Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Creating a Firewall Rule VLAN to WAN

Hi, 

 

I am used to the XG series and I think I am confusing myself lol, hence this post.

 

I have created multiple VLANS on 2 interfaces, i.e. VLAN 2, 4, 6, on eth0 and VLAN 8, 10 & 12 on eth5.  I also created masquerading rules for all VLANS to the uplink interfaces.

 

Now I want to create firewall rules and groups to make everything look right, I started to create the basic ones first.  i.e. VLAN 2 to WAN on any service.  However I am not sure how to add the WAN aspect.  Typically you could add any in the destination however if I do this won't it allow VLAN 2 to talk to any of the other VLANS?  I then thought to add the WAN interface but then I am not sure if I want to add (address) (broadcast) or (network).  I would think that address is the one to add but then I started hesitating and thought I would drop a line to see if this is what I want.

 

On the XG these would simply be zones but in the UTM I am not a 100% confident on this.



This thread was automatically locked due to age.
  • Typically, the WAN would be the internet so destination would be Internet IPv4 or Internet IPv6

    Watch you don't get caught out by the proxies!!

  • There are special predefined network objects called "Internet IPv4" and "Internet IPv6" (or simply "Internet" if no IPv6 active).
    Those are meant exactly for what you want.

    Take care that you don't allow traffic via Webfilter, etc., because Proxies come before manual firewall rules.

    Also read BAlfsons' "Rulz" pinned to the "General Discussion" forum, they are a "must read" when dealing with the Sophos UTM.

  • Hi,

    if you take "any" for destination, yes VLAN 2 can see all other VLANs.

    You have to take "WAN Network", because you want to see the whole network and not just a specific address (WAN Address)

  • Hallo Tom,

    You're right to warn him about using the "Any" object, but the "External (Network)" object only includes the subnet defined on the External interface.  See Louis' post above.

    Cheers - Bob