VLAN on ER605 do not isolate networks

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

VLAN on ER605 do not isolate networks

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
VLAN on ER605 do not isolate networks
VLAN on ER605 do not isolate networks
2023-05-03 10:31:43
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: V2-2.1.2

Hello,

(First, sorry for my english, isn't my language)


On my ER605 (firmware update), i create 2 VLAN, but communication between PC in different vlan is always possible (after reboot and configuration verified)

 

Details :

- LAN : 

(Id1) Lan2 - Vlan 2 - 192.168.2.1 - DHCP server enable (DHCP relay disable)

(id2) Lan3 - Vlan 3 - 192.168.3.1 - DHCP server enable (DHCP relay disable)

 

- VLAN : 

(id1) Vlan ID 2 : vlan2 - Port 2 (Untag)

(id2) Vlan ID 3 : vlan3 - Port 3 (Untag)

(vlan 4094 - Wan - port 1)

 

The problem : Normally, Vlan allow to separate networks, no ?

=> I plug a PC on port 2 : IP 192.168.2.100 (it's ok)

=> I plug a PC on port 3 : IP 192.168.3.101 (it's ok)

On PC on port 2 (PVid2 - Vlan 2 untag - IP 192.168.2.100), i do a ping to 192.168.3.101 (Port 3, PVid3, vlan 3 untag)... i have respons !!!
Vlan 2 et 3 are NOT separate !

 

Then, whats the problem ? Why vlan 2 and 3 can communicate ?

 

  0      
  0      
#1
Options
1 Reply
Re:VLAN on ER605 do not isolate networks
2023-05-05 09:54:39

  @Steph-TA 

 

VLAN Interface can communicate with each other by default, you need to set ACL to separate them.

Check this.

Just striving to develop myself while helping others.
  1  
  1  
#2
Options