This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
advanced-access [2023/09/12 17:20] – [LAN Access Notes] -clarity on unidirectional nature of rule, formatting hogwild | advanced-access [2024/11/27 01:30] (current) – [LAN Access] -Condense, formatting hogwild | ||
---|---|---|---|
Line 5: | Line 5: | ||
\\ | \\ | ||
- | For example, | + | For example, say we have two LANs, one primary (LAN0/br0) and one secondary (LAN1/br1). |
- | If you want devices on LAN0 to be able to communicate with devices on LAN1 (and vice versa), you might use these settings: | + | If you want devices on LAN0 to communicate with devices on LAN1 (and vice versa), you might use these settings: |
\\ | \\ | ||
Line 13: | Line 13: | ||
{{: | {{: | ||
- | **On: | + | **On: |
- | **Src:** This displays/ | + | \\ |
- | **Src Address:** This (optional) field narrows | + | **Src: |
- | **Dst:** Here, you specify the (logical) Destination LAN for the rule on this row of the table. | + | \\ |
- | **Dst Address: **(optional) narrows | + | **Src Address: |
- | **Description:** This is a free text field in which to enter whatever you wish as a reminder, note etcetera. | + | \\ |
+ | |||
+ | **Dst:** here, you specify the (logical) Destination LAN for the rule on this row of the table. | ||
\\ | \\ | ||
- | \\ | + | **Dst Address: **(optionally), |
+ | \\ | ||
- | ===== LAN Access Notes ===== | + | **Description: |
- | Regardless of LAN Access rules, by default a LANx device is able to reach (e.g. ping) all the router' | + | \\ |
- | All entries in LAN Access are one-way only. | + | \\ |
- | For example, if you want hosts on LAN0 to be able to communicate with hosts on LAN1, | + | |
- | and hosts on LAN1 to be able to communicate with hosts on LAN0, you will need to have two entries in the table to achieve that. | + | |
+ | ===== LAN Access Notes ===== | ||
- | LAN Access is an IP-level access control. | + | * Regardless of LAN Access rules, by default a LANx device is able to reach (e.g. ping) all the router' |
- | This means that **all ports/ | + | * All entries in LAN Access are one-way only. For example, if you want hosts on LAN0 to be able to communicate with hosts on LAN1, and vice versa, you'll need two entries in the table to achieve that. |
+ | * LAN Access is an IP-level access control. | ||
\\ | \\ |