[ previous ] [ next ] [ threads ]
 
 From:  "James W. McKeand" <james at mckeand dot biz>
 To:  <m0n0wall at lists dot m0n0 dot ch>
 Subject:  RE: [m0n0wall] Firewall Quiestion
 Date:  Wed, 26 Jan 2005 14:07:01 -0500
Robert Bialecki wrote:
> Hi,
> 
> What rule should I use to stop comunication between clients on lan?
> A client should only be able to go to the gateway (monowall) and not
> be able to comunicate on any port with any other client on lan. 
> 
> Thanks,
> 
> Robert Bialecki

AFAIK, this is not something you can do with firewall rules. I am not
an expert on VLANs (I can barely spell it), but you may be able to use
VLANs to segregate the clients. I think all of your network gear would
need to support VLANs for this to work. NICs in both m0n0wall and
client computers, plus your switching hardware need to support it.
Basically, your LAN interface will have a VLAN for each of the client
computers.

Good luck.

_________________________________
James W. McKeand