[USG Flex H] - Policy Control - Wrong Source/Destination Group




Hello everyone,
I have created an group object that contains other groups.
When I configure it as Source/Destination of a Policy Control, seems that is presented only one group of these (seems always the last group in the list).
Seems that is disappeared the "ALWAYSDenyWAN" group and in this case I don't know if is only a visual bug or really the "ALWAYSDenyWAN" group is not present (obviously I can check it from the log).
Thank you
All Replies
-
OK, I've checked the log and seems that both sub-groups hint the rule; so into the main group there are really two sub-groups but into the Policy Control view seems that only one group is reported (only the last in the list).
0 -
Yes just a display limitation really I don't like the idea of doing groups in a group.
0 -
You're right, but I have:
- Some IoT devices that I need to connect to internet only for firmware upgrade (only few minutes per month) — DenyInternet;
- Some other IoT devices that never reach internet — AlwaysDenyInternetSo I define two rules:
- One rule (deactivated by default) that cover only the DenyInternet group, in which I allow only certain IPs and Port (to permit the upgrade);
- One rule that deny all traffic from the both groups — this rule is defined below the other rule.So, in this case:
- When an DenyInternet device try to reach internet and keep the first rule enabled, enter on this only for defined destination IPs; if the IP isn't in the allowed destination, the connection is denied by the second rule;
- When an AlwaysDenyInternet device try to connect to internet, is always denied because hint directly the second rule.And obviously both device types must reach internal devices and services
If I don't use the groups in group, I need to define more than 2 rules; one for DenyInternet allow dest ip, one for deny others dest IP, one for deny AlwaysDenyInternet type.
You can do this better?
Thank you
0 -
If that works for you I'm not going to say its wrong.
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 196 Nebula Ideas
- 123 Nebula Status and Incidents
- 6.3K Security
- 480 USG FLEX H Series
- 313 Security Ideas
- 1.6K Switch
- 83 Switch Ideas
- 1.3K Wireless
- 45 Wireless Ideas
- 6.8K Consumer Product
- 284 Service & License
- 450 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 93 Security Highlight