cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
808
Views
5
Helpful
6
Replies

isolating a raspberryPi from local network except wan

linuxUser
Level 1
Level 1

Hello as the title reveals i try to block all local traffic to a raspberryPi, make it only accessable from the internet.

I want do so because of security reasons if someone get access to the raspberry

i try to archiev this with ACL on my cisco CBS250-8T-D switch.

can someone lead me a bit into the right direction?

my local subnet is 192.168.0.0/24

router is 192.168.0.1

the raspberry pi 192.168.0.15

the webserver is reachable whatever i try to block

thanks for your time

6 Replies 6

linuxUser
Level 1
Level 1

for any reason the attached screenshot was removed

You can try ACL source 192.168.0.0/24 to 192.168.0.15 (mask 255.255.255.255) deny from LAN 

If the device is in Layer 2 domain network time it does not even reach the gateway.

if the Pi need to be separated, use different VLAN and IP address and apply ACL.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

On my switch port 1 is a fritzbox, port 2,3 a nas, and port 8 is the raspberry pi
if i put port 1 and 8 in the same VLAN then my nas loose connection to the fritzbox
how can i add both VLAN to the router but seperate in same time localy?

how do i create such VLAN?

Rodrigo Diaz
Cisco Employee
Cisco Employee

hello @linuxUser  how are you applying the ACL and how's look like ?  if you are authenticating the device what you can enforce in the device' session a DACL 

i apply through web interface not in terminal, wich device should i authenticate?

Dacl is not aviable.. see screenshot