Forum Discussion
Nath
Finding a Voice
5 days agoWe originally tried blocking the socket LAN IP address on the WAN FW, but that stopped DHCP forwarding working.
What we've done instead is create a custom category for all the socket LAN IPs. For HA sites, that includes the IPs for the socket, and also the VIP - so 3 entries.
We use the Custom Service object type within the custom category, write the socket name and IP.
We then use this custom category in a WAN FW rule to block all access apart from authorised users.
It works well for us.