How to Configure ACL for Inter-VLAN Traffic Control on XGS4600?
Options
Zyxel_Lucious
Posts: 306
Zyxel Employee
Zyxel Employee
```html
To achieve the stated ACL requirements on the XGS4600 for inter-VLAN traffic, follow the steps below:
- Allow communication from VLAN 105 to VLAN 108:
No specific configuration is needed for this step because the traffic is allowed by default. - Deny communication from VLAN 108 to VLAN 105:
Create a classifier using the source (VLAN 108) and destination IP addresses (VLAN 105). Then, set a policy rule using this classifier and configure the Forward Action to Drop. - Allow 192.168.5.250 to access VLAN 108:
Create another classifier allowing source IP 192.168.5.250 to access VLAN 108. Set a policy rule using this classifier and configure the Forward Action to Forward. - Set Match Order to prioritize rules:
Navigate to Classifier Global Setting > Match Order and select Manual. Ensure that the allow rule (Step 3) has a higher priority than the deny rule (Step 2). - Verify the configuration:
You can check the Match Count of classifiers to confirm whether the traffic matches the defined rules.
Important Notes:
- If using ping to test, remember that ACLs on the switch are stateless, meaning they apply to each packet without maintaining session states. Return traffic also needs to be explicitly permitted for communication to succeed.
- If you require session persistence or need to block traffic initiation in one direction while still allowing responses, consider implementing these policies on a Stateful Firewall, as switches cannot distinguish sessions.
For additional support, feel free to contact Zyxel Support.
```0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 706 USG FLEX H Series
- 369 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 313 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight