Site Tools


advanced-access

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
advanced-access [2023/09/12 17:16] – [LAN Access Notes] -add note that table entries only permit traffic in one direction hogwildadvanced-access [2023/09/12 17:20] (current) – [LAN Access Notes] hogwild
Line 34: Line 34:
 Regardless of LAN Access rules, by default a LANx device is able to reach (e.g. ping) all the router's LAN interfaces (only). This is by design. Regardless of LAN Access rules, by default a LANx device is able to reach (e.g. ping) all the router's LAN interfaces (only). This is by design.
  
-All entries in the LAN Access table are one-way only. So, if you want hosts on LAN0 to be able to communicate with hosts on LAN1, +All entries in LAN Access are one-way only. \\  
-you must create have entries in the table to achieve that. One allowing traffic from LAN0 to LAN1 and another allowing traffic from LAN1 to LAN0.  +For example, if you want hosts on LAN0 to be able to communicate with hosts on LAN1, 
-  +and hosts on LAN1 to be able to communicate with hosts on LAN0, you will need to have two entries in the table to achieve that.  
-LAN Access is an IP-level access control. This means that **all ports/protocols are automatically enabled**. If additional fine tuning is required (for example, you wanted to allow only allow port 80/TCP) you will need to manually configure settings instead.+ 
 +LAN Access is an IP-level access control. \\  
 +This means that **all ports/protocols are automatically enabled**. If additional fine tuning is required (for example, you wanted to allow only allow port 80/TCP) you will need to manually configure settings instead.
  
  \\  \\
advanced-access.txt · Last modified: 2023/09/12 17:20 by hogwild