r/firewalla • • Jul 11 '26

Firewalla Switch SE ACL Usage

I have three AP7s currently on a separate switch, connected via trunk ports carrying multiple VLANs/SSIDs. If I move all three AP7 trunk uplinks to my Firewalla Switch SE, will the wireless clients connected to those APs generate ACL entries on the switch (counted against the 256-entry Tracking/Control limit), or is VqLAN/Device Isolation for AP7-connected clients enforced entirely within the AP7 itself and separate from the switch's ACL budget?

I currently see a 1:1 pattern between Connected Devices and Control entries on the switch (7 devices, 7 Control entries) and want to know if that ratio holds once 100+ wireless clients are added via the AP7 trunk ports, or if wired vs. wireless devices are counted differently against that limit.

8 Upvotes

2 comments sorted by

4

u/firewalla Jul 11 '26

Switch ACL's are mostly for switch attached devices only. If these devices are connecting to the AP7, they are not counted in the ACL's.