This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Allow any service vom particular network? Currently ends in default drop

Dear all

I have created a new network "IoT".
It should become the home for all devices I don't trust in my network. Such as playstation, weather station, radio...

I would like to allow all outbound traffic from that particular IoT network. 
But currently all outbound traffic runs into a default drop on the firewall log.

The blocking happens with firewall rule #1 "IoT (Network) -> any -> External (Network). 
However, If I set:
The blocking happens with firewall rule #1 "IoT (Network) -> any -> Any, it is working.

Of course, if I set the allowed destination network to "Any Network", I have traffic in my regular network. This I would like to avoid.

Could somebody help me with it?

 

 

Kind regards

Novice



This thread was automatically locked due to age.
Parents
  • You want the traffic selector to be 'IoT (Network) -> any -> Internet IPv4'.  The 'External (Network)' object includes very little - hover over it with your mouse and you will see.

    Yes, ping is special.  Refer to #2 in Rulz.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • thank you both. I is now working as intended.

     

    I see, I have a confusion about the service "External(Network)" vs "Internet IPv4".

    If I got it right now, it says:

    - External (Network) is the interface where traffic goes through; manly used in NAT settings
    whereas
    - "Internet IPv4" ist the destination network (public) as such; manly used in firewall settings

    ?

     

    Greetings

    N3

Reply
  • thank you both. I is now working as intended.

     

    I see, I have a confusion about the service "External(Network)" vs "Internet IPv4".

    If I got it right now, it says:

    - External (Network) is the interface where traffic goes through; manly used in NAT settings
    whereas
    - "Internet IPv4" ist the destination network (public) as such; manly used in firewall settings

    ?

     

    Greetings

    N3

Children
  • I've never found a use for the "External (Network)" object.  I always use the "(Address)" objects created when you define an Interface or Additional Addresses.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA