Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webfiltering makes LAN for guests accessible

Hello

I have a Sophos UTM home edition running. It's mostly running well down to one point, that doesn't work the way it should.

To the setup.
I have 3 interfaces.
1x External (WAN)
2x Internal (1x LAN / 1x Guest)

Now, as long as I'm using webfiltering only for one of the two internal networks, everything is good. The guest network cannot get to the LAN portion of the network.
As soon as I add the guest network to the webfiltering, it makes devices on the guest network able to get to devices on the LAN as long as you know the IP address of the devices on there - which is unacceptable.

I've been trying all kinds of things and been binging around a lot - but not found a solution for this. 
At the time, either I leave one of the two internal networks unfiltered and the networks are separated, so not one from one network can get to the other - or - I have both internal networks be filtered, but devices from one network can access devices on the other network.

I've set the webfilter to run the transparent mode - don't want to use the standard mode.

Does anyone know how I can make it possible, that both internal (lan / guest) are filtered without opening them up to each other?

Thanks

Mike


This thread was automatically locked due to age.
Parents
  • That's disconcerting... 

    Have you tried VLANs? Subnets?
  • VLANs shouldn't matter, since I'm using 2 different interfaces...
    All interfaces are in different subnets.

    Let me try 'drawing it out' for you.

    When only one interface / network is being filtered:

                                         _____________________________
                                       |                Sophos UTM                   |
      WAN interface ---------| Firewall, NAT, ===> Webfiltering   |
                                       |______________|______________|
                                               |                                 |
                                               |                                 |
                                      Interface Guest              LAN interface
                                        (unfiltered)                    (filtered)

                                                        
                                          the two cannot talk to each other



    When both interfaces / networks are being filtered:

                                         _________________________
                                       |                Sophos UTM           |
      WAN interface ---------|           Firewall, NAT, etc.        |
                                       |                       ||                    |
                                       |                       \/                    |
                                       |               Webfiltering             |
                                       |_________________________|
                                                  /                       \
                                                 /                         \
                                                /                           \
                                               /                             \
                                      Interface Guest          LAN interface
                                        (filtered)                    (filtered)

                                                        
                                          the two can talk to each other






    What I'm trying to do: (and which I'm not able to get done)

                                         _________________________
                                       |                Sophos UTM           |
      WAN interface ---------|           Firewall, NAT, etc.        |
                                       |                       ||                    |
                                       |                       \/                    |
                                       |               Webfiltering             |
                                       |_________________________|
                                                  /                       \
                                                 /                         \
                                                /                           \
                                               /                             \
                                      Interface Guest          LAN interface
                                        (filtered)                    (filtered)

                                                        
                                          the two cannot talk to each other


    Hope that makes sense.

    Mike
Reply
  • VLANs shouldn't matter, since I'm using 2 different interfaces...
    All interfaces are in different subnets.

    Let me try 'drawing it out' for you.

    When only one interface / network is being filtered:

                                         _____________________________
                                       |                Sophos UTM                   |
      WAN interface ---------| Firewall, NAT, ===> Webfiltering   |
                                       |______________|______________|
                                               |                                 |
                                               |                                 |
                                      Interface Guest              LAN interface
                                        (unfiltered)                    (filtered)

                                                        
                                          the two cannot talk to each other



    When both interfaces / networks are being filtered:

                                         _________________________
                                       |                Sophos UTM           |
      WAN interface ---------|           Firewall, NAT, etc.        |
                                       |                       ||                    |
                                       |                       \/                    |
                                       |               Webfiltering             |
                                       |_________________________|
                                                  /                       \
                                                 /                         \
                                                /                           \
                                               /                             \
                                      Interface Guest          LAN interface
                                        (filtered)                    (filtered)

                                                        
                                          the two can talk to each other






    What I'm trying to do: (and which I'm not able to get done)

                                         _________________________
                                       |                Sophos UTM           |
      WAN interface ---------|           Firewall, NAT, etc.        |
                                       |                       ||                    |
                                       |                       \/                    |
                                       |               Webfiltering             |
                                       |_________________________|
                                                  /                       \
                                                 /                         \
                                                /                           \
                                               /                             \
                                      Interface Guest          LAN interface
                                        (filtered)                    (filtered)

                                                        
                                          the two cannot talk to each other


    Hope that makes sense.

    Mike
Children
No Data