Orbi WiFi 7 RBE973
Reply

Re: Cannot access my IoT VLAN from Default VLAN

hajar1
Guide

Cannot access my IoT VLAN from Default VLAN

I have all my IoT devices connected to IoT VLAN. I have all my computers and phones connected to Default VLAN. This separation is for security obviously as recommended. I have Network Isolation turned on for IoT VLAN so that devices on IoT VLAN couldn't access any devices outside that VLAN. And Default VLAN comes with Network Isolation disables, which in theory should allow it to connect to all IoT devices. However, this doesn't happen. I cannot access any of my IoT VLAN devices, unless I disable Network Isolation on IoT VLAN. But as soon as I do that all Default VLAN devices become immediately visible from any IoT VLAN Device.

 

What am I doing wrong? Or how can I achieve the obvious security that I'd like to achieve without making it impossible to access any IoT devices from the non-IoT network?

Message 1 of 14
hajar1
Guide

Re: Cannot access my IoT VLAN from Default VLAN

Anyone any ideas or suggestions?

Message 2 of 14
schumaku
Guru

Re: Cannot access my IoT VLAN from Default VLAN

@BruceGuo please

Message 3 of 14
ErwinL
NETGEAR Moderator

Re: Cannot access my IoT VLAN from Default VLAN

Hello@hajar1 

And welcome to the NETGEAR Community! 🙂

 

In my perspective you are not doing anything wrong, the rule for Network Isolation is just implementing it's job. To clarify what is happening is that. If you can recall as you have mentioned, there should be no IoT devices be able to get out from it's VLAN. Now what is happening when you try to access them from your non IoT devices they would not respond as it's being blocked by the rule that nobody should be able to get out from it's VLAN. That is also why when you remove the Network Isolation everything will work fine. I believe only through access control list that you will be able to achieve your requirement. Please check page 59 to 63 from the link below to be guided about ACL:

 

https://www.downloads.netgear.com/files/GDC/SXK50/SXK50_UM_EN.pdf

 

Have a lovely day,
Erwin
Netgear Team

Message 4 of 14
hajar1
Guide

Re: Cannot access my IoT VLAN from Default VLAN

Thank you, Erwin. So does Netgear then have those access rules or other mechanism to achieve what I want?

 

The way other routers isolate IoT Vlan is that you can access devices from outside of IoT VLan, but IoT Vlan devices cannot access any devices outside of the IoT Vlan. This is very simply achieved with a couple of Firewall rules.

 

This type of isolation where IoT Vlan devices become completely inaccessible locally and are only accesible via Cloud is super inconvenient. Basically, I end up maintaining Wifi to IoT Vlan and Ethernet to Default VLan constantly completely defeating the point of IoT Vlan isolation as anyway have to be permanently exposed to it.

 

Any suggestions how to fix this annoyance and inconvenient lack of firewall in such an expensive Pro device?

 

Message 5 of 14
hajar1
Guide

Re: Cannot access my IoT VLAN from Default VLAN

Anyone any suggestions?

Message 6 of 14
ErwinL
NETGEAR Moderator

Re: Cannot access my IoT VLAN from Default VLAN

@hajar1

 

Were you able to check the manual I have provided? I believe it was mentioned there how you can allow or block devices from accessing the network using access list. 

 

Have a lovely day,

Erwin

Netgear Team

Message 7 of 14
hajar1
Guide

Re: Cannot access my IoT VLAN from Default VLAN

Yes I have and all it says that its either all blocked or all accessible. According to the manual there is no way to have Default VLAN access IoT VLAN but not vice versa. So it doesn’t solve my issue. So I am still looking for clever workarounds if anyone was able to find?
Message 8 of 14
ErwinL
NETGEAR Moderator

Re: Cannot access my IoT VLAN from Default VLAN

@hajar1

 

I see. If that will not work for your requirement. You might want to try putting a switch in between your router and devices that has access list feature like GS110TPv3. Try checking the documentation all about ACL on page 354 to 385 from the link below

 

https://www.downloads.netgear.com/files/GDC/GS108Tv3/GS108Tv3_GS110TPv3_GS110TPP_UM_EN.pdf

 

Have a lovely day,

Erwin

Netgear Team

Message 9 of 14
ErwinL
NETGEAR Moderator

Re: Cannot access my IoT VLAN from Default VLAN

Hello@hajar1 

 

Did you solve your problem? In this case could you give us a feedback on the situation and accept the post as a solution to make it more visible to other users?

 

Thanks in advance! 🙂

 

Have a lovely day,
Erwin
Netgear Team

Message 10 of 14
hajar1
Guide

Re: Cannot access my IoT VLAN from Default VLAN

@ErwinL I would solve my problem if I could achieve what I am trying to - be able to connect to any of my IoT device on IoT VLAN without having a security issue of any of my IoT devices being able to connect to my computers and phones on Default VLAN.

 

This is an absolute common sense need and way to isolate IoT devices. This is a standard in feature in most linux powered routers, like Ubiquiti and for no comprehensible reason absolutely impossible on Orbi Pro routers.

 

So did I solve my problem? Absolutely not.

Did I get clear that Orbi Pro routers are incapable of achieving what I need? Yes.

Message 11 of 14
ErwinL
NETGEAR Moderator

Re: Cannot access my IoT VLAN from Default VLAN

@hajar1,

 

I would like to apologize if the solution I have provided did not meet your requirements. If you think that this is a feature that is lacking for this device we are open for suggestions. Just visit the link below and find your way on suggesting your concern. Can we set this thread to closed now?

 

https://community.netgear.com/t5/Idea-Exchange-For-Business/idb-p/idea-exchange-for-business

 

Have a lovely day,

Erwin

NETGEAR Team

 

Message 12 of 14
hajar1
Guide

Re: Cannot access my IoT VLAN from Default VLAN

I posted feature request here should anyone else encounter this limitation and want to vote it up:
https://community.netgear.com/t5/Idea-Exchange-For-Business/Enable-one-way-connectivity-from-one-VLA...

Message 13 of 14
ErwinL
NETGEAR Moderator

Re: Cannot access my IoT VLAN from Default VLAN

Hello@hajar1

 

Thanks for requesting a feature. I do hope your feature request will be added to the device. With that, have I addressed your concern? In this case could you give us feedback on the situation and accept my post as a solution to make it more visible to other users?

 

Thanks in advance!

Have lovely day,
Erwin
Netgear Team

Message 14 of 14
Top Contributors
Discussion stats
  • 13 replies
  • 2717 views
  • 0 kudos
  • 3 in conversation
Announcements