This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Apply different rules to different interfaces

Hi gyus,

not sure if that’s possible but hope you can help me.

We have a SG210 with current firmware installed

 

Eth1 (LAN Interface) 192.168.0.1

When this port is connected to the lan switch the Users should be allowed to use http/https

When Eth1 is disconnected and Eth2 (192.168.0.2) is connected to the LAN switch then http/https should be blocked.

Eth1 and Eth2 will never be connected to the LAN (switch) at the same time. It’s either Eth1 OR Eth2.

Is that even possible?

 

Thanks and greetings



This thread was automatically locked due to age.
  • Hi guys,

    sorry my explanation was a bit messy and confusing so I want to explain again.

    Our setup is quite simple. We have one network with IP address 192.168.0.1 /24. Our SG has one internet connection connected to port eth0.

    Port eth1 is connected to the LAN and at the moment only Windows Update are allowed. No web surfing or anything else. The reason why it is so restricted is that this is a laboratory network with only a few PCs and it should be secured as much as possible.

    However, once in a while the users need web traffic like http/https in order to access website.

    The question now is:

    Would it be possible to configure port eth2 with less restrictions and allow e.g. webtraffic. Therefore if the users need to surf they can simply disconnect eth1 and connect to eth2. Once they are finished, they can plug it back.

    Thanks in advance!

    Aktuator

  • Yes this is possible, but simple use different IP-networks on the two interfaces (eg. eth1:192.168.0.1/24  eth2:192.168.1.1/24) and then use different policies for those networks.

    bye Josef

    BERGMANN engineering & consulting GmbH, Wien/Austria

  • But the clients are all in the network 192.168.0.1/24 and then they won't be able to reach the gateway anymore.

    Or am I missing something?

  • Hallo Aktuator,

    The answer to your original question is "No" - not possible.

    If these users will only be connecting one-at-a-time to use HTTP/S, then why not have them connect their individual machine to eth2, do an ipconfig renew and get a new IP in a different subnet?  When done, the user reconnects to the switch and renews their lease.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA