Old 01-11-2012, 10:49 PM   #1 (permalink)
Newbie
 
Join Date: Jan 2012
Posts: 4
stangride is on a distinguished road
Default Private & Public Network - stop communication between them

Hi:

We have three interfaces within our UTM device:

- Ext
- Int - 192.168.1.1/24
- DMZ - 192.168.10.1/24

The internal interface is used for our Private network and we would like the DMZ to be setup as our Public network that we can put a wireless connection on that doesn't have access through the network back to the 192.168.1.x/24 network. What do I need to do in the UTM/Firewall to prevent the two networks from talking?

Thanks,
Stangride
stangride is offline  
Old 01-11-2012, 10:50 PM   #2 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,611
dmorris is on a distinguished road
Default

either
1) add a packet filter rule to just filter traffic between the two
2) uncheck "NAT only WAN traffic" in config->networking->advanced->general. (NAT will happen between the two)

welcome to the forums.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 01-12-2012, 06:14 AM   #3 (permalink)
Newbie
 
Join Date: Jan 2012
Posts: 4
stangride is on a distinguished road
Default

dmorris:

I went with your option # 2 and unfortunately, if I am on a machine that is on the 192.168.1.x subnet, they can ping 192.168.10.1 which is the static IP assigned to the DMZ interface.

What should I do to eliminate communication between the two subnets but allow each to route to the outside (ext) interface.

Thanks you,
Stangride
stangride is offline  
Old 01-12-2012, 09:44 AM   #4 (permalink)
Newbie
 
Join Date: Jan 2012
Posts: 4
stangride is on a distinguished road
Default

Dmorris:

If I create two packet filters like this, will that do what I am looking for?

Configuration>Networking>Advanced>Packet Filter

Rule#1 Src=10.x DST=1.x
Action: Reject
Source Address: 192.168.10.0/24
Destination Address: 192.168.1.0/24

Rule#2 Src=1.x DST=10.x
Action: Reject
Source Address: 192.168.1.0/24
Destination Address: 192.168.10.0/24

Thank you,
Stangride
stangride is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:46 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2