Welcome, Guest. Please login or register.
Did you miss your activation email?
November 23, 2017, 01:29:17 AM

Login with username, password and session length

Visit the official Endian Community Mailinglist  HERE
13543 Posts in 4160 Topics by 5268 Members
Latest Member: Khmart
Search:     Advanced search
+  EFW Support
|-+  Support
| |-+  General Support
| | |-+  Policy implementation in VLANS
0 Members and 0 Guests are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Policy implementation in VLANS  (Read 235 times)
cmanriquezr
Jr. Member
*
Offline Offline

Posts: 1


« on: August 25, 2017, 03:43:17 AM »

I have the following scenario:

I have an admninistrable switch where I define the following Vlans 10, 20.30 and assign them as follows:

Port 1 untagged vlan 10 - access type
Port 2 untagged vlan 20 - access type
Port 3 untagged vlan 30 - access type
Port 4 untagged vlan 1, tagged vlan 10, 20, 30 - trunk type

In endian version 3.2.2, I also defined the same vlans 10, 20, 30 in the part of - Network - Interfaces - Vlans

Eth0.10 - green zone
Eth0.20 - green zone
Eth0.30 - green zone

In Endian, in the network configuration part, assign the interface eth0.10 to IP 30.0.0.254 in the green zone, which is the gateway for VLAN 10.

In the endian terminal at the command level assign:

- IP 40.0.0.254 to the virtual eth0.20 interface, which is the gateway.
- IP 50.0.0.254 to the virtual eth0.30 interface, which is the gateway.

Performing communication tests with the switch do the following:

First test:
- Device with IP 30.0.0.1 connected to port 1 (vlan 10) -> I was able to ping gateway 30.0.0.254.
- Applies policy in the areas of traffic between Internet to exit successfully.

Second test:
IP 40.0.0.1 computer connected to port 2 (vlan 20) -> I could not ping the gateway 40.0.0.254.
- Therefore I could not implement a policy to have Internet access if I did not reach my gateway.

So you can not apply policies for communication (allow and deny services) between Vlans.

Note:  This same scenario I have it implemented in another firewall other than Endian and it works for me, what do I lack?
Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Page created in 0.055 seconds with 18 queries.
Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Design by 7dana.com