<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WoL Wake on LAN to routed remote location in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63357#M18023</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I’ve a customer with routed remote-locations via MPLS.&lt;/P&gt;&lt;P&gt;Wake on LAN on the main location is working fine (upd-profile with match-criteria to 3 source-IPs, dst-broadcast-mac and dst udp port)&lt;/P&gt;&lt;P&gt;To get WoL running on the remote-location (also routing exos) I need to send WoL Pakets to a remote Broadcast-IP-Address and enable directed broadcast in dst-vlan. In theorie…&amp;nbsp;not tested yet.&lt;/P&gt;&lt;P&gt;Now I need / I will reduce the security impact. Only directed broadcasts from a limited group of IPs should be accepted.&lt;/P&gt;&lt;P&gt;How can / should I do this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;ACL? UDP-Profile? Where to bind?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Sep 2021 18:21:52 GMT</pubDate>
    <dc:creator>PeterK</dc:creator>
    <dc:date>2021-09-29T18:21:52Z</dc:date>
    <item>
      <title>WoL Wake on LAN to routed remote location</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63357#M18023</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I’ve a customer with routed remote-locations via MPLS.&lt;/P&gt;&lt;P&gt;Wake on LAN on the main location is working fine (upd-profile with match-criteria to 3 source-IPs, dst-broadcast-mac and dst udp port)&lt;/P&gt;&lt;P&gt;To get WoL running on the remote-location (also routing exos) I need to send WoL Pakets to a remote Broadcast-IP-Address and enable directed broadcast in dst-vlan. In theorie…&amp;nbsp;not tested yet.&lt;/P&gt;&lt;P&gt;Now I need / I will reduce the security impact. Only directed broadcasts from a limited group of IPs should be accepted.&lt;/P&gt;&lt;P&gt;How can / should I do this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;ACL? UDP-Profile? Where to bind?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:21:52 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63357#M18023</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2021-09-29T18:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: WoL Wake on LAN to routed remote location</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63358#M18024</link>
      <description>&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000076686" target="_blank" rel="noreferrer noopener nofollow ugc"&gt;Q A: How does EXOS treat directed broadcast traffic? | Extreme Portal (force.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You could limit it by with an ACL, with two entries:&lt;/P&gt;&lt;P&gt;Allow Traffic to remote Broadcast-Address for some source addresses&lt;/P&gt;&lt;P&gt;Deny Traffic to remote Broadcast-Address.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 19:02:27 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63358#M18024</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2021-09-29T19:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: WoL Wake on LAN to routed remote location</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63359#M18025</link>
      <description>&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;The Question is, does it make sense to bind this ACL to the destination vlan on the remote-location?&lt;/P&gt;&lt;P&gt;If think, this could also effect broadcasts inside of the destination-vlan. So I think, it would make more sense to bind the ACL to the Transfer-VLAN of MPLS-Router.&lt;/P&gt;&lt;P&gt;Or, what do you think?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 19:12:28 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63359#M18025</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2021-09-29T19:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: WoL Wake on LAN to routed remote location</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63360#M18026</link>
      <description>&lt;P&gt;Good question. Broadcasts inside the VLAN are addresses for FF:FF:FF:FF:FF:FF / 255.255.255.255. A ACL that denies traffic to 192.168.1.255 (given that the subnet is 192.168.1.0/24) shouldn’t affect this.&lt;/P&gt;&lt;P&gt;Will the WoL Packets only be sent from the main location to remote locations? Why not map the ACL there?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 19:23:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63360#M18026</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2021-09-29T19:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: WoL Wake on LAN to routed remote location</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63361#M18027</link>
      <description>&lt;P&gt;You’re right. Normaly inside the vlan it should addressed as&amp;nbsp;FF:FF:FF:FF:FF:FF / 255.255.255.255.&lt;/P&gt;&lt;P&gt;But, is it impossible that something is sending to L3-Broadcastaddress inside the vlan? I’m not sure.&lt;/P&gt;&lt;P&gt;Yes, currently the WOL Pakets should only send from the main location.&lt;/P&gt;&lt;P&gt;I need to enable directed broadcast on the destination vlan. If I bind the ACL in the main location, I can not prevent the dst. vlan from directed broadcasts from other vlans in the same remote-location.&lt;/P&gt;&lt;P&gt;But than, I would make more sense again to bind ACL to destination vlan.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 20:35:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/wol-wake-on-lan-to-routed-remote-location/m-p/63361#M18027</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2021-09-29T20:35:06Z</dc:date>
    </item>
  </channel>
</rss>

