Restrict access on LAN to specific LAN IPs
Hello -
I've tried numerous combinations of firewall rules, but I've yet to have any success.
Problem: I have a local server at 192.168.1.2 and the only LAN IP addresses I want to be able to access that are 192.168.1.20-29 (Using MAC-IP binding to assign those outside of the DHCP pool).
Is this possible or is it not possible to restrict access within the LAN?
Any help or hints would be appreciated!
I've tried numerous combinations of firewall rules, but I've yet to have any success.
Problem: I have a local server at 192.168.1.2 and the only LAN IP addresses I want to be able to access that are 192.168.1.20-29 (Using MAC-IP binding to assign those outside of the DHCP pool).
Is this possible or is it not possible to restrict access within the LAN?
Any help or hints would be appreciated!
0
Accepted Solution
-
The clients & server is local in the same subnet.
So that the traffic will direct forwarding between clients & server instead of go into the interface
on USG.
Here the possible solution,
1. To control the access on host firewall rules of server.
2. Control on the switch, connect clients or server, which support IP ACL.
3. Or you need to set up bridge interface on USG and joins ports. The clients and server need to under different ports of USG. Then you can use firewall rule to control the access.
From my point of view, solution 1 & 2 will not impact the transmit throughput between clients & server, which is preferred.
5
All Replies
-
The clients & server is local in the same subnet.
So that the traffic will direct forwarding between clients & server instead of go into the interface
on USG.
Here the possible solution,
1. To control the access on host firewall rules of server.
2. Control on the switch, connect clients or server, which support IP ACL.
3. Or you need to set up bridge interface on USG and joins ports. The clients and server need to under different ports of USG. Then you can use firewall rule to control the access.
From my point of view, solution 1 & 2 will not impact the transmit throughput between clients & server, which is preferred.
5 -
Thanks - that makes sense. I'll focus in on solution 1 & 2.0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 100 Nebula Status and Incidents
- 5.8K Security
- 284 USG FLEX H Series
- 278 Security Ideas
- 1.5K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 251 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 86 About Community
- 75 Security Highlight