NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
autoitaus
Dec 07, 2018Tutor
M5300 oneway VLAN Routing
I have two VLANs, VLAN 1 and VLAN 2
I want to allow computers in VLAN 1 to access the computers in VLAN 2
I DO NOT want computers in VLAN 2 to be able to access computers in VLAN 1
How ...
autoitaus
Jan 10, 2019Tutor
Sure - as above.
I want 192.168.1.1 to be able to access 192.168.19.1 but I DO NOT want 192.168.19.1 to access 192.168.1.1
DaneA
Jan 21, 2019NETGEAR Employee Retired
I also inquired your concern to the higher tier of NETGEAR Support and got a feedback today. As per the higher tier of NETGEAR Support, you can use extended ACL’s with TCP Flag. As reference guide, kindly read pages 222-236 of the M5300 user manual here on how to do this.
Regards,
DaneA
NETGEAR Community Team
- autoitausJan 22, 2019Tutor
Thanks for your persistence.
Step 5 on Page 224 says:
(Netgear Switch) (Config)#access-list 101 deny tcp any flag +syn -ack
Switch says:
(2920-Stack) (Config)#access-list 101 deny tcp any flag +syn -ack
^
% Invalid input detected at '^' marker.So, in other words, the manual has the incorrect syntax. Even if it did work, though, the next step binds to a Port, rather than a VLAN.
- autoitausJan 22, 2019TutorI managed to add this using the GUI and attached it to the VLAN in question however the PC on 192.168.19.1 can still access 192.168.1.1
- DaneAJan 23, 2019NETGEAR Employee Retired
Step 5 on Page 224 says:
(Netgear Switch) (Config)#access-list 101 deny tcp any flag +syn -ack
Switch says:
(2920-Stack) (Config)#access-list 101 deny tcp any flag +syn -ack
^
% Invalid input detected at '^' marker.So, in other words, the manual has the incorrect syntax. Even if it did work, though, the next step binds to a Port, rather than a VLAN.
Thank you for pointing this out. I will report this to the appropriate personnel to check on this.
I managed to add this using the GUI and attached it to the VLAN in question however the PC on 192.168.19.1 can still access 192.168.1.1
With regard to this, I do not have any suggestions as of now. I have already inquired your concern to the NETGEAR Support Team as well as with the higher tier of NETGEAR Support. I know that you do not have a support contract, however, you may want to consider having it for further investigation of your concern. This thread is still open for other community members to chime in and post their suggestions.
Regards,
DaneANETGEAR Community Team
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!