Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VLAN Rules

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    7 Posts 4 Posters 554 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • natethegreat21N
      natethegreat21
      last edited by

      So I have been having an issue trying to find the best way to set up firewall rules for my VLANS to stop talking to each other. Do I need to block all the VLANs individually as shown attached or is there a more simple way of doing this? There are 2 VLANS that need access to the others such as the Backup VLAN needing access to all the VLANS (VEEAM) and ActiveXperts for network monitoring. Thank you!! VLANS.PNG

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @natethegreat21
        last edited by NogBadTheBad

        @natethegreat21 create an alias with your subnets in that you want to block then do something like this:-

        Screenshot 2022-11-22 at 19.04.15.png

        NB I have IPv4 & v6 on my vlans.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        natethegreat21N 1 Reply Last reply Reply Quote 0
        • natethegreat21N
          natethegreat21 @NogBadTheBad
          last edited by

          @nogbadthebad Okay will do and just wondering if the way I set this up if it would work or not please

          NogBadTheBadN johnpozJ 2 Replies Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad @natethegreat21
            last edited by

            @natethegreat21 it would, the only issue would be if when you added another vlan you'd need to apply another rule to each interface, rather than just adding the new subnet to the alias.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            natethegreat21N 1 Reply Last reply Reply Quote 2
            • natethegreat21N
              natethegreat21 @NogBadTheBad
              last edited by

              @nogbadthebad I see what you mean. Thank you so much!

              J 1 Reply Last reply Reply Quote 0
              • J
                Jarhead @natethegreat21
                last edited by

                @natethegreat21
                Most on here just create an alias for all RFC1918 space.
                That way you wouldn't even need to add a new subnet to the alias since it already covers all private IP addresses.

                1 Reply Last reply Reply Quote 2
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @natethegreat21
                  last edited by

                  @natethegreat21 you can for sure block specific as you have done. But as mentioned its easier to just create an alias that either contains your specific networks, or just all the rfc1918 networks.

                  You could create an alias with your full prefix for your IPv6 space. Problem with dynamic ipv6 is that could change - which is one of the reasons I prefer tunnel from HE, I get a /48 to do with what I will and it doesn't change.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.