issues with understanding/get working L2 Isolation betwen fixed networks
We have just got an ATP800, and thrilled with it, but I'm still having issues with L2 isolation between physical ports.
Our current config port wise is:
Core | Peplink | VPN_Link |Workshop| CCTV| Wi-Fi | Pr_Failover | ZUKU|ge9|ge10|ge11|ge12|ge13|ge14
I want to isolate Wi-Fi, ZUJU, Workshop and CCTV, From Core. e.g. traffic from these networks should not cross into Core other than for the allow list.
As I understand things, putting 'Wi-Fi, Workshop, CCTV' into the member's list should be sufficient, possible for confirmation and correction if required, I have attached some picks which should explain.
I have read various Zyxel documentation on this, but it seems I'm missing something.
Thank you in advance. :)
Accepted Solution
-
Hi @cfts_ea ,
The "port" you configure is layer 3 IP interface.
So that you need to set interface Core to a ZONE(Object > ZONE), ex: Core ZONE.
And interfaces Workshop/CCTV/Wi-Fi/ZUKU into another ZONE, ex: ZONE1.
And then go to Security Policy > Policy Control to add rules,
rule1: From ZONE1 to Core, src: any, dst: address group of allow list, service: any, action: allow
rule2: From ZONE1 to Core, src: any, dst: any, service: any, action: deny.
1
All Replies
-
Hi @cfts_ea ,
The "port" you configure is layer 3 IP interface.
So that you need to set interface Core to a ZONE(Object > ZONE), ex: Core ZONE.
And interfaces Workshop/CCTV/Wi-Fi/ZUKU into another ZONE, ex: ZONE1.
And then go to Security Policy > Policy Control to add rules,
rule1: From ZONE1 to Core, src: any, dst: address group of allow list, service: any, action: allow
rule2: From ZONE1 to Core, src: any, dst: any, service: any, action: deny.
1 -
Sorry, and thank you, I only just got back to this I'd setup a Raspberry Pi, to do this, and will now look at seeing if this function can be implemented in the ATP, with the above info :)
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 202 Nebula Ideas
- 126 Nebula Status and Incidents
- 6.3K Security
- 515 USG FLEX H Series
- 328 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 288 Service & License
- 458 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 85 About Community
- 97 Security Highlight
Freshman Member
Master Member