<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EXOS ACL for block inter VLAN traffic in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-acl-for-block-inter-vlan-traffic/m-p/73625#M19120</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I need a advice from you regarding the acl configuration.&lt;/P&gt;&lt;P&gt;Scenario;&lt;/P&gt;&lt;P&gt;There are five VLANs names “Manage, VLAN1, VLAN2, VLAN3, VLAN4” All VLANs dhcp pools configured in core switch. Core is&amp;nbsp;X460-24p stack.&lt;/P&gt;&lt;P&gt;My points are:&lt;/P&gt;&lt;P&gt;1). All traffic from VLAN 1-4 to Manage VLAN should be block.&lt;/P&gt;&lt;P&gt;2). Manage VLAN can be access other VLANs&amp;nbsp;&lt;/P&gt;&lt;P&gt;3). VLAN3 and VLAN4 can not communicate each other and also can not access VLAN 1 and VLAN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2.&lt;/P&gt;&lt;P&gt;4). VLAN 1 and VLAN 2 can communicate each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created 5 different static ACLs as follow and apply each vlan as ingress. But those are not working and even there is no count.&lt;/P&gt;&lt;P&gt;entry denyUPC{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if match all{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; source-address 10.10.10.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; destination-address 192.168.20.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; then{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count denyUPC;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; deny;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;entry denyUPC1{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if match all{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; source-address 172.16.100.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; destination-address 192.168.20.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; then{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count denyUPC;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; deny;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help to solve this.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Gihan&lt;/P&gt;</description>
    <pubDate>Mon, 14 Sep 2020 12:31:57 GMT</pubDate>
    <dc:creator>Gihan1</dc:creator>
    <dc:date>2020-09-14T12:31:57Z</dc:date>
    <item>
      <title>EXOS ACL for block inter VLAN traffic</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-acl-for-block-inter-vlan-traffic/m-p/73625#M19120</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I need a advice from you regarding the acl configuration.&lt;/P&gt;&lt;P&gt;Scenario;&lt;/P&gt;&lt;P&gt;There are five VLANs names “Manage, VLAN1, VLAN2, VLAN3, VLAN4” All VLANs dhcp pools configured in core switch. Core is&amp;nbsp;X460-24p stack.&lt;/P&gt;&lt;P&gt;My points are:&lt;/P&gt;&lt;P&gt;1). All traffic from VLAN 1-4 to Manage VLAN should be block.&lt;/P&gt;&lt;P&gt;2). Manage VLAN can be access other VLANs&amp;nbsp;&lt;/P&gt;&lt;P&gt;3). VLAN3 and VLAN4 can not communicate each other and also can not access VLAN 1 and VLAN&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2.&lt;/P&gt;&lt;P&gt;4). VLAN 1 and VLAN 2 can communicate each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created 5 different static ACLs as follow and apply each vlan as ingress. But those are not working and even there is no count.&lt;/P&gt;&lt;P&gt;entry denyUPC{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if match all{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; source-address 10.10.10.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; destination-address 192.168.20.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; then{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count denyUPC;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; deny;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;entry denyUPC1{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if match all{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; source-address 172.16.100.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; destination-address 192.168.20.254/24;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; then{&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count denyUPC;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; deny;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help to solve this.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Gihan&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 12:31:57 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-acl-for-block-inter-vlan-traffic/m-p/73625#M19120</guid>
      <dc:creator>Gihan1</dc:creator>
      <dc:date>2020-09-14T12:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS ACL for block inter VLAN traffic</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-acl-for-block-inter-vlan-traffic/m-p/73626#M19121</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;EXOS ACLs are evaluated in order and have an implicit permit at the end. So, two entries will be necessary--one to deny traffic from each source subnet to each destination subnet. All other traffic (i.e. internet traffic) will be permitted:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is an article that describes it in more detail:&lt;/P&gt;&lt;P&gt;&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-use-an-ACL-to-prevent-inter-VLAN-traffic-for-internal-subnets-but-allow-internet-traffic" target="_blank" rel="nofollow noreferrer noopener"&gt;How to use an ACL to prevent inter-VLAN traffic for internal subnets but allow internet traffic&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chris Thompson&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 02:16:34 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-acl-for-block-inter-vlan-traffic/m-p/73626#M19121</guid>
      <dc:creator>CThompsonEXOS</dc:creator>
      <dc:date>2020-09-26T02:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: EXOS ACL for block inter VLAN traffic</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-acl-for-block-inter-vlan-traffic/m-p/73627#M19122</link>
      <description>&lt;P&gt;as far as I remember EXOS ACLs are working at the port as well as you apply it on a vlan. This means, you need to permit traffic inside of each vlan too, if you have an explicit “deny any” at the end.&lt;/P&gt;&lt;P&gt;Also ACLs are not statefull. So in Case of 2. - You can’t permit Manage to access VLAN 1-4 if other direction is denied (1.).&lt;/P&gt;&lt;P&gt;You should have a look to “private vlan” function. - I think this should have more sense for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2020 16:25:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-acl-for-block-inter-vlan-traffic/m-p/73627#M19122</guid>
      <dc:creator>PeterK</dc:creator>
      <dc:date>2020-09-27T16:25:23Z</dc:date>
    </item>
  </channel>
</rss>

