Omada Switch ACLs for established state

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Omada Switch ACLs for established state

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Omada Switch ACLs for established state
Omada Switch ACLs for established state
2021-02-16 11:13:50
Model: OC200  
Hardware Version:
Firmware Version:

Hi there,

 

just started my Omada SDN Setup. The main parts are:

* Controller OC200 v1.0 (Firmware 1.7.3 Build 20201119 Rel.63433, Controller Version 4.2.8)
* Gateway TL-R605 v1.0 (Firmware 1.0.0)
* Switch TL-SG2008P v1.0 (Firmware 1.0.0)

I wonder how to configure the following (pretty common I guess) setup:

* VLAN 1 as main VLAN
* VLAN 2 as IoT VLAN

1. I want to deny traffic from VLAN 2 to VLAN 1 (this worked pretty easy by adding a switch ACL rule for that)
2. I still want to allow (initiated) traffic from VLAN 1 to VLAN 2 so that I can for example access my IP camera

 

But for this to work I need something that is normally referred to as a firewall rule, that allows established connections from VLAN 2 to VLAN 1. How can this be done? I cannot find it in Omada. I also try to set it up by running all the devices in standalone mode, be even there I could not find a way to create an ACL rule that matches on established connection.

 

Any help would be appreciated.

Christian

  0      
  0      
#1
Options
5 Reply
Re:Omada Switch ACLs for established state
2021-02-16 16:44:24

@thekwasti 

 

If your camera are on a specific Port range you could createan IP Port group to ALLOW those ports then apply it via a Switch ACL, set this as a higher priority than the block VLAN and that should work

 

For example i have a IOT VLAN that is totally blocked from my main VLAN, however i also have cameras on that IOT so can access via ports 4455 and 4456 those specific IPs used for the cameras..  

 

That help?

 

  0  
  0  
#2
Options
Re:Omada Switch ACLs for established state
2021-02-16 17:43:18

@Philbert Thanks for the reply. That would work of course, but I don't think it is a good solution. Esp. IP cameras never have to be allowed to initiate connections themself (except for NTP for time sync).


I even tried to run both, the switch as well as the gateway in standalone mode, and even there it is not possible. I just really wonder, how a router in the business tier does not allow a simple firewall rule based on the established state.

 

Probably I will just step away from the whole omada ecosystem and get something like an edgeswitch (I already have an edgerouter running). The centralized management is super nice, but if fundamentals are just not available, then it does not really help. :(

  0  
  0  
#3
Options
Re:Omada Switch ACLs for established state
2021-05-08 22:08:34
I have to second this. I can setup any 2 random physical home routers and get this functionality by default. Omada needs provide this functionality across VLANs; it's a severe oversight.
  0  
  0  
#4
Options
Re:Omada Switch ACLs for established state
2021-06-26 10:52:49

Thank god I saw this forum post. That doesn't sound good.

Are there any news regarding this topic? This is a total knock out for our plans to migrate to Omada. Even Unifi offers this functionality.

Without that, a additional firewall is required and I don't see a reason for using a Omada gateway.

  0  
  0  
#5
Options
Re:Omada Switch ACLs for established state
2021-07-16 22:43:08
@ksx I'm jealous you found this post. I was running the EAP225s and a PoE 1500G switch with an ER-X router, and it was working as expected. I found the EdgeOS to be more complicated than I wanted to deal with (and I didn't want the expense of a full ubiquiti network to get their central management), but I have found the limitations of the Omada system to be extremely frustrating.
  0  
  0  
#6
Options