Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

This article describes how you can create an IP access control list (ACL) to allow TCP and UDP traffic from one IP address to another IP address. You can create the ACL with the traditional user interface (UI) on a NETGEAR Smart Switch or with the main UI on a NETGEAR fully managed switch.

For an article that describes the same procedure on a Smart Switch with a Smart UI, see How do I create an IP access control list (ACL) to allow TCP and UDP traffic between two IP addresses using the Smart user interface on a NETGEAR Smart Switch?

For an article that describes the same procedure using CLI commands on a fully managed switch, see How do I create an IP access control list (ACL) to allow TCP and UDP traffic between two IP addresses using CLI commands on a NETGEAR fully managed switch?

In this procedure, we are creating an ACL that allows TCP and UCP traffic from IP address 192.168.55.0/0.0.0.25 to IP address 192.168.44.0/0.0.0.255. (Subnet mask 0.0.0.255 indicates a single IP address.) The following main steps are involved:

  1. Create an extended IP ACL.
  2. Add a first rule to the ACL, allowing TCP traffic from IP address 192.168.55.0/0.0.0.25 to IP address 192.168.44.0/0.0.0.255.
  3. Add a second rule to the ACL, allowing UDP traffic from IP address 192.168.55.0/0.0.0.25 to IP address 192.168.44.0/0.0.0.255.
  4. Attach the ACL to an interface.

To create an IP ACL to allow TCP and UDP traffic from one IP address to another IP address using the traditional UI on a Smart Switch or the main UI on a fully managed switch:

  1. Log in to your switch:
    • Smart Switch: On a Smart Switch with a traditional UI, do the following:
      1. Connect your computer to the same network as the switch.
        You can use a WiFi or wired connection to connect your computer to the network, or connect directly to a switch that is off-network using an Ethernet cable.
      2. Launch a web browser
      3. In the address field of your web browser, enter the IP address of the switch.
        If you do not know the IP address, see How do I discover a NETGEAR Smart Switch.
        The Device UI login page displays.
      4. Enter one of the following passwords:
        • Enter your device admin password.
        • If you are also managing the switch through the Insight Cloud Portal or Insight
          app, enter the Insight network password for the Insight network location to which
          the switch is added.
      5. Click the Go button.
        The System Information page displays.
    • Fully managed switch: On a fully managed switch, do the following:
      1. Launch a web browser and enter the IP address of the switch in the address field of your web browser.
        The login page displays.
      2. Click the Main UI Login button.
        The main UI login page displays in a new tab.
      3. Enter admin as the user name and enter one of the following passwords:
        • Enter your local device password.
          The first time that you log in, no password is required. However, you then must specify a local device password to use each subsequent time that you log in.
        • If you are managing the switch through the Engage controller, enter the site password for the Engage site to which the switch is onboarded.
        • If, in addition to the main UI, you are also managing the switch through the Insight Cloud Portal or Insight app, enter the Insight network password for the Insight network to which the switch is added.
      4. Click the Login button.
        The System Information page displays.
  2. Create extended IP ACL 101:
    1. Select Security > ACL > Advanced > IP ACL.
    2. In the IP ACL ID field, type 101.
    3. Click the Add button.
      Your settings are saved.
  3. Create a first rule for ACL 101:
    1. Select Security > ACL > Advanced > IP Extended Rules.
    2. From the ACL ID menu, select 101.
    3. Click the Add button.
      The Extended ACL Rule Configuration page displays.
    4. Configure the setting for the first rule for ACL 101:
      • In the Sequence Number field, type 1.
      • Selection the Action Permit radio button.
      • From the Protocol Type menu, select TCP.
      • In the Src IP Address fields, type 192.168.55.0 in the left field, and 0.0.0.25 in the right field.
      • In the Dst IP Address fields, type 192.168.44.0 in the left field, and 0.0.0.25 in the right field.
    5. Click the Apply button.
      Your settings are saved.
  4. Create a second rule for ACL 101:
    1. Select Security > ACL > Advanced > IP Extended Rules.
    2. From the ACL ID menu, select 101.
    3. Click the Add button.
      The Extended ACL Rule Configuration page displays.
    4. Configure the setting for the second rule for ACL 101:
      • In the Sequence Number field, type 2.
      • Selection the Action Permit radio button.
      • From the Protocol Type menu, select UDP.
      • In the Src IP Address fields, type 192.168.55.0 in the left field, and 0.0.0.25 in the right field.
      • In the Dst IP Address fields, type 192.168.44.0 in the left field, and 0.0.0.25 in the right field.
    5. Click the Apply button.
      Your settings are saved.
  5. Attach ACL 101 to interface 2.
    1. Select Security > ACL > Advanced > IP Binding Configuration.
    2. From the ACL ID menu, select 101.
    3. From the Direction menu, select Inbound.
      For a Smart Switch, Inbound is the only possible option.
    4. In the Sequence Number field, optionally type a number to indicate the order of
      the access list relative to other access lists already assigned to the interface and
      direction. A low number indicates high precedence order.
    5. In the Ports table, click port 2 so that a check mark displays in the box.
    6. Click the Apply button.
      Your settings are saved.


For more information, see the following support articles:

Last Updated:08/19/2025 | Article ID: 21714

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email