<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic S Series Inbound Port Policy Deny Subnet in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/s-series-inbound-port-policy-deny-subnet/m-p/66616#M7849</link>
    <description>&lt;P&gt;We are routing multiple networks with S-Series routers.&amp;nbsp; Multiple networks inbound on a trunk port from closet switches.&amp;nbsp; At one point we set policies on the closet switch ports to deny destination ip range access.&amp;nbsp; EX.&amp;nbsp; Student Vlan defined port was manually assigned a policy to deny access to certain ip ranges (Employee vlans).&amp;nbsp; This can be troublesome because of the amount of moves and changes that take place in our environment at the closet level. We would like to do something similar on the S-Series core inbound trunk ports but by vlan definition?&amp;nbsp;&amp;nbsp;&amp;nbsp; But in this case its a trunk port so we want to deny the student subnet access to the employee range but not all traffic. &amp;nbsp; .&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2020 21:28:51 GMT</pubDate>
    <dc:creator>Walt_Witkowski</dc:creator>
    <dc:date>2020-01-10T21:28:51Z</dc:date>
    <item>
      <title>S Series Inbound Port Policy Deny Subnet</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/s-series-inbound-port-policy-deny-subnet/m-p/66616#M7849</link>
      <description>&lt;P&gt;We are routing multiple networks with S-Series routers.&amp;nbsp; Multiple networks inbound on a trunk port from closet switches.&amp;nbsp; At one point we set policies on the closet switch ports to deny destination ip range access.&amp;nbsp; EX.&amp;nbsp; Student Vlan defined port was manually assigned a policy to deny access to certain ip ranges (Employee vlans).&amp;nbsp; This can be troublesome because of the amount of moves and changes that take place in our environment at the closet level. We would like to do something similar on the S-Series core inbound trunk ports but by vlan definition?&amp;nbsp;&amp;nbsp;&amp;nbsp; But in this case its a trunk port so we want to deny the student subnet access to the employee range but not all traffic. &amp;nbsp; .&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 21:28:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/s-series-inbound-port-policy-deny-subnet/m-p/66616#M7849</guid>
      <dc:creator>Walt_Witkowski</dc:creator>
      <dc:date>2020-01-10T21:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: S Series Inbound Port Policy Deny Subnet</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/s-series-inbound-port-policy-deny-subnet/m-p/66617#M7850</link>
      <description>&lt;P&gt;On S-series you should be able to use source IP mapping to Policy Role:&lt;/P&gt; &lt;FIGURE&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ed258e41dbad4ceda2d78cd9099ed490_e3d5d857-1411-4bab-b5ce-359c075d4726.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/619i1E374C50E759FDB5/image-size/large?v=v2&amp;amp;px=999" role="button" title="ed258e41dbad4ceda2d78cd9099ed490_e3d5d857-1411-4bab-b5ce-359c075d4726.png" alt="ed258e41dbad4ceda2d78cd9099ed490_e3d5d857-1411-4bab-b5ce-359c075d4726.png" /&gt;&lt;/span&gt;&lt;/FIGURE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Then in rules you can define your actions…&lt;/P&gt; &lt;P&gt;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Z.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 21:32:56 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/s-series-inbound-port-policy-deny-subnet/m-p/66617#M7850</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2020-01-17T21:32:56Z</dc:date>
    </item>
  </channel>
</rss>

