<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL to Deny MDNS working? in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44498#M10920</link>
    <description>Have created an ACL that is meant to be blocking MDNS multicast addresses and an additional address used my Microsoft.&lt;BR /&gt;
&lt;BR /&gt;
Have written the ACL to every port on Ingress so that I can see hits per port.&lt;BR /&gt;
&lt;BR /&gt;
Problem is I'm not seeing the counters incrementing and aside from a packet trace I am confident there is this traffic on the network. I know this because we are trying to resolve an issue with a stack of X440's that keep rebooting because the CPU seems to be getting overwhelmed with packets from these address - as diagnosed by GTAC.&lt;BR /&gt;
&lt;BR /&gt;
Policies at Policy Server:&lt;BR /&gt;
Policy: Block_MDNS_Ingress&lt;BR /&gt;
entry Block_1_MDNS_Ingress {&lt;BR /&gt;
if match all {&lt;BR /&gt;
    source-address 224.0.0.251/32 ;&lt;BR /&gt;
}&lt;BR /&gt;
then {&lt;BR /&gt;
    deny  ;&lt;BR /&gt;
    packet-count Block_251_MDNS_Ingress ;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
entry Block_2_MDNS_Ingress {&lt;BR /&gt;
if match all {&lt;BR /&gt;
    source-address 224.0.0.252/32 ;&lt;BR /&gt;
}&lt;BR /&gt;
then {&lt;BR /&gt;
    deny  ;&lt;BR /&gt;
    packet-count Block_252_MDNS_Ingress ;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
entry Block_3_MDNS_Ingress {&lt;BR /&gt;
if match all {&lt;BR /&gt;
    source-address 239.255.255.250/32 ;&lt;BR /&gt;
}&lt;BR /&gt;
then {&lt;BR /&gt;
    deny  ;&lt;BR /&gt;
    packet-count Block_250_MDNS_Ingress ;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
Number of clients bound to policy: 1&lt;BR /&gt;
Client: acl bound once&lt;BR /&gt;
&lt;BR /&gt;
System Type:      X440-48p (Stack)&lt;BR /&gt;
&lt;BR /&gt;
SysHealth check:  Enabled (Normal)&lt;BR /&gt;
Recovery Mode:    All&lt;BR /&gt;
System Watchdog:  Enabled&lt;BR /&gt;
&lt;BR /&gt;
Current Time:     Sat Sep 12 16:28:48 2015&lt;BR /&gt;
Timezone:         [Auto DST Disabled] GMT Offset: 0 minutes, name is UTC.&lt;BR /&gt;
Boot Time:        Fri Aug 28 00:37:38 2015&lt;BR /&gt;
Boot Count:       135&lt;BR /&gt;
Next Reboot:      None scheduled&lt;BR /&gt;
System UpTime:    15 days 15 hours 51 minutes 9 seconds&lt;BR /&gt;
&lt;BR /&gt;
Slot:             Slot-1 *                     Slot-2&lt;BR /&gt;
                  ------------------------     ------------------------&lt;BR /&gt;
Current State:    MASTER                       BACKUP (In Sync)&lt;BR /&gt;
&lt;BR /&gt;
Image Selected:   secondary                    secondary&lt;BR /&gt;
Image Booted:     secondary                    secondary&lt;BR /&gt;
Primary ver:      15.3.1.4                     15.3.1.4&lt;BR /&gt;
Secondary ver:    15.5.4.2                     15.5.4.2&lt;BR /&gt;
                  patch1-5                     patch1-5&lt;BR /&gt;
&lt;BR /&gt;
Config Selected:  primary.cfg&lt;BR /&gt;
Config Booted:    Factory Default&lt;BR /&gt;
&lt;BR /&gt;
primary.cfg       Created by ExtremeXOS version 15.5.4.2&lt;BR /&gt;
                  2246563 bytes saved on Fri Sep 11 07:54:18 2015&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance.&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Sat, 12 Sep 2015 21:30:00 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2015-09-12T21:30:00Z</dc:date>
    <item>
      <title>ACL to Deny MDNS working?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44498#M10920</link>
      <description>Have created an ACL that is meant to be blocking MDNS multicast addresses and an additional address used my Microsoft.&lt;BR /&gt;
&lt;BR /&gt;
Have written the ACL to every port on Ingress so that I can see hits per port.&lt;BR /&gt;
&lt;BR /&gt;
Problem is I'm not seeing the counters incrementing and aside from a packet trace I am confident there is this traffic on the network. I know this because we are trying to resolve an issue with a stack of X440's that keep rebooting because the CPU seems to be getting overwhelmed with packets from these address - as diagnosed by GTAC.&lt;BR /&gt;
&lt;BR /&gt;
Policies at Policy Server:&lt;BR /&gt;
Policy: Block_MDNS_Ingress&lt;BR /&gt;
entry Block_1_MDNS_Ingress {&lt;BR /&gt;
if match all {&lt;BR /&gt;
    source-address 224.0.0.251/32 ;&lt;BR /&gt;
}&lt;BR /&gt;
then {&lt;BR /&gt;
    deny  ;&lt;BR /&gt;
    packet-count Block_251_MDNS_Ingress ;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
entry Block_2_MDNS_Ingress {&lt;BR /&gt;
if match all {&lt;BR /&gt;
    source-address 224.0.0.252/32 ;&lt;BR /&gt;
}&lt;BR /&gt;
then {&lt;BR /&gt;
    deny  ;&lt;BR /&gt;
    packet-count Block_252_MDNS_Ingress ;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
