Re: Is it possible to control access between clients on same LAN with a firewall?

K K <[email protected]>
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
Yes.
The most transparent (to the host) technique is what Cisco calls
"private VLAN", see:
http://en.wikipedia.org/wiki/Private_VLAN

There are other approaches to get the same results, all require either
a firewall with lots of interfaces (real or virtual) or a very smart
switch.

Kevin

On 1/25/10, William Fitzgerald <[email protected]> wrote:
> Dear all,
>
> I was just wondering how people control access amongst machines on the
> same subnet (LAN) that are protected by the same firewall.
>
> In my case, the firewall is a home router (WRT54G) running DD-WRT, so
> iptables is the firewall there.
>
> Presumably as with all firewalls, once a packet is not being sent to the
> firewall itself or forwarded through the firewall towards another
> network, the firewall will not protect machines behind the firewall from
> each other. Perhaps as a result of the built-in switch, packets don't
> get up to layer 3 and so the firewall is oblivious to inter-LAN packet
> traffic.
>
> It would be nice to be able to restrict some LAN clients from talking to
> each other, perhaps by layer 3 filtering. For example, it may make sense
> to prohibit the network printer from talking to a web server and vice versa.
>
> Is there away to force/make it easier for the firewall to inspect
> inter-LAN packets. Perhaps examining packets at layer 2 could capture this.
>
> I understand that one solution would be to install a local firewall on
> each machine.
>
> This is just a general question, so that I might better understand the
> area of "inter-LAN" protection.
>
> While it may be possible to have a firewall to not just protect traffic
> from Internet to LAN and LAN to Internet but also LAN to LAN, it may not
> be a practical thing to do.
>
> Any comments or insights are welcomed.
>
> regards,
> Will.
> _______________________________________________
> firewall-wizards mailing list
> [email protected]
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>

-- 
Sent from my mobile device
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.