Firewalld create a pvlan

Support for security such as Firewalls and securing linux
Post Reply
dazzpowder
Posts: 1
Joined: 2015/11/03 21:49:58

Firewalld create a pvlan

Post by dazzpowder » 2017/11/05 17:55:17

Hi all,

Have a situation where I have a host in a dmz, given the nature of the application the host cannot communicate with any host in that vlan nor can any host communicate with it, as if it were in an isolated private vlan.

I can create a rich rule that prevents any host in that segment talking to this host but no matter what I do I cannot get this host to stop communicating or accessing other hosts e.g I can still ping and ssh other hosts in the subnet, when I did stop it I could no longer access it from any other subnet which is required.

I was hoping to reject all but the default gateway and its own address.

Can this even be done?

-Thanks

Post Reply