Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

VLAN Firewall Rule Issue

Hi All,

I have configured VLAN on LAN; it is configured as below

LAN =192.168.0.0/24

VLAN 10 = 192.16.100.0/24

VLAN is configured OK, i can do what I want also clients on the VLAN are getting the correct IP. I have 2 issues & I apologies I am not a pro on XG firewall learning it.

 

1. I have configured a firewall Rule for VLAN, the VLAN clients are not hitting the rule instead bypassing through default rule. Rule for VLAN is configured as below :

=========================

Sources Zone = LAN 

Source Network/Devices = #Port1.10

=========================

Destination Zones = WAN

Destination Networks = Any

Services = HTTP/HTTPS

=========================

Identity 

User group = Any user

=========================

Scan FTP

Scan HTTP

========================

Rule Position = Top

What is it that I am doing wrong ?

 

2. Second issue I have is Clients on VLAN that need to access a resource that is on LAN on a specific IP. Atm they cant access it which I understand why, do i create a static route from PORT1.10 to the specific LAN IP

I will appreciate your help! 

Thank You

Alam



This thread was automatically locked due to age.
Parents
  • Hi Hammer,

    Please post a picture of the configuration and the firewall rule. For communicating VLAN with LAN, configure a FW-rule:

    Source: LAN // Networks: 192.168.0.0/24, 
    Destination: LAN // Networks: 192.16.100.0/24, 
    What: Any Service
    Action: Accept

    Vice versa.

    Hope that helps.

  • Also I don't want communication between the 2 networks. There is only one IP I need VLAN access to not the whole of the subnet, the firewall rule is required for more or less to control access   

  • Alam,

    1. Remove the source host port1 from the rule

    2. Create a firewall rule from vlan to LAN and add destination host the LAN ip you need to access.

    Thanks

  • Hi Luk

    I don't think I understand what you said :( sorry. 

  • 1. I have configured a firewall Rule for VLAN, the VLAN clients are not hitting the rule instead bypassing through default rule. Rule for VLAN is configured as below :

    Remove the Source Network/Devices = #Port1.10

    2. Create a firewall rule from vlan to LAN and add destination network/devices  the LAN ip you need to access to.

    If you do not understand, please upload a network diagram.

    Regards,

  • Thanks for the reply. I dont have a diagram but ask me what you need to know I will try my best to answer. In response to what you said

    1. I have configured a firewall Rule for VLAN, the VLAN clients are not hitting the rule instead bypassing through default rule. Rule for VLAN is configured as below :

    Remove the Source Network/Devices = #Port1.10

    By doing so the LAN traffic hits that Rule , All i want is just the VLAN traffic to hit the rule so I can apply different web policy to it

    LAN = 192.168.0.1 

    VLAN = 192.16.100.1 

    I don't want any communication between the 2 networks,apart from one IP on internal LAN which is 192.168.0.55

     

Reply
  • Thanks for the reply. I dont have a diagram but ask me what you need to know I will try my best to answer. In response to what you said

    1. I have configured a firewall Rule for VLAN, the VLAN clients are not hitting the rule instead bypassing through default rule. Rule for VLAN is configured as below :

    Remove the Source Network/Devices = #Port1.10

    By doing so the LAN traffic hits that Rule , All i want is just the VLAN traffic to hit the rule so I can apply different web policy to it

    LAN = 192.168.0.1 

    VLAN = 192.16.100.1 

    I don't want any communication between the 2 networks,apart from one IP on internal LAN which is 192.168.0.55

     

Children