Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG firewall rule with mac-host destination does not work

Hello again,

experiences with XG are splitten between "hm k" and "wtf", only view things which seems to be really better.

First thing (opinions are different here), its a shame that you cannot define hosts with IP and MAC in the same object, also the fact that it is only possible to define a "mac host" object with the option "mac list" where you have to enter ALL damn MACs, unsorted, horrible view and editing... why not like "ip hosts", where you can add ip-hosts as a group, same for "mac host group" with adding the "mac hosts"?

OK, now the problem from topic / title: when creating a firewall rule like following, it does not work - nothing can been seen in log viewer:

ALLOW: source zone: wlan2, source network: mac-host-X, destination zone: lan2, destination network: mac-host-Y

source host is dyn ip, destination host has additionally an dhcp reservation (next crappy conifiguration, the dhcp reservations).

The rule only works if I add a separate IP-host-Y to the rule for the host-Y.

OK, rules for firewall and webfilte seems to work when source-hosts are defined as IP-host and/or as mac-host. Right? So some tests suggested that.

Why not in destination?

Is that a "feature" or a bug?

Thx in advice



This thread was automatically locked due to age.
Parents
  • According to  it is not possible to use only a MAC-Host definition without a IP-Host definition in Destination-Network.

    On the other side it seems to be possible to use MAC-Hosts as Source.

    It´s not clearly answered, if this is a bug or a "feautre" - first on seems more plausible.

Reply
  • According to  it is not possible to use only a MAC-Host definition without a IP-Host definition in Destination-Network.

    On the other side it seems to be possible to use MAC-Hosts as Source.

    It´s not clearly answered, if this is a bug or a "feautre" - first on seems more plausible.

Children
No Data