Re: Is it possible to control access between clients on same LAN with a firewall?
K K <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
Yes. The most transparent (to the host) technique is what Cisco calls "private VLAN", see: http://en.wikipedia.org/wiki/Private_VLAN There are other approaches to get the same results, all require either a firewall with lots of interfaces (real or virtual) or a very smart switch. Kevin On 1/25/10, William Fitzgerald <[email protected]> wrote: > Dear all, > > I was just wondering how people control access amongst machines on the > same subnet (LAN) that are protected by the same firewall. > > In my case, the firewall is a home router (WRT54G) running DD-WRT, so > iptables is the firewall there. > > Presumably as with all firewalls, once a packet is not being sent to the > firewall itself or forwarded through the firewall towards another > network, the firewall will not protect machines behind the firewall from > each other. Perhaps as a result of the built-in switch, packets don't > get up to layer 3 and so the firewall is oblivious to inter-LAN packet > traffic. > > It would be nice to be able to restrict some LAN clients from talking to > each other, perhaps by layer 3 filtering. For example, it may make sense > to prohibit the network printer from talking to a web server and vice versa. > > Is there away to force/make it easier for the firewall to inspect > inter-LAN packets. Perhaps examining packets at layer 2 could capture this. > > I understand that one solution would be to install a local firewall on > each machine. > > This is just a general question, so that I might better understand the > area of "inter-LAN" protection. > > While it may be possible to have a firewall to not just protect traffic > from Internet to LAN and LAN to Internet but also LAN to LAN, it may not > be a practical thing to do. > > Any comments or insights are welcomed. > > regards, > Will. > _______________________________________________ > firewall-wizards mailing list > [email protected] > https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards > -- Sent from my mobile device