[ previous ] [ next ] [ threads ]
 
 From:  Harald Sauff <harald dot sauff at tu dash harburg dot de>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  simplifying packet filter rules
 Date:  Mon, 12 Nov 2007 14:36:12 +0100
Hello list,

I'm running m0n0wall 1.231 as our internet gateway. It connects WAN, DMZ
and several local subnets (real and VLANs).

Is there a way to specify a rule like "allow access to internet"? I want
to block access between local subnets, but every local subnet should be
able to access the internet.
So I'd like to rely on the implicit default "block everything" rule and
just add the "allow access to internet" rule. But when I specify "allow
*" then I have to add rules that block access to every subnet seperately
(block subnet A, block subnet B, block subnet C, allow *). And when I do
it this way and I add another subnet I have to extend the rules for
every device.
Did I miss a special configuration option?


greetinx,
 Harry