<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Block traffic via SSID firewall in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/block-traffic-via-ssid-firewall/m-p/99446#M9394</link>
    <description>&lt;P&gt;Hello, I have 2 Wireless Lan.&lt;BR /&gt;Corporate and visitors.&lt;BR /&gt;I need to block access to my server network when access is made on the guest LAN. Ex: lan 192.168.4.0/24&lt;BR /&gt;I created the rules and applied them as follows, but it blocks all access&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ErickLeon_1-1709068215191.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7010i910776403193FB5E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ErickLeon_1-1709068215191.png" alt="ErickLeon_1-1709068215191.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ErickLeon_0-1709068181166.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7009i198161DAD3387956/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ErickLeon_0-1709068181166.png" alt="ErickLeon_0-1709068181166.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ErickLeon_2-1709068294512.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7011i2732DE2E5A1F0DB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ErickLeon_2-1709068294512.png" alt="ErickLeon_2-1709068294512.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2024 21:12:18 GMT</pubDate>
    <dc:creator>ErickLeon</dc:creator>
    <dc:date>2024-02-27T21:12:18Z</dc:date>
    <item>
      <title>Block traffic via SSID firewall</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/block-traffic-via-ssid-firewall/m-p/99446#M9394</link>
      <description>&lt;P&gt;Hello, I have 2 Wireless Lan.&lt;BR /&gt;Corporate and visitors.&lt;BR /&gt;I need to block access to my server network when access is made on the guest LAN. Ex: lan 192.168.4.0/24&lt;BR /&gt;I created the rules and applied them as follows, but it blocks all access&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ErickLeon_1-1709068215191.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7010i910776403193FB5E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ErickLeon_1-1709068215191.png" alt="ErickLeon_1-1709068215191.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ErickLeon_0-1709068181166.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7009i198161DAD3387956/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ErickLeon_0-1709068181166.png" alt="ErickLeon_0-1709068181166.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ErickLeon_2-1709068294512.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7011i2732DE2E5A1F0DB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ErickLeon_2-1709068294512.png" alt="ErickLeon_2-1709068294512.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 21:12:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/block-traffic-via-ssid-firewall/m-p/99446#M9394</guid>
      <dc:creator>ErickLeon</dc:creator>
      <dc:date>2024-02-27T21:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Block traffic via SSID firewall</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/block-traffic-via-ssid-firewall/m-p/99457#M9395</link>
      <description>&lt;P&gt;Hello Erick,&lt;/P&gt;&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.extremenetworks.com/t5/user/viewprofilepage/user-id/46561"&gt;@ErickLeon&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You have an explicit deny all rule (you can't see this this) at end of firewall. You need to add an allow all rule to allow all other traffic. The rules will be executed from top to bottom so traffic will be denied from a certain subnet to your corp network but allowed all other traffic out to internet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN&gt;GUEST WLAN SETUP:&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If guest WLAN is going to go through corp network you will have to configure ACL rule for same by going back to Configuration &amp;gt;&amp;gt; Security &amp;gt;&amp;gt; IP Firewall Rules &amp;gt;&amp;gt; Create a New ACL (example&amp;nbsp; Guest_WLAN_ACL) &amp;gt;&amp;gt; Add following rules:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1 - Allow: Deny&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Source: Network (IP of network subnet: Example 192.168.0.0/24)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Destination: Network (IP of corp network: Example 10.0.0.0/24)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christoph_S_0-1709127389826.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7016i88D150817D679ADE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Christoph_S_0-1709127389826.png" alt="Christoph_S_0-1709127389826.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2 – Allow: Permit&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Source: Network 192.168.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Destination: Any&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christoph_S_1-1709127428968.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7017iF04478F9D8954392/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Christoph_S_1-1709127428968.png" alt="Christoph_S_1-1709127428968.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Create Guest WLAN &amp;gt;&amp;gt; go to Firewall &amp;gt;&amp;gt; IP Firewall Rules &amp;gt;&amp;gt; Inbound IP firewall .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Christoph_S_2-1709127446641.png" style="width: 400px;"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/7018i3A12C31242711F0C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Christoph_S_2-1709127446641.png" alt="Christoph_S_2-1709127446641.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In short, you'll need an allow all rule at the end of your firewall to allow all other traffic through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 13:38:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/block-traffic-via-ssid-firewall/m-p/99457#M9395</guid>
      <dc:creator>Christoph_S</dc:creator>
      <dc:date>2024-02-28T13:38:58Z</dc:date>
    </item>
  </channel>
</rss>

