Why the security policy cannot block the same LAN subnet client?
Zyxel_Jeff
Posts: 1,165 Zyxel Employee
in Networking
Scenario :
The user may encounter a situation when creating a security policy to block the same LAN subnet (or LAN interface groups such as ge4 and ge5 that belong to the same LAN group) for clients, but it's not working.
Answer :
This is by design. For example, if the user designates ge4 and ge5 as part of the same LAN group, the firewall will treat them as if there's an L2 dummy switch between the two GE interfaces. As a result, traffic transmitted on these two ports won't be processed by the security policy. The purpose of this design is to accelerate network efficiency.
Don't miss this great chance to upgrade your Nebula org. for free! https://bit.ly/4g2pS9L
Tagged:
0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 130 Nebula Ideas
- 90 Nebula Status and Incidents
- 5.4K Security
- 171 USG FLEX H Series
- 256 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 235 Service & License
- 372 News and Release
- 77 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 80 About Community
- 69 Security Highlight