Forum Discussion
Block traffic between two VLAN in one direction
I want to block all the incoming traffic on the VLAN 40 from the VLAN 20. I have a Firewall Rule in Global context with the next properties:
Source:
- Address/Region: 10.10.20.0/24
- Port: Any
- VLAN: Any
Destination:
- Address/Region: 10.10.40.0/24
- Port: Any
- Protocol: 6(TCP)
Action: Drop
Also I applied this firewall rule to the Self IP 10.10.20.252 with the same results, still traffic in both directions. Does anyone has any idea what is the best way to do this?
Best Regards,
5 Replies
- Stanislas_Piro2
Cumulonimbus
Hi,
- This rule applies only on TCP connections...
- Rules assigned on Self IPs are only to secure access to the self IP. to filter routing between VLANs, enable it on Global context, Route Domain or virtual server.
- Stanislas_Piro2
Cumulonimbus
AFM rule must drop the connection... if not, there may be a configuration issue (wrong network / net mask)
if AFM rule is enabled on Global context and action is drop, t may be dropped.
- Mathew
Cirrus
Can you make sure the default forward any any is marked to drop in AFM. Once you do this it will work.
Please follow the below
On the Main tab, click Security > Options > Network Firewall. The Firewall Options screen opens. From the Virtual Server & Self IP Contexts list, select the default action Drop for the self IP and virtual server contexts. Click Update. The default Virtual Server and Self IP firewall context is changed.
Make sure you have clear permit rules in place before doing this.
Please refer VLAN-KEYED CONNECTIONS in Local Traffic manager for generic solutions for different VLANS not to communicate, However in this case - This is purely specific to two VLANs on not being able to communicate.
If you put up all the protocols and still they are able to communicate - Your might problem might be with the configuration, IPs, SUbnet masks.,
- OCC_Ops_68605
Nimbostratus
Besides the firewall rule in Global context we have a Virtual Server Wildcard Forwarding, I try putting this rule before the "any to any" rule with the same results.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com