Page 1 of 1

Isolate VLAN

Posted: 27 Sep 2021 11:21
by lanwifi
Hello,

I created a new VLAN 20 for GUEST access:

Image

The new VLAN 20 will be NATed before goes to Internet with 192.168.1.100 address.

I want that the new 192.168.2.0/24 network could not access to the default (VLAN 1) 192.18.1.0/24 network.

Is it possible to create some ACL or firewall rules in the OS6350? The new GUEST network will only have access to Internet.

I will appreciate your help.

Best regards.

Re: Isolate VLAN

Posted: 03 Oct 2021 03:36
by silvio
yes. You can write a policy condition (source ip 192.168.2.0/24 destination ip 192.168.1.0/24) and a deny-action... and use both in a rule.
You will find samples here in the forum (or in the guides).
Best regards
Silvio