Dude..... ACLs are a layer2 function. You need to use Layer3 (Firewall). Block the subnets and be done. This video just shows a lack of basic knowledge.
@JasonsLabVideos11 ай бұрын
The built in switch IS L2, DERP ! Try again.
@seantellsit143110 ай бұрын
@@JasonsLabVideos yes... however, the second packets have a destination header to go to a different subnet, they go to the firewall for processing.... DERP
@JasonsLabVideos10 ай бұрын
Correct, but the features to block things properly is missing in this device. Its a switch & router & controller all in one! @@seantellsit1431
@jorgemtds8 ай бұрын
@@JasonsLabVideosI saw another video on KZbin complaining about that integrated device. Avoid at all costs. You should have gotten separate Router, Switch and Controller. I think those Will do what you want.
@JasonsLabVideos8 ай бұрын
The new firmware fixes the issue, I just haven't had time to do the video. @@jorgemtds
@hutchabilly1079 ай бұрын
@JasonsLabVideos have you updated the firmware to the latest version for the ER7212PC and rechecked to see if it is any better? I just updated my hardware and the Gateway ACL has LAN-LAN permit and blocking now.
@JasonsLabVideos4 ай бұрын
I did update it, and it works properly now :)
@apresuttАй бұрын
@@JasonsLabVideos Shouldnt you be pinning a comment or editing your description? Seems like clickbate at this point.
@JasonsLabVideosАй бұрын
@@apresutt The original Firmware was POOH! The new one improved everything and the unit is rock solid !
@alexandrpyankov4308 ай бұрын
From manual for the device: Interface: Create the network with a Layer 3 interface, which is required for inter-VLAN routing. VLAN: Create the network as a Layer 2 VLAN It is on page 55
@ChfReviewer8 ай бұрын
Recently I updated the ER7212PC to version : 1.1.0 Build 20230803 Rel.83667 with controller version 5.8.31 and I am happy to inform you that the Gateway ACL is now containing LAN-LAN option. I tried this ACL and it seems to be doing the job. So Finally this router looks ready for deployement.
@JasonsLabVideos8 ай бұрын
I'll be trying this very soon, thanks for letting me know sir !
@BlueNETGaming9 ай бұрын
On my ER706w setup with the controller separate on my network I can setup the networks as needed. Not sure if you just meant the standalone hardware or tplink Omada full setup? Still thanks for making the video, always good to educate each other
@JasonsLabVideos8 ай бұрын
The Er7212 was what I’m referring to.. but new firmware was released so, we shall see
@willbobgill Жыл бұрын
jason off topic, are any of those new grandstream switches silent like the ubiquti’s?
@JasonsLabVideos Жыл бұрын
100% they are !! They startup for 3 seconds then ramp down. BTW they are built like tanks and will last a very long time. Inside PSU"S are built VERY VERY well !!
@willbobgill Жыл бұрын
@@JasonsLabVideos rapid reply, thank you you’re the man
@ryancyr36229 ай бұрын
You can’t vlan tag the ports on that router. I learned the hard way too with a customer install I did but luckily they only required a guest network over wifi so I was good. I usually just get the er7206 or the er707-m2 and use a switch to vlan tag the ports. Much neater when you have all your ports in the house going to a 24 port port switch. Aps, printers, cameras all in one place. Then vlan tag the ports as needed.
@JasonsLabVideos9 ай бұрын
The new update might fix this, i need to try it..
@RubenSmitGooglePlus10 ай бұрын
@JasonsLabVideos a new firmware has been released on 2024-01-15 . The description says it fixes some known security vulnerabilities. Can you test if the problem is still there?
@JasonsLabVideos10 ай бұрын
I sure can, ill do that tonight, Thanks for letting me know about the new firmware !
@RubenSmitGooglePlus10 ай бұрын
@@JasonsLabVideos thanks! That would be great.
@Net-Extension Жыл бұрын
Is this problem only in the ER7212-PC or a general omada issue ?
@SPXLabs Жыл бұрын
It's specific to this router because TP-Link markets this as a Router, Controller, and Switch. However, the ACLs and other options that are normally available to a Omada Switch are not available here. So if you want the fully functionality of a traditional stack like a ER605 + Switch + AP, then this is not for you. If you just use WiFi then this could be for you since you can still create VLANs, ACLs, ect for APs.
