Quantcast
Channel: All Ethernet Switching posts
Viewing all articles
Browse latest Browse all 10307

Re: Guest internet firewall filter

$
0
0
set interfaces vlan unit 100 description guest
set interfaces vlan unit 100 family inet filter input guest-to-internet-only
set interfaces vlan unit 100 family inet filter output no-corp-to-guest
set interfaces vlan unit 100 family inet address 192.168.1.254/24

set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 10.0.0.0/8
set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 172.16.0.0/12
set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 192.168.0.0/16
set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 127.0.0.0/8
set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 169.254.0.0/16
set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 from destination-address 224.0.0.0/3
set firewall family inet filter guest-to-internet-only term deny-access-to-rfc1918 then discard
set firewall family inet filter guest-to-internet-only term allow-everything-else then accept
set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 10.0.0.0/8
set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 172.16.0.0/12
set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 192.168.0.0/16
set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 127.0.0.0/8
set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 169.254.0.0/16
set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 from source-address 224.0.0.0/3
set firewall family inet filter no-corp-to-guest term deny-access-from-rfc1918 then discard
set firewall family inet filter no-corp-to-guest term allow-everything-else then accept

Viewing all articles
Browse latest Browse all 10307

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>