Access Control List not working on AX7501-B1

CloudByte
CloudByte Posts: 6  Freshman Member
First Comment Friend Collector
edited December 2024 in Home Router

Hello Community

I own a AX7501-B1 and have configured two VLANs:

VLAN ID 1 - Default - 192.168.178.0/24
VLAN ID 10 - Guests - 192.168.5.0/24

This works fine so far.

My Goal is to drop traffic between those VLANs. That's why I've created two ACLs:

Both are configured like this:

Problem: Traffic is still going from one to the other VLAN:

I've tried all the "Direction" possible in the ACL. No luck.

Am I missing something? Any help is highly appreciated!

All Replies

  • tonygibbs16
    tonygibbs16 Posts: 970  Guru Member
    50 Answers 500 Comments Friend Collector Fourth Anniversary

    Hello @CloudByte

    Welcome to the forum.

    I wonder if the ACLs are not working because the 192.168.178.0/24 and 192.168.5.0/24 are subnets rather than specific IP addresses.

    As a test, what happens if you put 192.168.178.155 and 192.168.5.135 in the Source IP address and Destination IP address fields?

    If you get a deny, then is there a Specific Subnet setting available where you have Specific IP address selected?

    - if there is, then you can trying putting the subnets into the IP address fields.

    Merry Christmas and Kind regards,

    Tony

  • CloudByte
    CloudByte Posts: 6  Freshman Member
    First Comment Friend Collector

    Hi Tony

    Thank you very much for your response!

    I've already tried that. If I put IPs instead of Subnets in the Source & Destination address fields still nothing is denied/dropped between those two IPs… So that's why I'm out of ideas what to try next.
    Also had a look via SSH but there doesn't seems to be any Firewall settings available via SSH…

    Happy holidays to you too!

    Kind regards
    Stefan

  • tonygibbs16
    tonygibbs16 Posts: 970  Guru Member
    50 Answers 500 Comments Friend Collector Fourth Anniversary

    Hi Stefan @CloudByte

    Are you able to say what firmware version you are running?

    It might have a bug in it...

    Happy new year.

    Kind regards Tony

  • CloudByte
    CloudByte Posts: 6  Freshman Member
    First Comment Friend Collector

    Hi Tony @tonygibbs16

    I'm running on the newest firmware available by my provider init7 which is V5.17(ABPC.5.3)C0.

    Fells to me like a bug too…

    Happy new year!

    Best regards
    Stefan

  • tonygibbs16
    tonygibbs16 Posts: 970  Guru Member
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    edited December 2024

    Hi Stefan @CloudByte

    That firmware is the latest version available, and the release note is at https://spdl.zyxel.com/AX7501-B0/firmware(public_version)/AX7501-B0_5.17(ABPC.5.3)C0.pdf and it does not mention access control lists at all.

    It does feel like a bug…

    Something that could help confirm if it is a bug is what does the rule look like on the Security-Firewall-Access Control page when it is not working?

    from the user guide https://spdl.zyxel.com/AX7501-B1/user_guide/AX7501-B1_OPAL-Series%20%28EX5601-T0%29_UG_V5.15-5.70_Ed17.pdf

    Is a yellow bulb showing under Status when the access control list is not working?

    Is the Policy in the ACL set to Drop or Reject, rather than Accept?

    Happy New Year to you also. :-)

    Kind regards,

    Tony

  • CloudByte
    CloudByte Posts: 6  Freshman Member
    First Comment Friend Collector

    Hi @tonygibbs16

    Yes, yellow bulb is showing and the ACL is set to "Drop":

    Best regards
    Stefan

  • tonygibbs16
    tonygibbs16 Posts: 970  Guru Member
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    edited December 2024

    Hi Stefan @CloudByte

    Thanks very much for your reply.

    I have 2 final thoughts for your consideration:

    1. Do any of the Direction Settings make a difference? Are you using LAN to WAN or LAN to Router for example?

    2. If there is still no difference in behaviour, then maybe you could log a Consumer Idea at the following link

    Home Router - Zyxel Community

    for Zyxel to introduce a LAN to LAN Direction for the Access Control Lists in a future firmware revision.

    Happy New Year and Kind Regards,

    Tony

  • CloudByte
    CloudByte Posts: 6  Freshman Member
    First Comment Friend Collector

    Hello Tony @tonygibbs16

    1. I've tried all the "Direction" settings possible in the ACL. No luck.
    2. Thanks for sharing the link.

    Best regards
    Stefan

Consumer Product Help Center