Deny blue clients access to the IPFire interface

Hello,

I wanted to isolate my domotics network by a dedicated Wifi on the Blue interface (192.168.10.0/24)

I applied the rule proposed on the Wiki (www.ipfire.org - Blue Access) To disable access to the Ipfire web interface

It work fine

But I discovered that we could still access the web interface from the Blue network by the Ipfire Green address (https://192.168.20.1:444)

Same for ssh (222)

So I had to add a second rule to remove all access From Blue to Green interface (192.168.20.1)

I think this problem has already been raised
Deny access to WebUI from BLUE

What really it needs is a feature request to select networks and a Ethernet interface (Not assigned to any network, for out of band management) that can access web GUI.

1 Like

What you are looking for is listed in the wiki.

Deny blue clients access to the IPFire web interface

Thanks for the answer @hvacguy,

It is precisely this Wiki page that should be completed by adding a rule :
Deny Blue Access to the Green Ipfire (Web) interface.