cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
336
Views
0
Helpful
4
Replies

Block Inside Network

nikuhappy2010
Level 1
Level 1

Hi, We have been using ASA for last ne year and its working fine, now can I block the inside machines that means 2 machines are available in inside zone now i want that first machine not able to access or communicate with second machine, is it possible becoz the traffic wont bypass through firewall when both communicate. Thanks

1 Accepted Solution

Accepted Solutions

If both machines are in 'same subnet', then both will communicate 'directly' and will never each the firewall. You have the following options:

> Change the switch

> Change the network design

> Play around with some routes/proxy-arp

> NAT one of the machines on the firewall etc.

Regards

Farrukh

View solution in original post

4 Replies 4

Farrukh Haroon
VIP Alumni
VIP Alumni

You can use an access-list (VLAN or PORT) on the switch to block this communication.

Regards

Farrukh

Here, the Switch is not managable and all switch are connected with inside interface of FW, now is it possible?

If both machines are in 'same subnet', then both will communicate 'directly' and will never each the firewall. You have the following options:

> Change the switch

> Change the network design

> Play around with some routes/proxy-arp

> NAT one of the machines on the firewall etc.

Regards

Farrukh

Thanks Farruth.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card