Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Internet only access

    Firewalling
    2
    2
    694
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      ttanemori
      last edited by

      I have VLAN2 just for VoIP.

      Any to Any works, but I want to restrict the access to other VLANs.

      My idea is like this:

      On VLAN2 interface, allow VLAN2 net to "Internet". But I do not see an option to choose "Internet."

      "WAN net" did not work.

      Is it something like 0.0.0.0./32?

      Deny from VLAN2 net to the other VLANs net could be possible, but there are many other VLANs.

      May I have some advices?

      Thank you very much.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Create an alias, call it othervlans for example.. Put in this alias all the vlans you don't want this vlan to go to.  Then in the dest put ! othervlans (! = NOT)  This way as long as they are not going to these vlans they will be allowed.

        see attached example - this is my guest wireless vlan

        guestvlan.png
        guestvlan.png_thumb

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.