Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Block destination host access from source host in LAN/one subnet

Hi,

WARNING: I am absolutely new to firewall :)

I use IP Host to cluster my LAN devices belonging to my single subnet 10.x.y.z. These IP Host (IP lists and ranges)  I want to use to block cross access. F.e. DHCP (guest devices 10.x.y.100 - 10.x.y.110) should not access any of my SERVER.

 

I created a firewall rule with the following content:

Action REJECT or DROP

Source Zone LAN
Source Network DHCP (Host IP Range)

Destination Zone LAN
Destination Network SERVER (Host IP List)
Services ANY

but ... I can still access from a DHCP host any SERVER host.

Is it possible to achieve, what I am aiming for with only IP Host or do I have to go the ZONE / VLAN route?

Cheers

 

 



This thread was automatically locked due to age.
Parents
  • Norbert,

    if clients and servers are on the same subnet, traffic will never hit the Firewall so you cannot block/allow traffic.

    In oder to filter traffic by layer 3 and 4, you have to move your servers or clients to another subnet.

    Regards

Reply
  • Norbert,

    if clients and servers are on the same subnet, traffic will never hit the Firewall so you cannot block/allow traffic.

    In oder to filter traffic by layer 3 and 4, you have to move your servers or clients to another subnet.

    Regards

Children
No Data