This article describes how you can create an IP access control list (ACL) to allow TCP and UDP traffic from one IP address to another IP address. You can create the ACL with the Smart user interface (UI) on a NETGEAR Smart Switch.
For an article that describes the same procedure on a Smart Switch using the traditional UI or fully managed switch, see How do I create an IP access control list (ACL) to allow TCP and UDP traffic between two IP addresses using the traditional user interface on a NETGEAR Smart Switch or fully managed switch?
For an article that describes the same procedure using CLI commands on a fully managed switch, see How do I create an IP access control list (ACL) to allow TCP and UDP traffic between two IP addresses using CLI commands on a NETGEAR fully managed switch?
In this procedure, we are creating an ACL that allows TCP and UCP traffic from IP address 192.168.55.0/0.0.0.25 to IP address 192.168.44.0/0.0.0.255. (Subnet mask 0.0.0.255 indicates a single IP address.) The following main steps are involved:
- Create an extended IP ACL.
- Add a first rule to the ACL, allowing TCP traffic from IP address 192.168.55.0/0.0.0.25 to IP address 192.168.44.0/0.0.0.255.
- Add a second rule to the ACL, allowing UDP traffic from IP address 192.168.55.0/0.0.0.25 to IP address 192.168.44.0/0.0.0.255.
- Attach the ACL to an interface.
To create an IP ACL to allow TCP and UDP traffic from one IP address to another IP address using the Smart UI on a Smart Switch:
- Log in to your Smart Switch:
- Connect your computer to the same network as the switch.
You can use a WiFi or wired connection to connect your computer to the network, or
connect directly to a switch that is off-network using an Ethernet cable. - Launch a web browser.
- In the address field of your web browser, enter the IP address of the switch.
If you do not know the IP address, see How do I discover a NETGEAR Smart Switch.
The Device UI login page displays. - Enter one of the following passwords:
- Enter your device admin password.
- If you are also managing the switch through the Insight Cloud Portal or Insight
app, enter the Insight network password for the Insight network location to which
the switch is added.
- Click the Login button.
The Dashboard page displays.
- Connect your computer to the same network as the switch.
- Create extended IP ACL 101 with a first rule:
- Select Security > ACL > IP/ACL > IP ACL/Rules.
- Click the Add New button.
- Select the Add Rule to existing ACL or Add new ACL and Rule radio button.
- Select the Extended IP ACL radio button.
- Click the Add button.
The Extended ACL Rule Configuration page displays. - From the ACL ID/Name menu, select Add ACL.
- In the ACL Name, field, type 101.
- Configure the setting for the first rule for ACL 101:
- In the Sequence Number field, type 1.
- Select the Action Permit radio button.
- From the Protocol Type menu, select TCP.
- In the Src (source) section, type 192.168.55.0 in the IP Address field, and 0.0.0.25 in the Subnet Mask field.
- In the Dst (destination) section, type 192.168.44.0 in the IP Address field, and 0.0.0.25 in the Subnet Mask field.
- Click the Save button.
Your settings are saved.
- Create a second rule for ACL 101:
- Remain on the IP ACL/Rules page.
- Click the Add New button.
- Select the Add Rule to existing ACL or Add new ACL and Rule radio button.
- Select the Extended IP ACL radio button.
- Click the Add button.
The Extended ACL Rule Configuration page displays. - From the ACL ID/Name menu, select 101.
- Configure the setting for the second rule for ACL 101:
- In the Sequence Number field, type 2.
- Select the Action Permit radio button.
- From the Protocol Type menu, select UDP.
- In the Src (source) section, type 192.168.55.0 in the IP Address field, and 0.0.0.25 in the Subnet Mask field.
- In the Dst (destination) section, type 192.168.44.0 in the IP Address field, and 0.0.0.25 in the Subnet Mask field.
- Click the Save button.
Your settings are saved.
- Attach ACL 101 to interface 2.
- Select Security > ACL > IP ACL > IP Binding Configuration.
- From the ACL ID menu, select 101.
- From the Direction menu, select Inbound.
For a Smart Switch, Inbound is the only possible option. - In the Sequence Number field, optionally type a number to indicate the order of
the access list relative to other access lists already assigned to the interface and
direction. A low number indicates high precedence order. - In the Ports table, click port 2 so that the port displays blue.
- Click the Apply button.
Your settings are saved.
For more information, see the following support articles:
- What are access control lists (ACLs) and how do they work with my NETGEAR Smart Switch or fully managed switch?
- What are MAC access control lists (ACLs) and how do they work with my NETGEAR Smart Switch or fully managed switch?
- What are IP access control lists (ACLs) and how do they work with my NETGEAR Smart Switch or fully managed switch?