- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-19-2017 01:28 PM
Basic trust to untrust policy I see internal address sending snmp to addresses like 10.0.0.1, 192.168.1.x.
Do people create a policy to block internal traffic going to RFC1918 on the untrusted interface?
09-19-2017 01:52 PM
I usually block trust to untrust RFC1918.
Although ISP routers drop it anyway I like to keep it clean.
It is really common for many applications like Skype for example to scan internal ranges for peers.
12-15-2022 02:11 PM
Do you have the one line policy.
Trust to untrust ( the builtin PAN addresses appear confusing.
TrRUST or INSIDE zones
ANY
UNTRUST
Action Block/deny
This is the first policy I believe
12-22-2022 11:52 AM
Hello,
If you follow a DENY ALL allow by exception methodology, just put a DENY ALL policy at the bottom of the Security Policies. This way only traffic that you 'allow' is allowed to go between zones, etc.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!