Hello!
I have setup my UTM with several VLANS alongside with the default internal lan (this is untagged).
As I have understood the UTM creates routes to the different interfaces itself and the only thing
I have to do is to allow traffic through the firewall from one interface to another.. Am I right?
I have this issue right now;
Currently I have a computer connected (the one I am writing this text on) to the default internal lan that was
setup during the installation. As I have understood this is totally untagged, no VLAN at all.. I also have set up VLAN 10 on the same physical interface.
From version 9.3x the UTM seems to support this configuration.. I have a second VLAN set up (VLAN 2), also on the same interface.
My switch is setup as following: (it is a Zyxel GS1910-24):
UTM connects to port 2 on the switch and this port (2) has
Ingress acceptance: Tagged and Untagged
Egress tagging: Untag Port VLAN
Port VLAN: 1
Allowed VLANs: 1,2,10
My first server is connected to port 3 on the switch and this port (3) has
Ingress acceptance: Tagged and untagged
Egress tagging: Untag Port VLAN
Port VLAN: 2
Allowed VLANs: 2
My other server is connected to port 10 on the switch and this port (10) has
Ingress acceptance: Tagged Only
Egress tagging: Untag Port VLAN
Port VLAN: 10
Allowed VLANs: 10 (I have also tried 1,10)
I have made a firewall rule that is accepting traffic from the internal lan (the untagged default lan) to VLAN 10 with "Web surfing" (port 80, 443 and so on..)
The issue I have is that I get "No route to host" from my sophos and the traffic is blocked..
On the first server (connected to port 3) the ingress acceptance is accepting both Tagged and untagged traffic, but the switch
will untag traffic from VLAN 2. In this case I also have a firewall rule that is accepting traffic from internal lan (the untagged default interface) to VLAN 2.
In this case I reach the web page on the server..
Can you see any misconfiguration in my case?
Is it any issues to route from the default internal lan that is totally untagged to a tagged VLAN?
When UTM creates it's routes does the UTM tag the traffic from the untagged internal lan to VLAN 10?
I think I am correct when configuring port 10 on the swith to only allow tagged traffic, or Am i wrong there?
This is only the beginning of my set up and in the end I think I will only accept tagged frames in my switch
so all traffic is tagged in some way, but currently I have the normal default internal lan that is untagged "enabled".
One more question;
Is it possible to disable the default internal interface (without VLAN) when using VLANs on the same interface?
Or what happens with the VLANs on that interface in that case?
Thanks in advance! Hope you understand my questions, otherwise ask!
This thread was automatically locked due to age.