Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

This example shows how to isolate VLANs on a Layer 3 switch by using ACLs. In this example, PC 1 is in VLAN 24, PC 2 is in VLAN 48, and the server is in VLAN 38. PC 1 and PC 2 are isolated by an ACL but can both access the server.

Image

  1. Create VLAN 24 with IP address 192.168.24.1.
    1. Select Routing > VLAN > VLAN Routing Wizard.

      A screen similar to the following displays.

      Image
       
    2. Enter the following information:
      • In the Vlan ID field, enter 24.
      • In the IP Address field, enter 192.168.24.1.
      • In the Network Mask field, enter 255.255.255.0.
         
    3. Click Unit 1.

      The ports display.
       
    4. Click the gray box under port 24 twice until U displays.

      The U specifies that the egress packet is untagged for the port.
       
    5. Click Apply to save VLAN 24.
       
  2. Create VLAN 48 with IP address 192.168.48.1.
    1. Select Routing > VLAN > VLAN Routing Wizard.

      A screen similar to the following displays.

      Image
       
    2. Enter the following information:
      • In the Vlan ID field, enter 48.
      • In the IP Address field, enter 192.168.48.1.
      • In the Network Mask field, enter 255.255.255.0.
         
    3. Click Unit 1.

      The ports display.
       
    4. Click the gray box under port 48 twice until U displays.

      The U specifies that the egress packet is untagged for the port.
       
    5. Click Apply to save VLAN 48.
       
  3. Create VLAN 38 with IP address 10.100.5.34.
    1. Select Routing > VLAN > VLAN Routing Wizard.

      A screen similar to the following displays.

      Image
       
    2. Enter the following information in the VLAN Routing Wizard:
      • In the Vlan ID field, enter 38.
      • In the IP Address field, enter 10.100.5.34.
      • In the Network Mask field, enter 255.255.255.0.
         
    3. Click Unit 1. The ports display.
       
    4. Click the gray box under port 38 twice until U displays.

      The U specifies that the egress packet is untagged for the port.
       
    5. Click Apply to save VLAN 38.
       
  4. Enable IP routing:
    1. Select Routing > IP > Basic > IP Configuration.

      A screen similar to the following displays.

      Image
       
    2. Under IP Configuration, make the following selections:
      • For Routing Mode, select the Enable radio button.
      • For IP Forwarding Mode, select the Enable radio button.
         
    3. Click Apply to enable IP routing.
       
  5. Create an ACL with ID 101.
    1. Select Security > ACL > Advanced > IP ACL.

      A screen similar to the following displays.

      Image
       
    2. In the IP ACL Table, in the IP ACL ID field, enter 101.
       
    3. Click Add.
       
  6. Create an ACL with ID 102.
    1. Select Security > ACL > Advanced > IP ACL.

      A screen similar to the following displays.

      Image
       
    2. In the IP ACL Table, in the IP ACL ID field, enter 102.
       
    3. Click Add.
       
  7. Create an ACL with ID 103.
    1. Select Security > ACL > Advanced > IP ACL.

      A screen similar to the following displays.

      Image
       
    2. In the IP ACL ID field of the IP ACL Table, enter 103.
       
    3. Click Add.
       
  8. Add and configure an IP extended rule that is associated with ACL 101:
    1. Select Security > ACL > Advanced > IP Extended Rules.

      A screen similar to the following displays.

      Image
       
    2. Under IP Extended Rules, in the ACL ID field, select 101.
       
    3. Click Add.

      The Extended ACL Rule Configuration screen displays.

      Image
       
    4. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections:
      • In the Rule ID field, enter 1.
      • For Action, select the Deny radio button.
      • In the Match Every field, select False.
      • In the Destination IP Address field, enter 192.168.24.0.
      • In the Destination IP Mask field, enter 0.0.0.255.
         
    5. Click Apply to save the settings.
       
  9. Add and configure an IP extended rule that is associated with ACL 102.
    1. Select Security > ACL > Advanced > IP Extended Rules.

      A screen similar to the following displays.

