Block traffic on usg40 for different networks
Options
alexia_net
Posts: 9
Freshman Member
Freshman Member
Hi. I have a situation on my new USG40 firewall. The default network on this firewall is 192.168.1.0 / VLAN1. I have created a new VLAN, which got as IP newtork 192.168.11.0.
Now I want to block the traffic betwenn 192.168.1.1 and 192.168.1.11 and vice-versa.
I have created 2 rules in POLICY CONTROLL. Denying the traffic both ways, but it seems that the rules do not work. The rules are assigned with the highest priority.
I can still ping 192.168.11.1 from 192.168.1.0 network.
The only think I can think of is that the management network, has access to whatever other network defined. Hoever this is kind a strange. I do not think that it can be like this. So probably I am doing something wrong.
Any tips much appreciated. Thank you!
Now I want to block the traffic betwenn 192.168.1.1 and 192.168.1.11 and vice-versa.
I have created 2 rules in POLICY CONTROLL. Denying the traffic both ways, but it seems that the rules do not work. The rules are assigned with the highest priority.
I can still ping 192.168.11.1 from 192.168.1.0 network.
The only think I can think of is that the management network, has access to whatever other network defined. Hoever this is kind a strange. I do not think that it can be like this. So probably I am doing something wrong.
Any tips much appreciated. Thank you!
#Biz_Security_January
0
Comments
-
Sorry, one mistake. I want to block the traffic between 192.168.1.0 and 192.168.11.0
0 -
It has to do with the order the FW read the rules.0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 219 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.5K Security
- 588 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 298 Service & License
- 476 News and Release
- 91 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 102 Security Highlight