<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Deny access between to networks on one interface</title><link>https://community.sophos.com/utm-firewall/f/network-protection-firewall-nat-qos-ips/135396/deny-access-between-to-networks-on-one-interface</link><description>Hi. We have sophos sg 310 UTM. We have internal networks 192.168.0.0/23 and 192.168.4.0/24 on one of the interface. When i try to connect wifi router which is in 192.168.4.0/24 via web interface example: https://192.168.4.2 from network 192.168.0.0/23</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Deny access between to networks on one interface</title><link>https://community.sophos.com/thread/500463?ContentTypeID=1</link><pubDate>Thu, 14 Jul 2022 07:59:54 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:69ac7149-73dc-4d3c-8ee7-475be145597d</guid><dc:creator>Vivek Jagad</dc:creator><description>&lt;p&gt;Hello &lt;a href="/members/besik-chitidze"&gt;Besik Chitidze&lt;/a&gt;,&lt;br /&gt;&lt;br /&gt;Thank you for reaching out to the community, Firewall rules work from top to bottom fashion, you if the traffic for both the subnets do reach on the FW i.e. [&lt;span&gt;192.168.0.0/23 to 192.168.4.0/24] then you may create a FW rule with both subnets in source and destination with action drop/reject and then create another rule on top of that rule for [192.168.0.3] with the action allow.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>