NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Retired_Member
Sep 02, 2021Cannot apply IP filtering with subnet mask on VLAN
Dear all,
When I want to configure my Insight managed switch such that devices on certain VLAN's cannot reach certain IP's, a direct declaration of an IP address in the IP filtering section works:
If the image above doesn't work: Imgur version
In the situation above a device connected to the VLAN cannot access 192.168.1.1, but can access the other devices on the subnet.
However when I want to block the device in question along with all devices on the subnet, using the subnet mask 255.255.255.0, it doesn't work:
If the image above doesn't work: Imgur version
In the situation above a device connected to the VLAN can still access any device on the 192.168.1.x subnet.
Is this a bug or am I doing something wrong? Thanks in advance.
Footnote: I don't know if the problem regarding the images being yellow triangles is unique to me, or another bug. I've linked to Imgur below the images, I was prohibited from inserting the images in the HTML for some reason.
6 Replies
- DaneANETGEAR Employee Retired
Retired_Member,
Welcome to the community! :)
The Policy you have specified is "Allow" which is why the devices on the 192.168.1.0 range are allowed. Kindly try to change the Policy to "Deny."
As reference guide, kindly access and read the article below:
How do I set up IP address filtering for an existing VLAN in Insight?
Regards,
DaneA
NETGEAR Community Team
- Retired_Member
Thanks for the reply, I don't know why it says 'Allow' in the UI but it is in fact in the policy 'Deny', when I edit an entry in the 'Deny' policy it always shows 'Allow' for unknown reasons. Denying access without defining a subnet mask works, only when defining a subnet mask I encounter this problem.
- MrJoshWNETGEAR Expert
Hello,
See screenshots:
Logging into my Insight account and going to the VLAN > IP Filtering. I do see the deny policy as it is a drop down. After delecting deny, and selecting manual. I can add a deny policy.
Even when you select the deny policy, and select manual, do you see the policy screen for deny or allow?
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!