News
:
This forum is now permanently frozen.
m0n0wall Forum
>
m0n0wall Support (English)
>
Firewall/NAT
Topic: Multiple Network Isolation.
Pages: [
1
]
Topic: Multiple Network Isolation. (Read 1531 times)
Multiple Network Isolation.
« on: November 12, 2008, 20:17:19 »
jpm
Posts: 2
I have a Soekris 5501-70 with 4 Network interfaces configured in the following manner.
eth0 : WAN : Public IP DHCP
eth1 : LAN : 10.1.0.1/24
eth2 : OPT1 : 10.2.0.1/24
eth3 : OPT2 : 10.3.0.1/24
I've tried numerous combinations of Firewall rules to try and prevent the three private networks from talking to each other. However, regardless of my efforts any host on any of the private networks can always ping any host on any of the other private networks.
Can anyone explain to me how make it so each private network can see out to the internet but not see each other.
** Would like to add that all the private Subnets have their own switches and are not physically connected except at the Soekris box, obviously.
Thank you for any assistance
Jason.
«
Last Edit: November 12, 2008, 21:09:12 by jpm
»
Re: Multiple Network Isolation.
« Reply #1 on: November 12, 2008, 21:14:36 »
Fred Grayson
Posts: 994
You need Firewall: Rules for each interface blocking traffic to the other interfaces except the WAN.
--
Google is your friend and Bob's your uncle.
Re: Multiple Network Isolation.
« Reply #2 on: November 12, 2008, 21:27:40 »
jpm
Posts: 2
While I believe I've tried this .. I'll give it another go.
Thanks so much for the response.
Re: Multiple Network Isolation.
« Reply #3 on: November 13, 2008, 01:56:53 »
knightmb
Posts: 341
This may be easier, go to your firewall rules where you have the default rule on your LAN for example that is set for the source being "LAN net" and the destination is just *, * , * , etc.
Edit that rule and change the destination from "any" to "WAN address". Do that for all the other rules for the OPT1 and OPT2 and that should funnel all your LAN networks down the WAN only and they won't be able to talk to each other then (such as ping).
Radius Service for m0n0wall Captive Portal -
http://amaranthinetech.com
Pages: [
1
]