1
24.7 Production Series / Re: Unable to prevent traffic from VLANs to untagged LAN
« on: November 20, 2024, 12:03:26 am »So I assume that your management network is supposed to be covered by your PrivateNetworks alias? Double-check that?
Okay, my alias should be fine:
I'd maybe try adding an explicit block rule at the top of the list for INTERNAL and see if that gets applied, then try to figure out why some other rule is allowing more than you want. You could turn on logging for your (suspect) rules and try to use that to find out which one is doing it too.....
Thank you for this valuable hint. It has pushed me in the right direction. After adding a "block everything from anywhere to anywhere" rule at the INTERNAL VLAN, I was still able to ping hosts on the management LAN. I turned on logging for all floating rules (thanks for mentioning the logging!) and discovered a rule that was not configured correctly.
I have a rule that allows traffic from different VLANs to the AD server, but I have specified a wrong subnet mask (and obviously I have been very lazy while specifying it):
With that fixed, everything now seems to work as expected...
Thanks again for pointing me in the right direction!