      Image
       
    2. Under IP Extended Rules, in the ACL ID field, select 102.
       
    3. Click Add.

      The Extended ACL Rule Configuration screen displays.

      Image
       
    4. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections:
      • In the Rule ID field, enter 1.
      • For Action mode, select the Deny radio button.
      • In the Match Every field, select False.
      • In the Destination IP Address field, enter 192.168.48.0.
      • In the Destination IP Mask field, enter 0.0.0.255.
         
    5. Click Apply to save the settings.
       
  10. Add and configure an IP extended rule that is associated with ACL 103:
    1. Select Security > ACL > Advanced > IP Extended Rules.

      A screen similar to the following displays.

      Image
       
    2. Under IP Extended Rules, in the ACL ID field, select 103.
    3. Click Add.

      The Extended ACL Rule Configuration screen displays.

      Image
       
    4. Under Extended ACL Rule Configuration (100-199), enter the following information and make the following selections:
      • In the Rule ID field, enter 1.
      • For Action mode, select the Permit radio button.
      • In the Match Every field, select False.
      • In the Protocol Type field, select IP.
         
    5. Click Apply to save the settings.
       
  11. Apply ACL 102 to port 24:
    1. Select Security > ACL > Advanced > IP Binding Configuration.

      A screen similar to the following displays.

      Image
       
    2. Under Binding Configuration, make the following selection and enter the following information:
      • In the ACL ID field, select 102.
      • In the Sequence Number field, enter 1.
         
    3. Click Unit 1. The ports display.
       
    4. Click the gray box under port 24. A check mark displays in the box.
       
    5. Click Apply to save the settings.
       
  12. Apply ACL 101 to port 48:
    1. Select Security > ACL > Advanced > IP Binding Configuration.

      A screen similar to the following displays.

      Image
       
    2. Under Binding Configuration, make the following selection and enter the following information:
      • In he ACL ID field, select 101.
      • In the Sequence Number field, enter 1.
         
    3. Click Unit 1.

      The ports display.
       
    4. Click the gray box under port 48.

      A check mark displays in the box.
       
    5. Click Apply to save the settings.
       
  13. Apply ACL 103 to port 24 and port 48:
    1. Select Security > ACL > Advanced > IP Binding Configuration.

      A screen similar to the following displays.

      Image
       
    2. Under Binding Configuration, make the following selection and enter the following information:
      • In the ACL ID field, select 103.
      • In the Sequence Number field, enter 2.
         
    3. Click Unit 1.

      The ports display. Configure the following ports:
      • Click the gray box under port 24. A check mark displays in the box.
      • Click the gray box under port 48. A check mark displays in the box.
         
    4. Click Apply to save the settings.


For more information, see the following support articles:

 

 

This article applies to the following managed switches and their respective firmware:

 

 

  • M5300 - firmware version 10.0.0.x
    • M5300-28G (GSM7228S)
    • M5300-5G (GSM7252S)
    • M5300-28G3 (GSM7328Sv2h2)
    • M5300-52G3 (GSM7352Sv2h2)
    • M5300-28G_POE+ (GSM7228PSv1h2)
    • M5300-52G-POE+ (GSM7252PSv1h2)
    • M5300-28GF3 (GSM7328FSv2)
  • M4100 - firmware version 10.0.1.x
    • M4100-26G (GSM7224v2h2)
    • M4100-50G (GSM7248v2h2)
    • M4100-26G-POE (GSM7226Pv1h1)
    • M4100-50G-POE+ (GSM7248Pv1h1)
    • M4100-26G-POE (FSM7226Pv1h1)
    • M4100-50-POE (FSM7250Pv1h1)
    • M4100-D12G (GSM5212v1h1)
    • M4100-D10-POE (FSM5210Pv1h1)
  • M7100 - firmware version 10.0.1.x
    • M7100-24X (XSM7224)
  • XSM7224S - firmware version 9.0.1.x
Last Updated:07/07/2025 | Article ID: 21720

Our team is here to help!

Phone
Chat
Email