Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How can I deny inter-VLAN routing

I have the following Network topology

WAN -> eth1 
Internal -> eth0 (default VLAN untagged) 10.10.10.0/24
Internal2 -> eth2 (VLAN 10 untagged) 10.10.20.0/24

On the switch, I simply have dedicated untagged ports for VLANs for the respective networks. My issue is I'm trying to isolate the internal networks from each other. I want to deny routing from Internal to Internal2 and vice-versa.

I've tried adding a No NAT rule from one network to the other but that didn't work. I also tried adding a firewall rule to drop packets from one network to the other and again i can still access it. I'm sure I'm missing something obvious that someone can point out.

 



This thread was automatically locked due to age.
Parents Reply Children
  • Yes both internal networks have their respective gateways as the IP defined in the Sophos i.e. 10.10.10.1 and 10.10.20.1

    I think I might have had the HTTP Proxy on earlier when I was testing. I'll have to try again to be sure, since I don't have a computer on the 2nd network at the moment.

  • Yes, if you have Web Protection enabled and what is passing is HTTP/S traffic, then that's it, as the traffic will be relayed by the proxy to the other network. You'll have to block that access through Web Protection policies if that's the case.

    Regards,

    Giovani

  • Hi, Perry, and welcome to the UTM Community!

    You might be interested in a document I maintain that I make available to members of the UTM Community, "Configure HTTP Proxy for a Network of Guests."  If you would like me to send you this document, PM me your email address. I also maintain a version auf Deutsch initially translated by fellow member hallowach when he and I did a major revision in 2013.

    Cheers - Bob