01-11-2023 09:20 AM
Hello as the title reveals i try to block all local traffic to a raspberryPi, make it only accessable from the internet.
I want do so because of security reasons if someone get access to the raspberry
i try to archiev this with ACL on my cisco CBS250-8T-D switch.
can someone lead me a bit into the right direction?
my local subnet is 192.168.0.0/24
router is 192.168.0.1
the raspberry pi 192.168.0.15
the webserver is reachable whatever i try to block
thanks for your time
01-11-2023 09:22 AM
01-11-2023 01:01 PM - edited 01-11-2023 01:02 PM
You can try ACL source 192.168.0.0/24 to 192.168.0.15 (mask 255.255.255.255) deny from LAN
If the device is in Layer 2 domain network time it does not even reach the gateway.
if the Pi need to be separated, use different VLAN and IP address and apply ACL.
01-11-2023 01:25 PM
On my switch port 1 is a fritzbox, port 2,3 a nas, and port 8 is the raspberry pi
if i put port 1 and 8 in the same VLAN then my nas loose connection to the fritzbox
how can i add both VLAN to the router but seperate in same time localy?
01-13-2023 12:47 AM
how do i create such VLAN?
01-11-2023 12:53 PM
hello @linuxUser how are you applying the ACL and how's look like ? if you are authenticating the device what you can enforce in the device' session a DACL
01-11-2023 01:07 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide