Block intervlan routing MX64

EdgeFarming
Here to help

Block intervlan routing MX64

Hello,

 

I have following LAN networks.

LAN1 Vlan15   192.168.128.0/24

LAN2 Vlan10 10.10.10.0/24

 

I want to block LAN1 to access LAN1. I created rules under outbound rules but they are not working. Please check Attached screenshots.

 

Please let me know what I am missing.

Port Settings.pngoutbound.pngping .png

5 Replies 5
ww
Kind of a big deal
Kind of a big deal

Fw rules do not work on active sessions. You need to wait like 10 minutes for the firewall to clear active session.

 

Or reboot the mx to clear all sessions

jimmyt234
A model citizen

As well as this you need to test using actual end user devices, and not ping the MX itself as it will often ignore firewall rules. (Unclear if .3 is a host of the MX itself)

EdgeFarming
Here to help

Yes, 10.10.10.4 is my PC and 192.168.128.3 is an Access Point. I will wait for 10 min to take effect. Thanks

EdgeFarming
Here to help

Hi, ok ok I will wait 10 min or reboot the router, I'll let you know.

 

is that time apply for every rule? I mean if I block 10.10.10.4 to access nike.com  Do I need to wait 10 min to take effect? Because I also tried that and didn't work. 

 

Thanks

ww
Kind of a big deal
Kind of a big deal

Im not sure about the session timeout, could be 5-10 minutes. Also would depend on if the protocol closes the session itself or not.

 

If you didnt go to that website before, it should work/be blocked.

 

Get notified when there are additional replies to this discussion.