Community discussions

 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 116
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Block comms between VLANs except DHCP & Public IPs

Mon Apr 01, 2013 3:06 pm

Hi all,

Need help on how I configure RB750 to block comms between VLANs on internal IPs (10.x.0.0/16 subnets, 1 per VLAN) but allow DHCP (inc relay) and allow any traffic directed at public IPs which have NAT rules forwarding to a host on one of the VLANs.
Home user, working in IT. Home network is my lab.
ISP: Uno Communications
Hardware:
RB750 - Draytek Vigor 120v2 ADSL2+ Annex M
RB750Gr3 - Draytek Vigor 130 FTTC (VDSL) & RBD52G-5HacD2HnD
 
CelticComms
Forum Guru
Forum Guru
Posts: 1766
Joined: Wed May 02, 2012 5:48 am

Re: Block comms between VLANs except DHCP & Public IPs

Mon Apr 01, 2013 4:46 pm

Put a filter in the forwarding chain which drops everything (action=drop), then add filters above that one to permit (action=accept) each traffic type that you want to permit.
Interlynx | Networking and Information Security Consultants & Trainers | Email: routerlynx@gmail.com
BGP | EIGRP | OSPF | MPLS | Firewall | VPN | IPsec | Multicast | QOS | IPv4/6 | STP | VLAN | PON | AE | M2M | and more!

 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 116
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Re: Block comms between VLANs except DHCP & Public IPs

Tue Dec 24, 2013 9:03 pm

Edited:

I have this working now, except for one particular exception.

I have rules set as per below

Accept UDP 67-68 from 10.4.0.0/16 to 10.0.0.5
Drop all (other) from 10.4.0.0/16 to 10.0.0.0/8

I'm trying to add the following (above the drop rule), but it appears the below isn't allowing traffic to flow as desired.

Accept any from 10.4.0.0/16 to 10.0.6.1-2
(I've also tried adding Accept any from 10.0.6.1-2 to 10.4.0.0/16 as well even though my drop rule isn't configured to block this direction)

Any suggestions?
Home user, working in IT. Home network is my lab.
ISP: Uno Communications
Hardware:
RB750 - Draytek Vigor 120v2 ADSL2+ Annex M
RB750Gr3 - Draytek Vigor 130 FTTC (VDSL) & RBD52G-5HacD2HnD
 
User avatar
sjoram
Member Candidate
Member Candidate
Topic Author
Posts: 116
Joined: Sun Feb 10, 2013 8:47 pm
Location: Essex, UK

Re: Block comms between VLANs except DHCP & Public IPs

Sun Dec 29, 2013 11:15 am

Resolved - devices I was creating an exception for had a mis-configured gateway!
Home user, working in IT. Home network is my lab.
ISP: Uno Communications
Hardware:
RB750 - Draytek Vigor 120v2 ADSL2+ Annex M
RB750Gr3 - Draytek Vigor 130 FTTC (VDSL) & RBD52G-5HacD2HnD

Who is online

Users browsing this forum: No registered users and 16 guests