Nebula 20.00 - How could I block multple VLANs combinations via firewall?
Hello everyone,
inside an ORG I have 4 VLANs in this moment. It is essential that all of them DO NOT connect to VLAN1 and to ZyWALL.
For this reason I went here:
So I told the firewall to block these segments:
As you can see I miss to deny VLAN20 to VLAN50, VLAN20 to VLAN30, VLAN20 to VLAN60 and so on for the rest.
The problem is that I'm going to have also VLAN80 and VLAN90 for other services.
How can I isolate all the selected VLANs without remembering all the possible combinations? This could be time saving.
For example to have a list of VLANs:
- VLAN20
- VLAN30
- VLAN40
- VLAN50
- VLAN80
- VLAN90
that could go ONLY on the web without reaching anything else (including ZyWALL) inside the network.
Please let me know if I miss something somewhere 😎
All Replies
-
Hi @GiuseppeR,
To streamline your firewall rules and avoid multiple combinations, you can utilize Address Object Groups.
Instead of creating individual rules for each VLAN pair, you can:
- Define each VLAN subnet as an Address Object.
- Group all these objects into a single Address Object Group (e.g.,
Internal_VLAN_Group). - Create a single firewall rule: Set both the Source and Destination to that same group, and set the action to Deny.
This "Group-to-Group" rule will block inter-VLAN traffic among all members within that group using just one entry. Additionally, if you need to define specific exceptions or granular targets, you can create individual Address Objects for those destinations and prioritize them accordingly.
This gives you both the efficiency of grouping and the flexibility to manage specific traffic.
Zyxel Tina
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 228 Nebula Ideas
- 130 Nebula Status and Incidents
- 6.6K Security
- 645 USG FLEX H Series
- 357 Security Ideas
- 1.8K Switch
- 86 Switch Ideas
- 1.4K Wireless
- 54 Wireless Ideas
- 7.1K Consumer Product
- 303 Service & License
- 496 News and Release
- 93 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.9K FAQ
- 34 Documents
- 89 About Community
- 110 Security Highlight
Guru Member


Zyxel Employee
