Block traffic on usg40 for different networks

alexia_net
alexia_net Posts: 9  Freshman Member
First Comment
edited April 2021 in Security
Hi. I have a situation on my new USG40 firewall. The default network on this firewall is 192.168.1.0 / VLAN1. I have created a new VLAN, which got as IP newtork 192.168.11.0.
Now I want to block the traffic betwenn 192.168.1.1 and 192.168.1.11 and vice-versa.
I have created 2 rules in POLICY CONTROLL. Denying the traffic both ways, but it seems that the rules do not work. The rules are assigned with the highest priority. 
I can still ping 192.168.11.1 from 192.168.1.0 network.

The only think I can think of is that the management network, has access to whatever other network defined. Hoever this is kind a strange. I do not think that it can be like this. So probably I am doing something wrong.
Any tips much appreciated. Thank you!

#Biz_Security_January

Comments

  • alexia_net
    alexia_net Posts: 9  Freshman Member
    First Comment
    Sorry, one mistake. I want to block the traffic between 192.168.1.0 and 192.168.11.0
    :)
  • alexia_net
    alexia_net Posts: 9  Freshman Member
    First Comment
    It has to do with the order the FW read the rules.

Security Highlight