Devices in mgmt VLAN reachable by VPN and local Clients

Options
2»

All Replies

  • Zyxel_Tina
    Zyxel_Tina Posts: 642 image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments

    Hi @Sergi330,

    The problem you're seeing is due to how the device handles traffic blocking: traffic between segments is blocked by one rule, but traffic to the device itself requires a separate "to device" rule. For example:

    image.png

    Please note that for this rule, it is important to specify the correct port since selecting "Any" will block all traffic from that segment to the device. As shown in the image above for Protocol 443 (USG LITE 60AX web GUI port), this blocks segment IPs from accessing the web interface.

    We appreciate your patience and understanding!

    Zyxel Tina

  • Sergi330
    Sergi330 Posts: 10 image  Freshman Member
    First Comment Friend Collector First Anniversary
    edited February 14

    Hi @Zyxel_Tina ,

    Thanks for the instructions. Are these rules in addition to the previous two?

    I confirm that now I can't reach the router's GUI this way. But what about the access points? Clients connected to Wi-Fi can still reach them (VPN and wired clients it's ok).

    Thanks!

  • Sergi330
    Sergi330 Posts: 10 image  Freshman Member
    First Comment Friend Collector First Anniversary

    Specifically, clients connected via Wi-Fi to VLAN 10 reach the GUI of the access point to which they are connected, not the other ones present on the site.

Nebula Tips & Tricks