Hi,
I am *finally* getting around to putting this firewall into production @ my house. I have a question regarding access to the Admin interfaces from separate zones. I have provisioned all of my network gear forever with a completely separate subnet for admin access (which is the most common practice out there). This makes it simplistic to manage access with lists, etc.. You'll find the majority of the internet provisioned this way.
I have a MGMT zone and other zones as well. I have granted another zone access to the MGMT zone, but I still cannot reach the Admin interface unless I also give Admin interface access to the originating zone. This allow the originating zone Admin access on the MGMT zone as well as the originating zone's IP address too though. I have created more detailed firewall rules to block other devices in the originating zone to not be able to get to the Admin interface on it's own router interface, but this seems very counter-intuitive to me.
Is there a way to just allow Admin access to the host group in another zone without also allowing Admin access on the other zone's interface?
Thanks,
Greg
This thread was automatically locked due to age.