@Net-Extension Жыл бұрын
@@SPXLabs I see. Its not a huge price difference. Since you mentioned it. What is the point of creating VLANs when you can not segregate them ?
@SPXLabs Жыл бұрын
@@Net-Extension Yeah the pricing is odd too. Beats the heck out of me.
@mikemarcus419011 ай бұрын
@@SPXLabs Thanks for this video and reply
@razorous4 ай бұрын
@@SPXLabs Thanks for this, was almost going to consider this as my mini network rack is full. I'm sticking to the ER605 + Switch + APs setup
@wojciech_migda11 ай бұрын
I understand your complaint, but maybe this router is just not designed for that kind of task? I bought it just for a SOHO use without any guests and in this scenario it should be just right..... But once again it is good, that for users who might need a lan guest access, you presented what this router lacks!
@MatysPC11 ай бұрын
Należy ustawić Gateway ACL żeby router blokował ruch. Nie działało jakiś czas temu, ale już zostało poprawione. Na tym filmie masz pewnie jeszcze nieaktualny firmware.
@googler384 ай бұрын
I need a wireless controller and a newer router for a simple home network - I'll probably get this yoke as the sw omada seems to work well to facilitate fast roaming.
@JasonsLabVideos4 ай бұрын
The er7212 with a few WAP's will be perfect. I have about 28 of them out in the filed and all rock sold and working with VPN.
@gaston53678 ай бұрын
The TPLink ER7212 is a layer 2 switch and a router, because of that you can´t deny communication trough the Vlans, for that you need a switch layer 3. It is not a problem of security, is a matter of kind of switch you are using.
@JasonsLabVideos4 ай бұрын
The newest firmware fixed the issue.
@gaston53674 ай бұрын
@@JasonsLabVideos What version is?
@clabretro Жыл бұрын
That's wild, defeats the entire purpose VLANs!
@JasonsLabVideos Жыл бұрын
Yup, so no security LOL ! Pretty dumb right ?
@diomedessanchez99527 ай бұрын
Hi Jason, Do you know if the controller in the device communicate well with Tp-link VIGI cameras and NVR?
@JasonsLabVideos7 ай бұрын
I don't think so, but i'm not 100% sure.
@diomedessanchez99527 ай бұрын
@@JasonsLabVideos Thanks Jason
@keyoke Жыл бұрын
I shall stick to my er605, sg2008p set up then. Thanks for the video! At least now i can block inter vlans via ACL as well as my IoT devices are on a separate vlan, and i have a acl to block these devices from accessing my internal network for security measures just in case they got hacked
@JasonsLabVideos Жыл бұрын
Yep, maybe one day they will fix it for now PASS on Tp-link.
@MrDuka2511 ай бұрын
Do you have a.dedicated controller?
@keyoke11 ай бұрын
@@MrDuka25 yes i do
@JasonsLabVideos11 ай бұрын
It's built into the ER7212.@@MrDuka25
@ChrisPorosky11 ай бұрын
Are you taking a pass on tplink in general or a pass on the er7212pc (which appears to be a one off device with specific limits)?
@ShawnEdwardsDJShawnChristian8 ай бұрын
Ok. Since there crap for you. would you donete theme to mjeear in Jamaica. I'd like to use them for a school set up
@JasonsLabVideos8 ай бұрын
Sure give me $500 for shipping.
@ChevyBlazerBoy Жыл бұрын
Running tplink omada switches and APs and opnsense protectli For firewall/router. Been rock solid. I knew going into it the tplink routers sucked thats why i went opnsense.
@TismoGaming Жыл бұрын
Man my setup exactly like yours but I am not sure if I set it up right. I wish you were my neighbor so you can give it a look and see if it’s all good 😅
@JasonsLabVideos Жыл бұрын
Yup, that will work well. Their ap's are decent & switches not sure. BUT this ER7212 & other firewalls = garbage..
@homenetworkguy Жыл бұрын
I have managed TP-Link switches with OPNsense as the router/firewall and it works great. I have a couple of older UniFi APs as well. I’m planning on getting some other switches to try in the future to meet my needs/wants.
