Problem with MAC binding to VLAN

dominikpl
dominikpl Posts: 1
edited February 2024 in Security

On ZyXel USG FLEX I want to create some VLAN which each have own clients binding by MAC address.

The VLAN will have specific private policy, etc.

I tried to find any answer, but I can't find it.

Actually, I have LAN2 on P6 and P7.

IP Adress: 192.168.2.1

Subnet Mask: 255.255.255.0

DHCP

IP Pool Start Adress: 192.168.2.111 Pool Size 5

VLAN

Interface: internal

ZONE: LAN2

Base Port: lan2

VLAN ID 21

IP Adress Assignment

IP Adress: 192.168.21.1

Subnet Mask: 255.255.255.0

DHCP

IP Pool Start Adress: 192.168.21.100 Pool Size 10

STATIC DHCP Table

IP Adress 192.168.21.10, correct MAC and description PC_2.

And checked checkbox Enable IP/MAC Binding and DHCP Enforcement

When I plugin the PC_2 it gets an IP address 192.168.2.111, why not 192.168.21.10? What I made wrong?

All Replies

  • PeterUK
    PeterUK Posts: 3,503  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    You need a VLAN switch or if you connect PC to FLEX directly set PC NIC to VLAN21

  • Zyxel_Kevin
    Zyxel_Kevin Posts: 897  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 500 Comments

    Hi @dominikpl ,

    Greeting Forum, Your switch port where connected to Friewall need to act as Trunk port and allowed VLAN21.

    Then other switch port where connected to End Device act as Access port within VID 21.

    Thanks