Firewall rules priority?

My network scheme

If i set httpd-admin (NethServer web interface) to “Access only from green networks”, connection from is work. If i set:

Connection from works too.
And in shorewall’s rules i see

Why isn’t blocked and refers to the NET and not to LOC.
You need to add a zone firewall object, with ip and device eth1.

Thank you, Filippo. I add zone. But now connections from subnet is blocked. Only if i set ip from subnet in “Allow hosts” i can connect. My zone connected to eth1, but not GREEN.
And why if i create rule:

where Host zsm -, i can connect to FW (allow hosts is clear).
But if i create:

where fw_green - firewall’s GREEN interface address, my connection is blocked?

Firewall rules don’t allow control on traffic for the firewall itself, now. You need to use the Network services page.
I think this is confusing, we probably will extend the fiewall rules editor to handle traffic for the firewall itself.
We are open to suggestions.

But why my zone, assigned to eth1, not GREEN? It’s normal?

I’m sorry, but I can’t understand your question.
Your green is and is a network behind a router. Using a zone you tell shorewall that it is connected to the green. By default nethserver assumes that all external network are connected to the red.
I’m not sure that this is a limit of nethserver, do you have an example of a different configuration?

Filippo, if i assign zone to eth1 and set httpd-admin (NethServer web interface) to “Access only from green networks” it block connections from to httpd-admin. But eth1 is green. May be i misunderstand something…

(Filippo Carletti) #8 is not green, is connected to green through a router.

Thank you. I thought, that all zones, assigned to local interface, must be green by default.

You can have multiple green, but those need to be connected directly to a network interface.
I have to think about your idea, maybe it’s possible to define as green networks connected through routers.

Better manually define color of zone or optionally leave zone without color.