What's new

Firewall Rules for Local Traffic

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

lime237

Occasional Visitor
Hello everybody,

I was wondering if anyone knew if there's any way to configure simple firewalls rules for local device to device traffic. As an example, I would like a device at 192.168.1.20 to be blocked from talking to any other devices on the network (192.168.1.0 /24), except for one FTP server at 192.168.1.30, on ports 21 and 20. Would there be a way to write an allow rule that allows that traffic, followed by a deny rule that blocks all other traffic? If so, how?

If it helps, I am using a RT-AC68U, with Asuswrt-Merlin firmware version 386.4, with another one behind it as an AiMesh node. I am already using guest wireless for devices I want segmented, but I would like to have this more granular control if possible at all.

Thank you all. Cheers.
 
The firewall only blocks traffic to and from the internet, it doesn't effect LAN to LAN traffic. You could possibly do some complex custom scripting to create VLANs on specific physical LAN ports, but that's physical connections not IP-based. It's also unlikely to work in an AiMesh setup.
 

Similar threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top