Forum Discussion

OCC_Ops_68605's avatar
OCC_Ops_68605
Icon for Nimbostratus rankNimbostratus
May 10, 2016

Block traffic between two VLAN in one direction

I want to block all the incoming traffic on the VLAN 40 from the VLAN 20. I have a Firewall Rule in Global context with the next properties:

 

Source:

 

  • Address/Region: 10.10.20.0/24
  • Port: Any
  • VLAN: Any

Destination:

 

  • Address/Region: 10.10.40.0/24
  • Port: Any
  • Protocol: 6(TCP)

Action: Drop

 

Also I applied this firewall rule to the Self IP 10.10.20.252 with the same results, still traffic in both directions. Does anyone has any idea what is the best way to do this?

 

Best Regards,

 

5 Replies

  • Hi,

     

    1. This rule applies only on TCP connections...
    2. Rules assigned on Self IPs are only to secure access to the self IP. to filter routing between VLANs, enable it on Global context, Route Domain or virtual server.
  • AFM rule must drop the connection... if not, there may be a configuration issue (wrong network / net mask)

     

    if AFM rule is enabled on Global context and action is drop, t may be dropped.

     

  • Can you make sure the default forward any any is marked to drop in AFM. Once you do this it will work.

     

    Please follow the below

     

    On the Main tab, click Security > Options > Network Firewall. The Firewall Options screen opens. From the Virtual Server & Self IP Contexts list, select the default action Drop for the self IP and virtual server contexts. Click Update. The default Virtual Server and Self IP firewall context is changed.

     

    Make sure you have clear permit rules in place before doing this.

     

  • Please refer VLAN-KEYED CONNECTIONS in Local Traffic manager for generic solutions for different VLANS not to communicate, However in this case - This is purely specific to two VLANs on not being able to communicate.

     

    If you put up all the protocols and still they are able to communicate - Your might problem might be with the configuration, IPs, SUbnet masks.,

     

  • Besides the firewall rule in Global context we have a Virtual Server Wildcard Forwarding, I try putting this rule before the "any to any" rule with the same results.