Problem with MAC binding to VLAN

Options
dominikpl
dominikpl Posts: 1
edited February 19 in Security

On ZyXel USG FLEX I want to create some VLAN which each have own clients binding by MAC address.

The VLAN will have specific private policy, etc.

I tried to find any answer, but I can't find it.

Actually, I have LAN2 on P6 and P7.

IP Adress: 192.168.2.1

Subnet Mask: 255.255.255.0

DHCP

IP Pool Start Adress: 192.168.2.111 Pool Size 5

VLAN

Interface: internal

ZONE: LAN2

Base Port: lan2

VLAN ID 21

IP Adress Assignment

IP Adress: 192.168.21.1

Subnet Mask: 255.255.255.0

DHCP

IP Pool Start Adress: 192.168.21.100 Pool Size 10

STATIC DHCP Table

IP Adress 192.168.21.10, correct MAC and description PC_2.

And checked checkbox Enable IP/MAC Binding and DHCP Enforcement

When I plugin the PC_2 it gets an IP address 192.168.2.111, why not 192.168.21.10? What I made wrong?

All Replies

  • PeterUK
    PeterUK Posts: 2,796  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    You need a VLAN switch or if you connect PC to FLEX directly set PC NIC to VLAN21

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 771  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @dominikpl ,

    Greeting Forum, Your switch port where connected to Friewall need to act as Trunk port and allowed VLAN21.

    Then other switch port where connected to End Device act as Access port within VID 21.

    Thanks

Security Highlight