How to allow the clients which are isolated by ACL to access the printer in same VLAN?
Options
Zyxel_Melen
Posts: 1,673 Zyxel Employee
Scenario:
Since port isolation cannot isolate clients in different switches, users can use ACL to restrict the connection between each client. However, it causes clients not to access the server or printer in the same subnet. This FAQ will guide you on how to allow the clients to access the server or printer in the same subnet.
Topology:
Configuration:
Please navigate to Site-wide > Configure > Switches > ACL to set up the rules.
- Setup the rule to allow your DHCP server can provide DHCP IP address. Rule 1 in below is the example. You can change the source IP address as your DHCP server’s and the other columns are the same.
- Setup the rule to allow clients to access the Internet. Rule 2 & 3 in below are the examples. You can change the subnet if your subnet is not 192.168.1.x. And you must change the MAC address to your firewall’s with mask FF:FF:FF:FF:FF:00.
- Set up the rule to allow clients to access the printer. Rule 4 & 5 below are the examples. In many cases, the printer is set with a static IP address. If your printer has a static IP address, you should also fix the MAC address instead of any to prevent IP spoofing.
- Setup the deny rule to deny other traffics. Rule 6 in below is the example. You can change the subnet if your subnet is not 192.168.1.x.
Verification:
The results are below. The PC can ping to the Internet, the firewall, and the printer. But it cannot ping to other devices.
Zyxel Melen
0
Categories
- All Categories
- 396 Beta Program
- 2.1K Nebula
- 117 Nebula Ideas
- 81 Nebula Status and Incidents
- 5.1K Security
- 86 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 69 Switch Ideas
- 915 WirelessLAN
- 34 WLAN Ideas
- 5.9K Consumer Product
- 211 Service & License
- 337 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2K FAQ
- 912 Nebula FAQ
- 419 Security FAQ
- 237 Switch FAQ
- 207 WirelessLAN FAQ
- 46 Consumer Product FAQ
- 139 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 72 About Community
- 62 Security Highlight