USG LITE 60AX vlan firewalling



Hello, just a quick question: Does the USG LITE 60AX support firewall rules between vlans that are on the lan side of the device other than then the toggle for "Guest Network"?
I know that the SCR 50AX can't do that, because I have a SCR 50AX and I have tried and there was also a question about this on the forum. But I couldn't find this information in regards to the USG LITE 60AX.
Best Answers
-
Hi @best_heygman,
USG Lite 60AX supports entering customized IP addresses/CIDRs to allow/deny traffic.
For example, my LAN is 192.168.100.0/24 and my VLAN 10 is 192.168.10.0/24. Here's my policy to block these two subnets from communicating:
In addition, you need to set two denial rules for this purpose.
Zyxel Melen0 -
And the rules also work and block the traffic? I can create rules between vlans also on the SCR 50AXE, they just don't do anything. Same as with this user here: https://community.zyxel.com/en/discussion/24318/scr-50axe-firewall-rules-for-vlan-segmentation-not-working/p1
0
All Replies
-
It might be best to look at FLEX H models
0 -
Yeah, I thought about the Flex 50H. The thing is that the firewall is for home use and Web Content Filtering is important. With the lite 60ax I would be at 200€ for the device and 50€/year for the content filter license. That's ok for home use.
With the flex 50h I would be at 450€ for the device plus 200€ for an access point plus a couple of hundred Euros for the gold pack license per year, because web filtering is not available on the entry defense pack.
You know, I can't explain that I have to spend that much money just to properly firewall my old laptop that acts as a server. If web filtering was in the entry defense license, then maybe. But the gold license is kinda much.
0 -
I think if the LITE 60AX doesn't allow for firewall rules between the vlans, I'd build something like:
Internet - SCR50AX - DMZ - LITE60AX - Home
Rather than buying a Flex H + acces point + gold license.
0 -
Hi @best_heygman,
USG Lite 60AX supports entering customized IP addresses/CIDRs to allow/deny traffic.
For example, my LAN is 192.168.100.0/24 and my VLAN 10 is 192.168.10.0/24. Here's my policy to block these two subnets from communicating:
In addition, you need to set two denial rules for this purpose.
Zyxel Melen0 -
And the rules also work and block the traffic? I can create rules between vlans also on the SCR 50AXE, they just don't do anything. Same as with this user here: https://community.zyxel.com/en/discussion/24318/scr-50axe-firewall-rules-for-vlan-segmentation-not-working/p1
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 157 Nebula Ideas
- 106 Nebula Status and Incidents
- 5.9K Security
- 327 USG FLEX H Series
- 286 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 257 Service & License
- 400 News and Release
- 86 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.8K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 78 Security Highlight