[BUG/Issue] EAP ACL not functioning between wireless connections on the same EAP. (653, 650, 225)

[BUG/Issue] EAP ACL not functioning between wireless connections on the same EAP. (653, 650, 225)

21 Reply
Re:[BUG/Issue] EAP ACL not functioning between wireless connections on the same EAP. (653, 650, 225)
2024-08-29 21:17:08 - last edited 2024-08-29 21:19:42

Running into the same problem. Doesn't sound like there is any intent to update this 'feature'?

 

I'm setting up a network with PPSK for a marina with a mix of permanent users who are living on site and regular day users (slip holders with smaller boats without living quarters). I will have only one SSID, but several passwords getting clients to their appropriate VLAN. One of those VLANs will be intended for the general use and day guests, who don't need their own indivudual VLAN. This will use a simple shared password posted locally to avoid using an open portal login and the issues that brings. I don't want to consider transmitting multiple SSIDs for multiple reasons, mainly simplicity, but also due to the airspace being very crowded already, so I don't want to add any more SSID's than neccessary. For this VLAN, due to this EAP ACL issue, I am unable to replicate a true guest network behavior and am compromising security for those clients. Since I'm using a single SSID with PPSK it seems overly complicated, but maybe not impossible, to use ACLs to work backwards into this functionality from a base guest network, as I'll have 30+ VLANs, most with interLAN traffic permitted.

 

Is there any guarantee from TP-Link that usign ACLs to selectively permit access around a guest network will always be allowed and not altered in future firmware updates? If so it sounds like it may be worth trying to work backwards from a default guest network.

 

It sounds like there may be options in the Switch/EAP settings outside of controller mode to help address this, but this is going to be a decent sized system with multiple outdoor switches (SG2005P-PD) feeding multiple EAPs so dropping out of controller mode is not an option. Any plans to integrate those settings into controller mode?

  1  
  1  
#22
Options