Home Support Blog

Industrial switch acl configuration

Release date:2026-09-15

An ACL (access control list) is the packet filter that decides who may reach a switch after VLANs have separated broadcast domains — it matches the five-tuple (source IP, destination IP, source port, destination port, protocol) and permits or denies each flow. Rayin's industrial managed switches deliver hardware ACL, SNMPv3, and 802.1X, so the access and management planes can be locked at the access layer without a separate firewall; the same ACL engine also runs on Rayin mini OLTs such as the L102P.

image

Why VLAN Alone Leaves Gaps

VLAN, defined by IEEE 802.1Q, only splits Layer-2 broadcast domains. Three problems survive a VLAN plan:

  • Management plane exposed: default Telnet uses TCP port 23 and sends the password in clear text; SNMP v1/v2c carries its community string in clear text, readable by anyone who captures a packet.

  • Cross-VLAN reachability: once Layer-3 routing is enabled, VLAN 10 (office) and VLAN 20 (surveillance) can still talk.

  • Broadcast leakage: without inter-domain ACL, scan traffic spills across domains.

ACL is what enforces "after the split, who is actually allowed through."

KEY TAKEAWAYS
  • VLAN separates; ACL enforces. You need both.

  • Bind management (Web/SSH/SNMP) to a dedicated management VLAN, not a business VLAN.

  • Kill Telnet (TCP 23), keep SSH (TCP 22); move SNMP to v3 with AES.

Step 1: Disable Telnet, Enable SSH and Restrict the Source

Turn off the Telnet service and keep only SSH on TCP 22. Add one ACL line that permits the ops segment (e.g. 192.168.99.0/24) to port 22 and denies everything else:

acl 2000
 rule 10 permit tcp source 192.168.99.0 0.0.0.255 destination-port eq 22
 rule 20 deny   tcp destination-port eq 22

Step 2: Lock Management to a Management VLAN

Put the switch's Web (443), SSH (22), and SNMP (161) on an isolated management VLAN 99 (192.168.99.0/24), physically separate from business VLANs 10/20/30. Where available, use a dedicated out-of-band MGMT port so management traffic never shares business bandwidth. This step alone stops camera and guest segments from touching the control plane.

Step 3: Isolate Business Domains (Office / Surveillance / Guest)

  • Office VLAN 10 may not initiate to surveillance VLAN 20; only allow the NVR to pull streams on the required ports.

  • Guest VLAN 30 reaches only the internet; an ACL denies all RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).

  • Surveillance VLAN 20 may reach only NVR and storage, never the public internet.

    image

Step 4: Move SNMP to v3 with AES

SNMP v1/v2c ships the device inventory in clear text. Switch to SNMPv3 (RFC 3414 USM) with AES encryption, username + authentication, and restrict trap and poll sources to the NMS segment. Ports stay UDP 161 (agent) and 162 (trap).

Step 5: Add Port-Security as a Backstop

  • Enable MAC binding (port-security) on access ports so only registered endpoints come up.

  • Pair with IEEE 802.1X; dumb terminals fall back to MAB (MAC Authentication Bypass).

  • On uplinks, enable BPDU guard and root guard to prevent accidental loop or rogue bridge.

Common ACL Configuration Mistakes

MistakeConsequenceFix
VLAN only, no ACLCross-VLAN L3 reach, no controlVLAN + ACL together
Telnet left onClear-text password captured (TCP 23)Disable 23, SSH 22 only
SNMP v2cCommunity string leakedSNMPv3 + AES (RFC 3414)
Management in business VLANStorm takes down managementSeparate VLAN 99 / OOB port

FAQ

What is the difference between an ACL and a firewall?

An ACL is a Layer-3/4 packet filter on the switch or router — line-rate and stateless. A firewall adds stateful inspection but is usually a separate device. At the access layer, ACL is the cheapest first line of defense.

Must the management VLAN be separate?

Strongly recommended. Putting management and business traffic in the same VLAN is like leaving the door key on the handle. Use VLAN 99 or a dedicated out-of-band port.

Is SNMPv3 much harder than v2c?

You add one user and key, but gain encryption and authentication — mandatory on an industrial network. The UDP 161/162 ports do not change.

How do I let the guest network reach only the internet?

On the guest VLAN, permit only outbound to public addresses and deny all RFC 1918 ranges (10/8, 172.16/12, 192.168/16) on the inbound ACL.

Does ACL rule order matter?

Yes. Most switches match first-hit-wins, so place specific permit rules first and a deny catch-all last.

Related Reading

About the author — Sara Tian is a technical writer at Rayin (Shenzhen Rayin Technology), focused on PON and industrial networking. Connect with Sara on LinkedIn.

About Rayin → Rayin company profile

Get A Quote

You have agreed to this website’s《Privacy Policy》