I am unable to select IP Group as the destination, and so can't specify what the IoT vlan can access at a single ip level.
I should note, that I am unable to ping anything on my main vlan from the IoT, and when I disable the "deny all" ACL it allow pings, so the ACLs are working, just not the specific one to allow IoT access to one device on the main vlan.
Am I missing something obvious here? Surely there's a way to only allow access from a vlan to one specific device on a different vlan?
Many thanks
gary