AB_IT Posted October 10, 2023 Posted October 10, 2023 (edited) Hey All, Hoping you can help as I'm really unsure what I'm doing here. I have two sites with the following IP ranges: Site A: 192.196.91.0/24 Site B: 192.168.200.0/24 I want site B to be able to ping site A but not the other way around. I also need the firewall rule controlling this to be on Site B's side of things. I've setup the following which I thought should work but I can still ping from site A to B? The IPv4 "Source" group has it selected as the 192.196.91.0/24 network and on the destination I've tried having it just set to Any network and have also manually added 192.168.200.0/24 but to no avail. Any help from someone much more in the know than me would be most appreciated [ATTACH=CONFIG]70029[/ATTACH] [ATTACH=CONFIG]70030[/ATTACH] Edited October 10, 2023 by AB_IT
ibpalle Posted October 10, 2023 Posted October 10, 2023 If you are testing by pinging the firewall internal IP on A from B then you may get misleading results. Not a Unifi user but generally you would setup a policy to deny source IP range A access to Destination IP range B. This can be added on either side really. You may need to pay attention to the interfaces too - if traffic is passing over VPN, the VPN interface may need to be set specifically in some of these policies.
AB_IT Posted October 10, 2023 Author Posted October 10, 2023 If you are testing by pinging the firewall internal IP on A from B then you may get misleading results. Not a Unifi user but generally you would setup a policy to deny source IP range A access to Destination IP range B. This can be added on either side really. You may need to pay attention to the interfaces too - if traffic is passing over VPN, the VPN interface may need to be set specifically in some of these policies. Thanks for your help, not doing that I'm pinging a seperate device on both networks to test. I thought that's what I've done with the above rule to basically drop all source traffic from A to B?
Steve21 Posted October 10, 2023 Posted October 10, 2023 I thought that's what I've done with the above rule to basically drop all source traffic from A to B? I'm assuming that was in reference to the fact you have it set as "Lan In" rather than WAN/Internet etc, depending on what it's called on Unifi If the second network isn't defined as a local/LAN one the pings would be coming in via the WAN/Internet interface normally. e.g. A client, goes ping, goes to A firewall, out via WAN/Internet interface, goes to B firewall in on WAN/internet interface and should be dropped there Steve
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now