Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Sonicwall TZ210 routing private IP space thru wan interface?

Status
Not open for further replies.

anthonymo

Vendor
Aug 19, 2008
48
US
I've discovered that 192.168.1.1 is pingable from inside my 10.1.1x network.
It appears to belong to a mikrotik on my WISP's network.
I've verified using Packet Monitor that when I ping it goes out my WAN interface.

My question is I thought it was standard practice to block the routing of "Private" IP space thru wan ports.

Since sonicwall doesn't seem to do this by default, what is my best approach to blocking all RFC 1918 traffic thru the wan?

Thank you,
Tony
 
Set up address objects for 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, add them to an address group called something like RFC1918, then set up a DENY any/all LAN to WAN rule for this group?
 
That sounds about right, let me give it a try, thank you
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top