Firewall Rule Bug

Comments

4 comments

  • Avatar
    Firewalla

    "Group" is a virtual way to apply rules to a set of devices. Members can move around.

    While VLAN is a physical group, that you can apply rules to them. Members can not move around.

    So in your case, guests can or can not access VLAN's, depending on the network layer rules that you place them. For example, 

    VLAN1: d1,d2

    VLAN2: c1, c4

    Group1: c1,d2

    When you apply rules to Group1, say can't access VLAN2, it will not work for c1, since c1 is in VLAN2 already.

     

    0
    Comment actions Permalink
  • Avatar
    SH

    Yes totally understand the group is a virtual way; maybe my explanation was incorrect.

    Management VLAN is seperate
    Guest VLAN is seperate 
    Lan VLAN is seperate

    Device c1 connects to Guest VLAN - no access to management vlan - Correct
    Device c1 connects to Guest VLAN - moved to another group that has access to managment VLAN via firewall rule - Works
    Device c1 connects to Guest VLAN and moved back to its original group that has no access to management VLAN- access still works, i would have thought i'd this point it should stop access.

    Right?

    0
    Comment actions Permalink
  • Avatar
    SH

    I am defo not going mad, just replicated this with 2 seperate VLANs + management VLAN

    d1 connected to VLAN1 - before firewall rule can access management LAN
    d1 connected to VLAN1 - applied firewall rule to block access to management LAN - Success, traffic dropped

    d2 connected to VLAN1 - before firewall rule can access management LAN
    d2 connect to VLAN2 - no rules, can access management LAN
    d2 connected to VLAN2 - apply firewall rule to block access to management LAN - failure, still can access management LAN

    Both VLAN's now have same rule to deny access, vlan1 is working blocking the traffic yet VLAN2 same rule but still can access managment LAN

    I am not going bonkers here, this thing is driving me nuts

    0
    Comment actions Permalink
  • Avatar
    GZ

    I did some similar tess and FWG seems reliable. In my tests, I move a computer to a different VLAN by connecting to a different SSID. Every time FWG behaved according to the rules. 

    0
    Comment actions Permalink

Please sign in to leave a comment.