Zonger Lv4Posted 19 Mar 2024 20:20
  
You can implement an Access Control List (ACL) to define traffic rules for a network. Initially, identify the IP addresses that should be permitted or blocked within the subnet. Then, configure the ACL to reject traffic from the blocked IPs while allowing traffic from the specified ones to access the designated IP. Ensure accurate subnet masking and precise ACL rule formulation to target the intended IP ranges effectively.
Ervin Santos Lv1Posted 19 Mar 2024 22:38
  
Last edited by Ervin Santos 19 Mar 2024 22:40.

Is it normal for Sangfor NGAF 8.0.85 have no a Destination Zone in the ACL Policy?
jerome_itable Lv2Posted 25 Mar 2024 11:51
  
No, directly blocking an IP on the same subnet through the router's firewall typically isn't possible. Here's why:

    Subnet Traffic Flow: Devices on the same subnet communicate directly with each other, bypassing the router's firewall. The firewall is mainly for controlling traffic entering or leaving the subnet, not internal communication.

However, there are alternative approaches to achieve some level of control:

    Client-side Firewalls: You can configure individual device firewalls (Windows Defender Firewall, etc.) on the machines you want to restrict. This allows them to block incoming traffic from the specific IP on the subnet.

    VLANs (Advanced): If you have a managed switch that supports VLANs (Virtual LANs), you can segment your network into separate logical subnets. By placing specific devices on separate VLANs, you can control communication between them using firewall rules on the router for inter-VLAN traffic.

    Sangfor HCI Specific Tools (if applicable): If you're using Sangfor HCI, it's possible they offer specific tools or functionalities for managing internal network traffic within a subnet. Check their documentation for details.

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders