How to use ACL to isolate the clients in the same VLAN but connect to different switches?
Options
![Zyxel_Melen](https://us.v-cdn.net/6029482/uploads/defaultavatar/nN4PAQRO7TCNP.jpg)
Zyxel_Melen
Posts: 1,934
Zyxel Employee
![](https://us.v-cdn.net/6029482/uploads/userpics/FN0BI9T10CTX/n6O940IZ5DEW6.png)
![First Anniversary](https://us.v-cdn.net/6029482/uploads/badges/SJKCAIG91R5S.png)
![10 Comments](https://us.v-cdn.net/6029482/uploads/badges/818CA6MI9BTU.png)
![Friend Collector](https://us.v-cdn.net/6029482/uploads/badges/HNJASEUSC535.png)
![First Answer](https://us.v-cdn.net/6029482/uploads/badges/OV6XOPPO8V59.png)
Scenario:
A user might have many switches in one site and want to isolate the clients in a specific VLAN that connects to different switches. Since port isolation cannot fulfill this requirement, users can use ACL to restrict.
This FAQ is going to guide you on how to set the ACL.
Topology:
Configuration:
Please navigate to Site-wide > Configure > Switches > ACL to set up the rules.
- Set up the rule to allow your DHCP server to provide a DHCP IP address. Rule 1 below is the example. You can change the source IP address to your DHCP server’s IP address and the other columns are the same.
- Set up the rule to allow the clients to access the Internet. Rule 2 & 3 below are the examples. You can change the subnet if your subnet is not 192.168.1.x. You must change the MAC address to your firewall's MAC address with mask FF:FF:FF:FF:FF:00.
- Set up the deny rule to deny other traffic. Rule 4 below is the example. You can change the subnet if your subnet is not 192.168.1.x.
Verify:
The results are below. I can ping to the Internet and the firewall, but cannot ping to other devices.
0
Categories
- All Categories
- 413 Beta Program
- 2.3K Nebula
- 192 Nebula Ideas
- 87 Nebula Status and Incidents
- 5.3K Security
- 142 USG FLEX H Series
- 253 Security Ideas
- 1.3K Switch
- 75 Switch Ideas
- 993 Wireless
- 51 Wireless Ideas
- 6.1K Consumer Product
- 231 Service & License
- 362 News and Release
- 74 Security Advisories
- 23 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 101 About Community
- 67 Security Highlight