|
||||||||
This is probably a noob question, but I'm used to Cisco access lists, so I need to be sure that I get this right. Any traffic is blocked until a rule permits it... even LAN->WAN (and DMZ->WAN) traffic? The idea is to setup three LANs for: wired LAN, wireless and server (LAN, DMZ and DMZ2) all off them with full internet access but limited or no access to each other. If configuring rules for LAN you can only invert permission for one subnet like DMZ but that would still give access to DMZ2, right? I know it's mentioned under caveats as being "cumbersome" but is there really any way? Could you Invert permission for eg. 192.168.0.0 /16 and then add pinholes afterward? Great product by the way!! /Martin |