Group rule that allows access to one LAN device and blocks all the rest

Comments

3 comments

  • Avatar
    Support Team

    Sorry for the confusion. If the devices are connected to the Firewalla AP7, you don’t need an extra switch to manage local traffic. Allow rules take precedence over block rules, and the failure to allow local IPs appears to be a bug on our side — our developers will work on a fix.

    In the meantime, please try adding the host you want to allow to the Media group’s Allowed Devices list: In the Firewalla App, go to Devices"Media" group. Scroll to the bottom and tap Allowed Devices. Add the host you’d like to allow. You can find more details in our Microsegmentation doc.

    Side note: There’s no need for the rule "ALLOW – Traffic to Internet, Outbound only, Always". In Router Mode, the inbound firewall is already enabled to block incoming traffic, and outbound traffic is allowed by default.

    0
    Comment actions Permalink
  • Avatar
    CaptainRewind

    Thanks. To clarify, the Media group is a mix of wired and WiFi clients, but the 10.0.0.10 is a Wired server on LAN 1.

    Thanks for the tip about not needing the rule "ALLOW – Traffic to Internet, Outbound only, Always". That will simplify my configurations and maybe be good for performance.

    I will look into the Microsegmentation. I did consider that very early on, but I couldn't get that configured the way I thought it would be, either. But I know a lot more about how these rules are supposed to work now than I did then, so I'll try it. 

    As for this problem, I did a little test where I checked iptables before and after making the changes. I see that this:

    Chain FW_FIREWALL_DEV_G_ALLOW

    comes before this:

    Chain FW_FIREWALL_DEV_G_BLOCK

    And that's where my Rules landed (which contain the ipset lists). iptables rules get applied in order, so I'm unclear on why this isn't working, actually. Of course, that was also based on a very cursory check. I'll try to parse that out better, those ipset groups and iptables rules can get very confusing very fast.

    Finally, my frustration. Sorry. It's all good, I know these things take work. I was indeed frustrated because I had spent so long setting up everything the way I wanted it and running into some roadblocks. But this is, I think, my one remaining issue, as I have already setup Pi-Hole in Docker per the article on this site (I had to make a few modifications to that process, I'll post my updates there). 

    Thanks!

    0
    Comment actions Permalink
  • Avatar
    Support Team

    Have you tried allowing the device under your media group? Let us know if it works for you.

    0
    Comment actions Permalink

Please sign in to leave a comment.