Simple zone SDN

UtilisateurCXS

New Member
Dec 9, 2025
9
0
1
I need help because I can't isolate two VMs on two different VNets, in two different zones, each with their own subnet, and it still manages to ping. I've also enabled the data center firewall on the node and on the VNets. Here are some screenshots of my configuration:


Firewall datacenter with non rule :
Capture d'écran 2025-12-11 093823.png


Node firewall :

1765442415901.png1765442437916.png



Zone :
1765442462538.png

1765442479930.png


1765442556159.png
1765442575961.png


1765442586190.png
 
The traffic between those two zones gets routed by the host, so you'd need to create the forward rules on the host (where the routing happens), not inside the VNet firewall. Also, in order to use the forward rules you'd need to activate the nftables firewal (which is still in tech preview state!).
 
The traffic between those two zones gets routed by the host, so you'd need to create the forward rules on the host (where the routing happens), not inside the VNet firewall. Also, in order to use the forward rules you'd need to activate the nftables firewal (which is still in tech preview state!).
Thanks you
 
Last edited: