An ACL (access control list) is the packet filter that decides who may reach a switch after VLANs have separated broadcast domains — it matches the five-tuple (source IP, destination IP, source port, destination port, protocol) and permits or denies each flow. Rayin's industrial managed switches deliver hardware ACL, SNMPv3, and 802.1X, so the access and management planes can be locked at the access layer without a separate firewall; the same ACL engine also runs on Rayin mini OLTs such as the L102P.

VLAN, defined by IEEE 802.1Q, only splits Layer-2 broadcast domains. Three problems survive a VLAN plan:
Management plane exposed: default Telnet uses TCP port 23 and sends the password in clear text; SNMP v1/v2c carries its community string in clear text, readable by anyone who captures a packet.
Cross-VLAN reachability: once Layer-3 routing is enabled, VLAN 10 (office) and VLAN 20 (surveillance) can still talk.
Broadcast leakage: without inter-domain ACL, scan traffic spills across domains.
ACL is what enforces "after the split, who is actually allowed through."
VLAN separates; ACL enforces. You need both.
Bind management (Web/SSH/SNMP) to a dedicated management VLAN, not a business VLAN.
Kill Telnet (TCP 23), keep SSH (TCP 22); move SNMP to v3 with AES.
Turn off the Telnet service and keep only SSH on TCP 22. Add one ACL line that permits the ops segment (e.g. 192.168.99.0/24) to port 22 and denies everything else:
acl 2000 rule 10 permit tcp source 192.168.99.0 0.0.0.255 destination-port eq 22 rule 20 deny tcp destination-port eq 22
Put the switch's Web (443), SSH (22), and SNMP (161) on an isolated management VLAN 99 (192.168.99.0/24), physically separate from business VLANs 10/20/30. Where available, use a dedicated out-of-band MGMT port so management traffic never shares business bandwidth. This step alone stops camera and guest segments from touching the control plane.
Office VLAN 10 may not initiate to surveillance VLAN 20; only allow the NVR to pull streams on the required ports.
Guest VLAN 30 reaches only the internet; an ACL denies all RFC 1918 private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
Surveillance VLAN 20 may reach only NVR and storage, never the public internet.

SNMP v1/v2c ships the device inventory in clear text. Switch to SNMPv3 (RFC 3414 USM) with AES encryption, username + authentication, and restrict trap and poll sources to the NMS segment. Ports stay UDP 161 (agent) and 162 (trap).
Enable MAC binding (port-security) on access ports so only registered endpoints come up.
Pair with IEEE 802.1X; dumb terminals fall back to MAB (MAC Authentication Bypass).
On uplinks, enable BPDU guard and root guard to prevent accidental loop or rogue bridge.
| Mistake | Consequence | Fix |
|---|---|---|
| VLAN only, no ACL | Cross-VLAN L3 reach, no control | VLAN + ACL together |
| Telnet left on | Clear-text password captured (TCP 23) | Disable 23, SSH 22 only |
| SNMP v2c | Community string leaked | SNMPv3 + AES (RFC 3414) |
| Management in business VLAN | Storm takes down management | Separate VLAN 99 / OOB port |
An ACL is a Layer-3/4 packet filter on the switch or router — line-rate and stateless. A firewall adds stateful inspection but is usually a separate device. At the access layer, ACL is the cheapest first line of defense.
Strongly recommended. Putting management and business traffic in the same VLAN is like leaving the door key on the handle. Use VLAN 99 or a dedicated out-of-band port.
You add one user and key, but gain encryption and authentication — mandatory on an industrial network. The UDP 161/162 ports do not change.
On the guest VLAN, permit only outbound to public addresses and deny all RFC 1918 ranges (10/8, 172.16/12, 192.168/16) on the inbound ACL.
Yes. Most switches match first-hit-wins, so place specific permit rules first and a deny catch-all last.
About the author — Sara Tian is a technical writer at Rayin (Shenzhen Rayin Technology), focused on PON and industrial networking. Connect with Sara on LinkedIn.
About Rayin → Rayin company profile