This is so cool, but I am not comprehending something about LAN configuration on the FW Gold

Comments

3 comments

  • Avatar
    Chris Thomas

    With the Firewalla platform, it helps to remember that by default, all outbound traffic from a network is permitted (default allow).  And stateful firewalls track sessions, so it's all about who 'initiates' the connection.

    Therefore, you would create a firewall rule to block 'Traffic to All Local Networks' from 'LAN-JUNK'.  This would allow devices in LAN-PRIMARY to initiate connections to devices in LAN-JUNK, but would not allow devices in LAN-JUNK to initiate connections to devices in LAN-PRIMARY.

     

    Rules > Add Rule

    Action = Block
    Matching = Traffic to All Local Networks
    On = LAN-JUNK
    Schedule = Always

     

    0
    Comment actions Permalink
  • Avatar
    Scott

    That helped me sort it all out, I had made a set of rules that actually did all that but as it turns out your suggestion was a much simpler way. Its a learning curve but going well.

    0
    Comment actions Permalink
  • Avatar
    Chris Thomas

    Scott,

      Excellent, happy to help.

     

    ..ct

    0
    Comment actions Permalink

Please sign in to leave a comment.