Welcome, Guest. Please login or register.
Did you miss your activation email?
Friday 29 March 2024, 04:24:22 am

Login with username, password and session length

Download the latest community FREE version  HERE
14247 Posts in 4376 Topics by 6490 Members
Latest Member: maquino
Search:     Advanced search
+  EFW Support
|-+  Support
| |-+  General Support
| | |-+  Policy implementation in VLANS
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Policy implementation in VLANS  (Read 5773 times)
cmanriquezr
Jr. Member
*
Offline Offline

Posts: 1


« on: Friday 25 August 2017, 03:43:17 am »

I have the following scenario:

I have an admninistrable switch where I define the following Vlans 10, 20.30 and assign them as follows:

Port 1 untagged vlan 10 - access type
Port 2 untagged vlan 20 - access type
Port 3 untagged vlan 30 - access type
Port 4 untagged vlan 1, tagged vlan 10, 20, 30 - trunk type

In endian version 3.2.2, I also defined the same vlans 10, 20, 30 in the part of - Network - Interfaces - Vlans

Eth0.10 - green zone
Eth0.20 - green zone
Eth0.30 - green zone

In Endian, in the network configuration part, assign the interface eth0.10 to IP 30.0.0.254 in the green zone, which is the gateway for VLAN 10.

In the endian terminal at the command level assign:

- IP 40.0.0.254 to the virtual eth0.20 interface, which is the gateway.
- IP 50.0.0.254 to the virtual eth0.30 interface, which is the gateway.

Performing communication tests with the switch do the following:

First test:
- Device with IP 30.0.0.1 connected to port 1 (vlan 10) -> I was able to ping gateway 30.0.0.254.
- Applies policy in the areas of traffic between Internet to exit successfully.

Second test:
IP 40.0.0.1 computer connected to port 2 (vlan 20) -> I could not ping the gateway 40.0.0.254.
- Therefore I could not implement a policy to have Internet access if I did not reach my gateway.

So you can not apply policies for communication (allow and deny services) between Vlans.

Note:  This same scenario I have it implemented in another firewall other than Endian and it works for me, what do I lack?
Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Page created in 0.031 seconds with 18 queries.
Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Design by 7dana.com