GS1920-48HP VLAN's and MAC Address binding

TuSFuh
TuSFuh Posts: 2
First Comment Friend Collector
edited May 24 in Switch

Hello, i have a question. I have the case that I have multiple Access Points connected to a Switch and want to set up some kind of MAC Filtering of these. I want to make it that only the Access Point can connect to the Switch directly and if u want to put your Laptop for example on that Switch Port, it wont allow a pass through to the network. The Problem is, that I also want to allow all Clients connected over the AP to go through the Network and I dont know all the MAC-Addresses from these clients. And also these are all on different VLAN, like the AP is in VLAN 1 and all the Clients go VLAN 101, that works with no problems.

Accepted Solution

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,291  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @TuSFuh,

    For this requirement, you need to change your access point to NAT mode, and then set port security on GS1920.

    Here's the step to set port security for your reference:

    1. Check your access point is connecting to which port and its MAC address. My is connecting to port 7.
    2. Navigate to Menu > Security > Port Security page. Enter the port number in the MAC Freeze port list and click the "MAC Freeze" button.
    3. You will find the Port Security has been enabled and the address learning of port 7 is disabled.
    4. Check the Mac table. You will find the AP's MAC address has been changed to static.
    5. You may edit the static MAC address in Menu > Switching > Statci MAC Forwarding page.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,291  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @TuSFuh,

    Your requirement "Allows the switch to pass the traffic from the access point and its clients, but blocks the traffic from the clients connect to the switch directly." can be achieved with two different methods. You can reference the below information and choose one to apply.

    1. Enable port security and disable address learning on the ports not connecting with the access points. This makes the switch to not learn the MAC address on these ports, therefore, no traffic will be forwarded.
    2. Create a non-used VLAN for these ports and change the port VLAN ID (PVID) to this VLAN. This keeps these clients in a VLAN which is isolated from your network. In addition, other VLANs (like VLAN 1 & 101) are recommended to exclude these ports. (Change these ports from fixed to Normal/Forbidden.)

    Hope it helps.

  • TuSFuh
    TuSFuh Posts: 2
    First Comment Friend Collector

    Hi, thanks for the reply. I think you got my question wrong, it's not about the unused switch ports.

    I will try to explain it again. Think of like a hotel where you have access points on the wall. Now if you disconnect the Access Point and connect your Laptop via LAN port with the port used to plug in the AP. If thats happening I want to disallow the connection of the Laptop to the managment VLAN (VID 1) and want it to not have a connection at all or to a differnt vlan. I hope this helps for declaration of my needs.

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,291  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    Hi @TuSFuh,

    For this requirement, you need to change your access point to NAT mode, and then set port security on GS1920.

    Here's the step to set port security for your reference:

    1. Check your access point is connecting to which port and its MAC address. My is connecting to port 7.
    2. Navigate to Menu > Security > Port Security page. Enter the port number in the MAC Freeze port list and click the "MAC Freeze" button.
    3. You will find the Port Security has been enabled and the address learning of port 7 is disabled.
    4. Check the Mac table. You will find the AP's MAC address has been changed to static.
    5. You may edit the static MAC address in Menu > Switching > Statci MAC Forwarding page.