SassyScorpio Lv2Posted 28 Mar 2023 01:55
  
Yes, you can configure access control policies on your Sangfor firewall to restrict access to the web interface from all zones except for the specific zone that should have access.

Here are the steps you can follow:

1- Log in to the Sangfor firewall's web interface and navigate to the "Access Control" or "Security Policy" section.

2- Create a new access control policy and set the source zone to "Any" or "All Zones" and the destination zone to the specific zone that should have access.

3- Set the service to "HTTP" or "HTTPS" depending on which protocol the web interface uses.

4- Set the action to "Allow" or "Permit".

5- Save the policy and apply it.

By creating this policy, you are allowing access to the web interface only from the specified zone and denying access from all other zones. This should help to prevent unauthorized access to the web interface from any interface other than the allowed zone.

If you also want to prevent access to the web interface from the GRE tunnel, you can create a separate policy to deny access from the GRE tunnel's source IP address or range.