Skip to main content
BusinessUser
Explorer
January 15, 2024
Solved

Create Multiple Firewall Rules For Each Subinterface?

  • January 15, 2024
  • 4 replies
  • 2392 views

I have a physical interface "internal1" with 3 subinterfaces.

I have another physical interface "internal2".

If i want to create firewall rule to allow traffic from "internal1" to "internal2",

do i have to create 1 firewall rule only or i have to do 3 firewall rules?

Best answer by Nchandan

In your case, if you have a physical interface "internal1" with three subinterfaces (let's call them Sub1, Sub2, and Sub3), and another physical interface "internal2," you would need to create three firewall rules to allow traffic from each subinterface of "internal1" to "internal2."

 

Policy1

Source Interface: internal1:Sub1 Destination Interface: internal2 Action: Allow

 

Policy2 

Source Interface: internal1:Sub2 Destination Interface: internal2 Action: Allow

 

Policy3

Source Interface: internal1:Sub3 Destination Interface: internal2 Action: Allow

 

Each rule specifies the source and destination interfaces, allowing traffic between the specified subinterfaces on "internal1" and "internal2." This approach ensures that you have control over traffic between each pair of subinterfaces.

4 replies

pminarik
Staff
Staff
January 15, 2024

A firewall policy for "internal-X" will not match traffic for any of its sub-interfaces. "internal-X" and its sub-interfaces are independent logical interfaces, and any permutation of A->B traffic flow must be addressed with a firewall policy for specifically A->B.

 

The only exception would be using "any" as a source/destination interface in a policy, or if you were to select multiple interfaces as source/destination in a policy. (this needs to be enabled in Feature Visibility first for the GUI to allow it)

mle2802
Staff
Staff
January 15, 2024

Hi @BusinessUser,

You can run sniffer to identify the flow of the traffic if it is just from internal1 to 2, then you will not need the sub-interface policy.

hbac
Staff
Staff
January 16, 2024

Hi @BusinessUser,

 

I believe internal1 and its 3 subinterfaces are in different subnets/VLANs. It depends which subnets you want to allow to access internal2, you need to create a firewall policy for that interface. 

 

Regards, 

Nchandan
Staff
NchandanAnswer
Staff
January 17, 2024

In your case, if you have a physical interface "internal1" with three subinterfaces (let's call them Sub1, Sub2, and Sub3), and another physical interface "internal2," you would need to create three firewall rules to allow traffic from each subinterface of "internal1" to "internal2."

 

Policy1

Source Interface: internal1:Sub1 Destination Interface: internal2 Action: Allow

 

Policy2 

Source Interface: internal1:Sub2 Destination Interface: internal2 Action: Allow

 

Policy3

Source Interface: internal1:Sub3 Destination Interface: internal2 Action: Allow

 

Each rule specifies the source and destination interfaces, allowing traffic between the specified subinterfaces on "internal1" and "internal2." This approach ensures that you have control over traffic between each pair of subinterfaces.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.