entry Block_3_MDNS_Ingress {&lt;BR /&gt;
if match all {&lt;BR /&gt;
    source-address 239.255.255.250/32 ;&lt;BR /&gt;
}&lt;BR /&gt;
then {&lt;BR /&gt;
    deny  ;&lt;BR /&gt;
    packet-count Block_250_MDNS_Ingress ;&lt;BR /&gt;
}&lt;BR /&gt;
}&lt;BR /&gt;
Number of clients bound to policy: 1&lt;BR /&gt;
Client: acl bound once&lt;BR /&gt;
&lt;BR /&gt;
System Type:      X440-48p (Stack)&lt;BR /&gt;
&lt;BR /&gt;
SysHealth check:  Enabled (Normal)&lt;BR /&gt;
Recovery Mode:    All&lt;BR /&gt;
System Watchdog:  Enabled&lt;BR /&gt;
&lt;BR /&gt;
Current Time:     Sat Sep 12 16:28:48 2015&lt;BR /&gt;
Timezone:         [Auto DST Disabled] GMT Offset: 0 minutes, name is UTC.&lt;BR /&gt;
Boot Time:        Fri Aug 28 00:37:38 2015&lt;BR /&gt;
Boot Count:       135&lt;BR /&gt;
Next Reboot:      None scheduled&lt;BR /&gt;
System UpTime:    15 days 15 hours 51 minutes 9 seconds&lt;BR /&gt;
&lt;BR /&gt;
Slot:             Slot-1 *                     Slot-2&lt;BR /&gt;
                  ------------------------     ------------------------&lt;BR /&gt;
Current State:    MASTER                       BACKUP (In Sync)&lt;BR /&gt;
&lt;BR /&gt;
Image Selected:   secondary                    secondary&lt;BR /&gt;
Image Booted:     secondary                    secondary&lt;BR /&gt;
Primary ver:      15.3.1.4                     15.3.1.4&lt;BR /&gt;
Secondary ver:    15.5.4.2                     15.5.4.2&lt;BR /&gt;
                  patch1-5                     patch1-5&lt;BR /&gt;
&lt;BR /&gt;
Config Selected:  primary.cfg&lt;BR /&gt;
Config Booted:    Factory Default&lt;BR /&gt;
&lt;BR /&gt;
primary.cfg       Created by ExtremeXOS version 15.5.4.2&lt;BR /&gt;
                  2246563 bytes saved on Fri Sep 11 07:54:18 2015&lt;BR /&gt;
&lt;BR /&gt;
Many thanks in advance.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 12 Sep 2015 21:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44498#M10920</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-09-12T21:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL to Deny MDNS working?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44499#M10921</link>
      <description>Hi Martin,&lt;BR /&gt;
&lt;BR /&gt;
It looks like you specified source-address in the policy file, rather than destination-address. For MDNS traffic, the source will be the IP of the device that is sending the traffic, and the destination will be the MDNS multicast group.&lt;BR /&gt;
&lt;BR /&gt;
If you just change 'source-address' to 'destination-address' in the policy file, it should work.&lt;BR /&gt;
&lt;BR /&gt;
Note that you will need to either remove and re-apply the ACL, or refresh it with the command 'refresh policy '.&lt;BR /&gt;
&lt;BR /&gt;
-Brandon&lt;BR /&gt;
&lt;BR /&gt;
Edit: Changed 'group-address' to 'destination-address'</description>
      <pubDate>Sat, 12 Sep 2015 21:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44499#M10921</guid>
      <dc:creator>BrandonC</dc:creator>
      <dc:date>2015-09-12T21:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL to Deny MDNS working?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44500#M10922</link>
      <description>Brilliant! Thanks Brandon - obvious when you think about it </description>
      <pubDate>Sat, 12 Sep 2015 21:40:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44500#M10922</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-09-12T21:40:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL to Deny MDNS working?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44501#M10923</link>
      <description>Got this error for group-address:&lt;BR /&gt;
&lt;BR /&gt;
configure access-list Block_MDNS_Ingress ports 1:1-48 ingress&lt;BR /&gt;
Error: Policy Block_MDNS_Ingress has syntax errors&lt;BR /&gt;
Line 3 : "group-address" is not a valid attribute&lt;BR /&gt;
&lt;BR /&gt;
I'll change it to destination address.&lt;BR /&gt;
&lt;BR /&gt;
Thanks.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Sat, 12 Sep 2015 21:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44501#M10923</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-09-12T21:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL to Deny MDNS working?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44502#M10924</link>
      <description>Sorry, that should be 'destination-address'. Looks like my brain got ahead of my fingers when I was typing!</description>
      <pubDate>Sat, 12 Sep 2015 21:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/acl-to-deny-mdns-working/m-p/44502#M10924</guid>
      <dc:creator>BrandonC</dc:creator>
      <dc:date>2015-09-12T21:44:00Z</dc:date>
    </item>
  </channel>
</rss>

