News: This forum is now permanently frozen.
Pages: [1]
Topic: Firewall Not Allow Traffic from Different Networks  (Read 443 times)
« on: September 13, 2014, 20:17:31 »
0xAether *
Posts: 5

I have a fairly simple home network set up. First off I have a VMware ESXi server running some VMs. I have an Extreme Networks x250e-48t switch doing all of my routing between the several VLANs I have.

Right now I have a Juniper Networks firewall that I wish to get rid of and use a M0n0wall VM in place of it. Since I am only using one of the two network cards in my server, I decided to plug my cable modem into the second one. I installed M0n0wall and then put the first virtual network card into the "Default" VLAN and the second virtual network card onto the second physical network card of my ESXi server.

Everything seems to be working with it, except for one major problem. Any traffic from any VLAN except for the "Default" VLAN is getting blocked. Even though I set up a rule that says allow any protocol to any destination from any network (Not just the "Default" VLAN network).

I only can get online when I go on a machine that is on the "Default" VLAN. The network for the "Default" VLAN is 10.1.0.0/16 My PC is on the 10.8.0.0/16 network. The 10.5.0.0/16 network is for servers.

My question is how do I make m0n0wall accept any traffic for any of the VLANs I have and make it stop rejecting any LAN traffic rather than what it's doing right now (Only passing traffic from the 10.1.0.0/16 network)

http://i.stack.imgur.com/zxpRE.png - The Log file of the traffic that is being blocked.
http://i.stack.imgur.com/OSzhW.png - The LAN rules I have in place at the moment. The one that doesn't have a description is one that I made. It allows any traffic from any network originating for the LAN interface to any destination and to any port.
« Reply #1 on: September 19, 2014, 00:39:59 »
Lee Sharp *****
Posts: 517

Since m0n0wall is vlan aware, you have to make it recognize you vlans.  However, this could be an internal switching issue filtering you vlans.  But either way, anything outside of 10.1.0.0/16 will not be seen by m0n0wall unless it has a route there.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines