- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Intervlan routing allow A>B but Block B>A
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Intervlan routing allow A>B but Block B>A
Hey everyone.. can anybody share some experience on how they achieved a setup with inter vlan routing where vlan A can access B but B cannot access A
In my ubiquiti world where I come from I was able to push a firewall rule stating that established & related traffic was allowed and then I blocked B to A..
thay way A was able to access B and B was allowed to reply, but B was never able to start the connection ..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It works exactly the same way in Check Point.
You define an Access Policy rule that allows A to talk to B on the desired ports/services.
This allows reply traffic from B only if A initiated the connection.
B cannot initiate a connection to A unless there is an explicit rule allowing it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That’s nice. So if I ever needed bi directional access I would have to make explicit rule allowing A to B and B to A otherwise it would not happen ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes @skandshus it everything will be blocked until you open/configure the relevant policy.
