<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: how can I create a access-list on egress to allow only a few vlans inside a vman ? drop all doesnt work too in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-can-i-create-a-access-list-on-egress-to-allow-only-a-few/m-p/56970#M16769</link>
    <description>Hi Immo,&lt;BR /&gt;
&lt;BR /&gt;
It sounds like what you want to do is configure port 3 as a customer edge port, allowing inner tags 100 and 102 only.&lt;BR /&gt;
&lt;BR /&gt;
For example,&lt;BR /&gt;
configure vman &lt;VMAN_NAME&gt; add port 3 cep cvid 100 configure vman &lt;VMAN_NAME&gt; add port 3 cep cvid 102You can see more info on this at the link below:&lt;BR /&gt;
&lt;A href="https://documentation.extremenetworks.com/exos_commands_22.4/EXOS_21_1/EXOS_Commands_All/r_configure-vman-add-ports-cep.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/exos_commands_22.4/EXOS_21_1/EXOS_Commands_All/r_configure...&lt;/A&gt;&lt;/VMAN_NAME&gt;&lt;/VMAN_NAME&gt;</description>
    <pubDate>Tue, 13 Mar 2018 01:10:00 GMT</pubDate>
    <dc:creator>BrandonC</dc:creator>
    <dc:date>2018-03-13T01:10:00Z</dc:date>
    <item>
      <title>how can I create a access-list on egress to allow only a few vlans inside a vman ? drop all doesnt work too</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-can-i-create-a-access-list-on-egress-to-allow-only-a-few/m-p/56969#M16768</link>
      <description>HI,&lt;BR /&gt;
my target is to allow only a few vlans from a vman to exit a specific port.&lt;BR /&gt;
&lt;BR /&gt;
example port 1, 2 and 3  at untagged in vman 2000.&lt;BR /&gt;
all traffic from 1 should be forwarded to 2 and vice versa. only vlan 100 and 102 should be forwarded to port 3..  I do not know the vlans inserted into port 1 and 2 except 100 and 102 therefore the vman untagged idea.&lt;BR /&gt;
&lt;BR /&gt;
to start I tried a deny all rule on port 3&lt;BR /&gt;
docu say egress rule:&lt;BR /&gt;
denyAll.pol&lt;BR /&gt;
entry DenyAllEgress{&lt;BR /&gt;
    if {&lt;BR /&gt;
        source-address 0.0.0.0/0;&lt;BR /&gt;
    } then {&lt;BR /&gt;
        deny;&lt;BR /&gt;
    }&lt;BR /&gt;
}but after &lt;BR /&gt;
configure access-list denyAll ports 3 egress&lt;BR /&gt;
still all traffic is visible at port 3 and also on the next switch...&lt;BR /&gt;
&lt;BR /&gt;
Whats the fault and whats the solution ?</description>
      <pubDate>Tue, 13 Mar 2018 00:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-can-i-create-a-access-list-on-egress-to-allow-only-a-few/m-p/56969#M16768</guid>
      <dc:creator>Immo_Wetzel</dc:creator>
      <dc:date>2018-03-13T00:02:00Z</dc:date>
    </item>
    <item>
      <title>RE: how can I create a access-list on egress to allow only a few vlans inside a vman ? drop all doesnt work too</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-can-i-create-a-access-list-on-egress-to-allow-only-a-few/m-p/56970#M16769</link>
      <description>Hi Immo,&lt;BR /&gt;
&lt;BR /&gt;
It sounds like what you want to do is configure port 3 as a customer edge port, allowing inner tags 100 and 102 only.&lt;BR /&gt;
&lt;BR /&gt;
For example,&lt;BR /&gt;
configure vman &lt;VMAN_NAME&gt; add port 3 cep cvid 100 configure vman &lt;VMAN_NAME&gt; add port 3 cep cvid 102You can see more info on this at the link below:&lt;BR /&gt;
&lt;A href="https://documentation.extremenetworks.com/exos_commands_22.4/EXOS_21_1/EXOS_Commands_All/r_configure-vman-add-ports-cep.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;https://documentation.extremenetworks.com/exos_commands_22.4/EXOS_21_1/EXOS_Commands_All/r_configure...&lt;/A&gt;&lt;/VMAN_NAME&gt;&lt;/VMAN_NAME&gt;</description>
      <pubDate>Tue, 13 Mar 2018 01:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-can-i-create-a-access-list-on-egress-to-allow-only-a-few/m-p/56970#M16769</guid>
      <dc:creator>BrandonC</dc:creator>
      <dc:date>2018-03-13T01:10:00Z</dc:date>
    </item>
    <item>
      <title>RE: how can I create a access-list on egress to allow only a few vlans inside a vman ? drop all doesnt work too</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-can-i-create-a-access-list-on-egress-to-allow-only-a-few/m-p/56971#M16770</link>
      <description>ok but how about untagged and vlan 0 traffic ?</description>
      <pubDate>Tue, 13 Mar 2018 01:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-can-i-create-a-access-list-on-egress-to-allow-only-a-few/m-p/56971#M16770</guid>
      <dc:creator>Immo_Wetzel</dc:creator>
      <dc:date>2018-03-13T01:10:00Z</dc:date>
    </item>
  </channel>
</rss>

