<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VDX-6740(7.3.0aa) - Extended Out/In ACL : not working as expected in Data Center (VDX)</title>
    <link>https://community.extremenetworks.com/t5/data-center-vdx/vdx-6740-7-3-0aa-extended-out-in-acl-not-working-as-expected/m-p/96428#M720</link>
    <description>&lt;DIV&gt;Hello Experts,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I have configured the below ACL , when I apply it "In" direction then it is working as expected&lt;/DIV&gt;&lt;DIV&gt;but if I apply the same ACL&amp;nbsp; "out" direction then it drops the traffic for the permitted rule even.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 10 permit tcp host 192.168.11.4 gt 80 host 192.168.21.4 gt 80&lt;BR /&gt;seq 20 permit tcp host 192.168.11.5 lt 70 host 192.168.21.5 lt 70&lt;BR /&gt;seq 30 permit tcp host 192.168.11.6 neq 80 host 192.168.21.6 neq 81&lt;BR /&gt;seq 40 permit tcp host 192.168.11.7 range 10 20 host 192.168.21.7 range 10 20&lt;BR /&gt;exit&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If I keep only below a single line in the ACL then it works as per config in both directions (in/out) -&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 10 permit tcp host 192.168.11.4 gt 80 host 192.168.21.4 gt 80&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If I keep only below a single line in the ACL then it works as per config in both directions (in/out)-&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 20 permit tcp host 192.168.11.5 lt 70 host 192.168.21.5 lt 70&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;The combination of "gt" &amp;amp; "lt" is also not working as per config, switch drops the seq 20 traffic when it applies in the "out" direction :&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 10 permit tcp host 192.168.11.4 gt 80 host 192.168.21.4 gt 80&lt;BR /&gt;seq 20 permit tcp host 192.168.11.5 lt 70 host 192.168.21.5 lt 70&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;This is weird behaviour. Please confirm if this is a software bug/defect&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Note - If I use "eq" in the port then no issue&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;-Pavan Pawar&lt;/DIV&gt;</description>
    <pubDate>Thu, 13 Jul 2023 12:25:02 GMT</pubDate>
    <dc:creator>pawarpavan</dc:creator>
    <dc:date>2023-07-13T12:25:02Z</dc:date>
    <item>
      <title>VDX-6740(7.3.0aa) - Extended Out/In ACL : not working as expected</title>
      <link>https://community.extremenetworks.com/t5/data-center-vdx/vdx-6740-7-3-0aa-extended-out-in-acl-not-working-as-expected/m-p/96428#M720</link>
      <description>&lt;DIV&gt;Hello Experts,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I have configured the below ACL , when I apply it "In" direction then it is working as expected&lt;/DIV&gt;&lt;DIV&gt;but if I apply the same ACL&amp;nbsp; "out" direction then it drops the traffic for the permitted rule even.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 10 permit tcp host 192.168.11.4 gt 80 host 192.168.21.4 gt 80&lt;BR /&gt;seq 20 permit tcp host 192.168.11.5 lt 70 host 192.168.21.5 lt 70&lt;BR /&gt;seq 30 permit tcp host 192.168.11.6 neq 80 host 192.168.21.6 neq 81&lt;BR /&gt;seq 40 permit tcp host 192.168.11.7 range 10 20 host 192.168.21.7 range 10 20&lt;BR /&gt;exit&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If I keep only below a single line in the ACL then it works as per config in both directions (in/out) -&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 10 permit tcp host 192.168.11.4 gt 80 host 192.168.21.4 gt 80&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;If I keep only below a single line in the ACL then it works as per config in both directions (in/out)-&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 20 permit tcp host 192.168.11.5 lt 70 host 192.168.21.5 lt 70&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;The combination of "gt" &amp;amp; "lt" is also not working as per config, switch drops the seq 20 traffic when it applies in the "out" direction :&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended Extended_Named&lt;BR /&gt;seq 10 permit tcp host 192.168.11.4 gt 80 host 192.168.21.4 gt 80&lt;BR /&gt;seq 20 permit tcp host 192.168.11.5 lt 70 host 192.168.21.5 lt 70&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;This is weird behaviour. Please confirm if this is a software bug/defect&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Note - If I use "eq" in the port then no issue&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;-Pavan Pawar&lt;/DIV&gt;</description>
      <pubDate>Thu, 13 Jul 2023 12:25:02 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/data-center-vdx/vdx-6740-7-3-0aa-extended-out-in-acl-not-working-as-expected/m-p/96428#M720</guid>
      <dc:creator>pawarpavan</dc:creator>
      <dc:date>2023-07-13T12:25:02Z</dc:date>
    </item>
  </channel>
</rss>

