Bridge Mode, separate plural VPN bridges on Firewalla Gold Pro
I am using the Gold Pro on the LAN/VLAN side a UniFi UDM SE, and have defined plural Bridges for different VLANs, and would like to define the blocking and pass rules between the untagged LAN and the VLANs in the UDM SE. This means the the individual bridges should let all traffic pass to the UDM SE, also if an IP address of another VLAN is the target, but that there shouldn't be a passing of such traffic between the VLANS within the Gold Pro. The below inserted advice to create a rule to block the IP range of a respective second VLAN from the bridge of a respective first VLAN would block such traffic completely, I assume, so that it wouldn't reach the UDM SE. Is this correct, and, if yes, is there a solution that achieves that all bridges are effectively independent bridges not allowing that traffic passes between them?
Rules for blocking VLANs
If you like to block vlan1 to access vlan2, a blocking rule that matches the local network - VLAN 1, apply to VLAN 2, will not work. instead, you can create a rule to block the IP range - (the subnet of VLAN 1), then apply it to VLAN 2. If you have several VLANs, Target List will make this easier.
-
Thank you Michael. However, it appears that I can specify in the bridge modes blocking rules only with respect to "ON" or "TARGET", but not with respect to "SOURCE". The latter would be needed to follow your advice according to my understanding. Or did I overlook or misunderstand something?
-
Hi Michael, yes, this should work, but the respective IP range would be blocked completely according to my understanding so that corresponding IP traffic would not reach the router (in my case the UDM SE). I would like to define the transmission and blocking rules for IP traffic between the LAN and VLANs in the UDM SE, not in the Firewalla device.
-
So you have UDM SE {router mode} > Gold Pro {bridge mode}. That's fine, as long as all devices connect downstream of Gold.
I would like to define the blocking and pass rules between the untagged LAN and the VLANs in the UDM SE. This means the the individual bridges should let all traffic pass to the UDM SE,That is what will happen.
also if an IP address of another VLAN is the target, but that there shouldn't be a passing of such traffic between the VLANS within the Gold Pro.
Not sure I follow you here. Each VLAN in Gold Pro will send traffic to the UDM SE and it will decide what to do. The traffic on each VLAN is separate from all the other VLANs in bridge mode.
-
Hi Michael, I think that your assumption at the end of your post is not correct. My understanding is that the IP traffic passes between the bridges of the Gold pro in bridge mode. Otherwise the advice
Rules for blocking VLANs
If you like to block vlan1 to access vlan2, a blocking rule that matches the local network - VLAN 1, apply to VLAN 2, will not work. instead, you can create a rule to block the IP range - (the subnet of VLAN 1), then apply it to VLAN 2. If you have several VLANs, Target List will make this easier.
at https://help.firewalla.com/hc/en-us/articles/1500012304202-Firewalla-Transparent-Bridge-Mode
makes no sense according to my understanding.
-
In router mode, all networks are managed by Firewalla. You can create a rule to block all local traffic from/to a specific network.
But in bridge mode, each bridge network are independent and it couldn't control local traffic. If you want to block traffic VLAN 1 to VLAN 2, you will need to Set 'MATCHING' to IP range and manually enter VLAN 1 IP range. If you need to block several VLAN networks access VLAN 2, you can set rules for those VLAN network seperatly or create a target list with those VLANs included. That could be easier. So far no other better choice for your case.
-
Hi Firewalla Team, thank you for your response, but I do not completely understand it. You write that in bridge mode each bridge network is independent. But what means "independent" in this context? If you have to set these blocking rules to prevent that traffic passes from VLAN 1 to VLAN 2 (within the Firewalla device I assume), I would say that the bridge for VLAN 1 and the bridge for VLAN2 are not independent.
Or do I understand your advice wrong?
Please sign in to leave a comment.
Comments
9 comments