Jump to content

Recommended Posts

Posted (edited)

Hey All,

 

Hoping you can help as I'm really unsure what I'm doing here. I have two sites with the following IP ranges:

 

Site A: 192.196.91.0/24 Site B: 192.168.200.0/24

 

I want site B to be able to ping site A but not the other way around. I also need the firewall rule controlling this to be on Site B's side of things.

 

I've setup the following which I thought should work but I can still ping from site A to B? The IPv4 "Source" group has it selected as the 192.196.91.0/24 network and on the destination I've tried having it just set to Any network and have also manually added 192.168.200.0/24 but to no avail.

 

Any help from someone much more in the know than me would be most appreciated :)

 

[ATTACH=CONFIG]70029[/ATTACH]

 

[ATTACH=CONFIG]70030[/ATTACH]

Screenshot 2023-10-10 at 15.33.39.png

Screenshot 2023-10-10 at 15.33.52.png

Edited by AB_IT
Posted
If you are testing by pinging the firewall internal IP on A from B then you may get misleading results. Not a Unifi user but generally you would setup a policy to deny source IP range A access to Destination IP range B. This can be added on either side really. You may need to pay attention to the interfaces too - if traffic is passing over VPN, the VPN interface may need to be set specifically in some of these policies.
Posted
If you are testing by pinging the firewall internal IP on A from B then you may get misleading results. Not a Unifi user but generally you would setup a policy to deny source IP range A access to Destination IP range B. This can be added on either side really. You may need to pay attention to the interfaces too - if traffic is passing over VPN, the VPN interface may need to be set specifically in some of these policies.

Thanks for your help, not doing that I'm pinging a seperate device on both networks to test.

 

I thought that's what I've done with the above rule to basically drop all source traffic from A to B?

Posted
I thought that's what I've done with the above rule to basically drop all source traffic from A to B?

 

I'm assuming that was in reference to the fact you have it set as "Lan In" rather than WAN/Internet etc, depending on what it's called on Unifi

 

If the second network isn't defined as a local/LAN one the pings would be coming in via the WAN/Internet interface normally. e.g. A client, goes ping, goes to A firewall, out via WAN/Internet interface, goes to B firewall in on WAN/internet interface and should be dropped there

 

Steve

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...