NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
mike1110
Jul 22, 2026Tutor
Inter VLAN Traffic open between Multi-PSK SSID Connected VLANS - BUG
Hello,
I run a PR60X via Insight, and have five vlans. My Core Switch is the MS510TXUP and intervlan routing as far as I am aware is done on the PR60X. When I log on directly to the MS510TXUP, its disabled.
The Router Traffic Rules are quite limited, no feature to create IP/Network Groups, or select Interface Groups (LAN/VLAN) and in general, the featureset is quite disappointing (Yes, no IPv6 support, no Snort, no affordable Exium support for private/insight premium users, etc. Way to go, Netgear!)
That rant had to be :-)
I run five vlans with Class B Nets:
10.10.0.0/16
10.20.0.0/16
10.30.0.0/16
...
I run three SSID:
1: home -> connected to VLAN10
2: iot -> Multi-PSK connected to VLAN20, 30, 40
3: Guest -> connected to VLAN50
When I do a network sweep from the Multi-PSK Networks, every thing is open. I added a few allow lists in the Traffic Rules, but nevertheless, all is wide open, and no implicit DENY rule is applied.
When I run a sweep from the Guest net, it seems there is an implicit DENY rule active.
So the only difference is the Multi-PSK Network. This in my opinion is a dangerous and buggy approach to handle different SSID Types differently.
The interesting thing is, all vlans are open, not only the three Multi-PSK connected VLANS.
So where is this behavior documented, or is it at all?
Anyway, should we find a way to have a simple solution for explicit catch-all DENY rules for inter-vlan traffic?
How would we do that? Blocking the A-Net space (10.0.0.0/8) leaves the Router offline because the Rules block all VLAN Interfaces too.
So do we need 5x5 Rules to explicitly block the ip subnets of each vlan from each vlan? Because just use Source Interface: VLANXX, Source IP Any, Destination Interface ANY, Destination IP ANY seems to block any Interface, so the router goes offline even when there is an explicit Allow rule beforehand.
Help and Info much appreciated
Thanks,
Michael
1 Reply
- schumakuGuru - Experienced User
Hi Michael,
mike1110 wrote:
When I do a network sweep from the Multi-PSK Networks, every thing is open.
The router can't make a difference between SSID types - simply does know about.
mike1110 wrote:
: iot -> Multi-PSK connected to VLAN20, 30, 40
The same ssid (it's say "iot" here?) is supposed to connect just to one network, so one VLAN only.
This design "stinks" a little bit to me, sorry sayin'... I don't wonder that the devices on VLAN20, 30, and 40 will see each other.
In my logic and understanding - working with many major Wi-Fi infrastructure brands and vendor implementations - a single SSID can (and should from the audit prospective) connect to a single VLAN only.
And yes, I'm a little bit buffed on where and how you configured the iot SSID associated to three different VLANs.
-Kurt
PS. Just yet another active community member, not a NTGR rep.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!