  • Good day,

    building a new XG7100 to replace a fortigate..

    I have 5 interfaces.. 2 of them i block them to access other network, but I want to allow them to access internet only...

    i dont find the way :(


  • LAYER 8 Global Moderator

    Rules are evaluated as traffic enters an interface from the network the interface is connected to.. Top down, first rule to trigger wins..

    If you want to block lan from going to vlan X, then at the top block lan net from going to vlan X on your lan interface, above the default any any rule that lets it go to the internet.

    Post up your interface rules - and can help you with what your doing wrong.

  • so.. something like that should then be ok ?

    allow some access and block the rest

    allow traffic between 2 interface, but allow only one machine to access the net

  • LAYER 8 Global Moderator

    Not sure what is in your aliases - but yeah that is how you would do it.