@JasonsLabVideos Жыл бұрын
Try Alta Labs or Grandstream stuff. Ditch the Tp-link.@@homenetworkguy
@homenetworkguy Жыл бұрын
@@JasonsLabVideos Yeah, I have my eyes on one of the Engenious switches. Also a cheaper brand managed 48 port switch with 10G SFP+ interfaces. TP-Link managed switches do work ok for budget home network usage, but I definitely would never use any of their routers as you have mentioned in your video.
@Practical-IT Жыл бұрын
When it comes to routers these days, I'm in the "pfSense/OPNSense or bust" camp. Great video BTW.
@pinsjax Жыл бұрын
Me with HUAWEI WIFI AX3 No problem / And it have a Guest mode(^~^)
@ChfReviewer8 ай бұрын
@JasonsLabVideos Recently I updated the ER7212PC to version : 1.1.0 Build 20230803 Rel.83667 with controller version 5.8.31 and I am happy to inform you that the Gateway ACL is now containing LAN-LAN option. I tried this ACL and it seems to be doing the job. So Finally this router looks ready for deployement. Please give us a followup to this video
@CompuWhizz Жыл бұрын
Piles of steaming doodoo
@PE4Doers Жыл бұрын
A courageous video Jason - Great 🙂
@JasonsLabVideos Жыл бұрын
Thanks sir !
@PE4Doers Жыл бұрын
@@JasonsLabVideos You are very welcome.
@MrDuka2511 ай бұрын
Does the issue happen only when using this specific device? What if I use a dedicated tplink router and a dedicated switch?
@JasonsLabVideos11 ай бұрын
ON this device yes,
@SWLinPHX11 ай бұрын
Both my TP-Link mesh systems I've installed (one a few years ago and one just this past year) work great but I have had issues with other older TP-Link products such as WiFi extenders.
@rayjaymor87547 ай бұрын
to be fair, wifi extenders as a whole are a lotto bet. I avoid them unless I have zero other choice
@212helpdesk2 ай бұрын
But I think you said you can block the wifi traffic from the hard wired lan traffic. Is that correct? Just don't provide a cable to the devices you don't want on your sensitive (accounting, HR systems) maybe.
@JasonsLabVideos2 ай бұрын
The point was to have a so called device like a wired printer accessible from another wireless network BUT only by the printing port & block everything else !
@albanabraham5295 Жыл бұрын
I like the logo.
@Hein07033 ай бұрын
Is this issue fixed after all those Firmware updates ??
@JasonsLabVideos3 ай бұрын
Yup sure are
@noshibear84087 ай бұрын
its a good thing i saw this video as i was considering putting up one... went for another brand instead
@JasonsLabVideos7 ай бұрын
Grandstream ? IMO tey fixed the main issue in the new firmware, I have applied it to all 18 units i manage and all is now good.
@tv175s310 ай бұрын
I see you have1.0.3 on the router, I do have LAN->LAN on ER7212 with v1.1.1
@JasonsLabVideos10 ай бұрын
I'm going to be doing a new video after i get 1.1.1 downloaded and tested ! Crossing fingers they fixed this !
@WillieHowe Жыл бұрын
Great video. If you run a tplink 605 by itself without Omada it works. Omada is the problem here for sure. Let's do a collab!
@ceramicchef Жыл бұрын
Works fine on a 605 with Omada too.
@Kunstentech Жыл бұрын
Thank you for sharing !!!
@BDBD16 Жыл бұрын
FACTS!
@ericyost528711 ай бұрын
Do you know if this security issue has been fixed?
@JasonsLabVideos11 ай бұрын
It's still not fixed ! Tried it last week actually.
@ericyost528711 ай бұрын
@@JasonsLabVideos Wow I wonder if they are atleast aware of the issue?
@projectcoopservis402011 ай бұрын
kzbin.info/www/bejne/ppq1fHSBn5Z0rrM
@JasonsLabVideos7 ай бұрын
@@ericyost5287 This has been fixed :)
@ericyost52877 ай бұрын
@@JasonsLabVideos nice. When was it fixed?
@richcreedy4118 Жыл бұрын
i found if you want to do anything serious, then TP-link isn't the best
@attilazk7 ай бұрын
It all depends on how serious you want/need to go. Anyway, the issue was only on this specific device and even this was solved with a new firmware in short time. Generalising statements like "this is $hit" is just as dumb as saying any some brand as "super safe" (especially at TP-Link price points).
@daltonschrader8328 Жыл бұрын
Their switches and APs are awesome. Routers not so much