User`s guide

Chapter 9 Firewall Screens
LAN-Cell 2 User’s Guide
204
Figure 118 Block VPN to LAN Traffic by Default Example
From VPN To VPN Packet Direction
From VPN To VPN firewall rules apply to traffic that comes in through one of the LAN-
Cell’s VPN tunnels and terminates at the LAN-Cell (like for remote management) or goes out
through another of the LAN-Cell’s VPN tunnels (this is called hub-and-spoke VPN, see
Section 10.9 on page 238 for details). The LAN-Cell decrypts the traffic and applies the
firewall rules before re-encrypting it or allowing the traffic to terminate at the LAN-Cell.
In the following example, the From VPN To VPN default firewall rule silently blocks the
traffic that the LAN-Cell receives from any VPN tunnel (either A or B) that is destined for the
other VPN tunnel or the LAN-Cell itself. VPN traffic destined for the DMZ is allowed
through.