<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EXOSVM access-list help in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exosvm-access-list-help/m-p/60983#M17724</link>
    <description>&lt;P&gt;Hello, I have lab in GNS3 with 2 pc, exosvm switch and ubuntu server with www on apache and SSH. How can I connect PC1 only to www site and PC2 only to SSH. How can I use ACL to do it? Any advice?&amp;nbsp;&lt;BR /&gt;I’m glad for any help.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2020 01:27:00 GMT</pubDate>
    <dc:creator>jasiowski</dc:creator>
    <dc:date>2020-11-26T01:27:00Z</dc:date>
    <item>
      <title>EXOSVM access-list help</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exosvm-access-list-help/m-p/60983#M17724</link>
      <description>&lt;P&gt;Hello, I have lab in GNS3 with 2 pc, exosvm switch and ubuntu server with www on apache and SSH. How can I connect PC1 only to www site and PC2 only to SSH. How can I use ACL to do it? Any advice?&amp;nbsp;&lt;BR /&gt;I’m glad for any help.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 01:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exosvm-access-list-help/m-p/60983#M17724</guid>
      <dc:creator>jasiowski</dc:creator>
      <dc:date>2020-11-26T01:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: EXOSVM access-list help</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exosvm-access-list-help/m-p/60984#M17725</link>
      <description>&lt;P&gt;Jasioswski,&lt;/P&gt;&lt;P&gt;Here from my cheat sheet:&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;#STATIC = from a policy&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;'1-Check if there are enough ACL resources available&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;'2-Create a STATIC ACL policy file&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;#edit policy &amp;lt;policy-name&amp;gt;.pol 'edit = vi&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;# entry &amp;lt;rule-name&amp;gt; {&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;# if {&amp;lt;condition&amp;gt;;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;# then{&amp;lt;actions&amp;gt;;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;# }&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;edit policy denyTelnet.pol&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;entry noTelnet {&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;if {&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;destination-address 10.1.10.1/32;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;source-address 10.1.10.101/32;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;protocol tcp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;destination-port 23;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;then {&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;deny;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;'3-Save or copy the policy file to the flash as .pol&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;'4-Check the policy for syntax errors&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;check policy &amp;lt;policy-name&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;'5-Apply the policy to port(s), VLAN(s) or any "wildcard"&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;#immediately applied&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;#precedence is port, VLAN, wildcard&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;configure access-list &amp;lt;policy-name&amp;gt;.pol ports &amp;lt;ports_numbers&amp;gt;[ingress|egress]&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;configure access-list &amp;lt;policy-name&amp;gt;.pol vlan &amp;lt;vlan_name|vlan_ID&amp;gt;[ingress|egress]&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;configure access-list &amp;lt;policy-name&amp;gt;.pol any [ingress|egress]&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;refresh policy &amp;lt;policy_name&amp;gt; 'will refresh the deployment of the policy&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;'6-VERIFY&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;show policy&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;show policy &amp;lt;policy-name&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;show access-list&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 17:01:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exosvm-access-list-help/m-p/60984#M17725</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2020-11-28T17:01:19Z</dc:date>
    </item>
  </channel>
</rss>

