Issue: Created a 2nd “separate zone” wireless network, but unable to browse internet and firewall repeatedly reports “country blocked” regardless of website being accessed.
I can successfully see new wireless network from devices/laptops, and can successfully connect to the wireless network if the device/laptop is in whitelist. Where the failure seems to be is between the device/laptop and the New Wireless Network’s gateway. I am unable to ping the IP of the gateway. The firewall logs show the devices/laptops being “Country Blocked”, UDP and TCP, for any internet address including the gateway itself. If I disable “Country Blocking”, then I am able to browse the internet from the new wireless network but still unable to ping gateway. Same websites are accessible (no Country Blocking issue) from LAN and other two existing wireless networks, and all can ping respective gateways.
I am sure I have something misconfigured, but cannot locate the problem.
More details below:
UTM Model: SG230
Wireless Appliance: AP30
Firmware version: 9.409-9
There are 2 existing wireless networks (“employee” bridged to AP LAN, and “guest” separate zone) that are working flawlessly. I needed a second “guest” wireless network. I performed the following:
- Created new wireless network (mostly mimicking settings of current guest WiFi), making sure to select Separate Zone, client isolation enabled, and MAC filtering “Whitelist” enabled.
- Created appropriate MAC Address Definition group for whitelist.
- New “wlan2” interface was created. Made sure IP, netmask etc., was correct.
- Created new DHCP pool (making sure IPs were correct, and have DNS1 and GW pointing to same subnet x.x.x .1).
- Added firewall rule and turned on:
- Source: New Wireless Network (network)
- Services: Web Surfing
- Destinations: Any
- Allow
- Log traffic enabled
- Created NAT Masquerading Rule:
- Network: New Wireless Network (network)
- Interface: External (WAN)
- Use address: <<Primary address>>
- Added New Wireless Network (network) to DNS Global tab > Allowed Networks.
This thread was automatically locked due to age.