NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Retired_Member's avatar
Retired_Member
Sep 02, 2021

Cannot apply IP filtering with subnet mask on VLAN

Dear all,

 

When I want to configure my Insight managed switch such that devices on certain VLAN's cannot reach certain IP's, a direct declaration of an IP address in the IP filtering section works:

If the image above doesn't work: Imgur version

In the situation above a device connected to the VLAN cannot access 192.168.1.1, but can access the other devices on the subnet.

However when I want to block the device in question along with all devices on the subnet, using the subnet mask 255.255.255.0, it doesn't work:

If the image above doesn't work: Imgur version

In the situation above a device connected to the VLAN can still access any device on the 192.168.1.x subnet.

Is this a bug or am I doing something wrong? Thanks in advance.

 

Footnote: I don't know if the problem regarding the images being yellow triangles is unique to me, or another bug. I've linked to Imgur below the images, I was prohibited from inserting the images in the HTML for some reason.

6 Replies

  • DaneA's avatar
    DaneA
    NETGEAR Employee Retired

    Retired_Member,

     

    Welcome to the community! :) 

     

    The Policy you have specified is "Allow" which is why the devices on the 192.168.1.0 range are allowed.  Kindly try to change the Policy to "Deny."

     

    As reference guide, kindly access and read the article below: 

     

    How do I set up IP address filtering for an existing VLAN in Insight?

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

    • Retired_Member's avatar
      Retired_Member

      DaneA,

       

      Thanks for the reply, I don't know why it says 'Allow' in the UI but it is in fact in the policy 'Deny', when I edit an entry in the 'Deny' policy it always shows 'Allow' for unknown reasons. Denying access without defining a subnet mask works, only when defining a subnet mask I encounter this problem.

      • MrJoshW's avatar
        MrJoshW
        NETGEAR Expert

        Hello,

         

        See screenshots:

         

        Logging into my Insight account and going to the VLAN > IP Filtering. I do see the deny policy as it is a drop down. After delecting deny, and selecting manual. I can add a deny policy. 

         

        Even when you select the deny policy, and select manual, do you see the policy screen for deny or allow?

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More