<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ingress ACL Block traffic to Private networks and Enable establish from Private Network in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ingress-acl-block-traffic-to-private-networks-and-enable/m-p/93962#M21668</link>
    <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;I am managing and testing an EXOS x435;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;Ingress ACL to VLAN8 to block all private traffic:&lt;/P&gt;&lt;P&gt;source VLAN8 destination All Private networks 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16&lt;/P&gt;&lt;P&gt;Apply rule to VLAN8 in Ingress (only), everything works.&lt;/P&gt;&lt;P&gt;but&lt;/P&gt;&lt;P&gt;I need to enable establish traffic from private networks to VLAN8.&lt;/P&gt;&lt;P&gt;I tried to set TCP-flags ACK and SYN_ACK but nothing, It doesn't work&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;THIS is the policy:&lt;/P&gt;&lt;P&gt;/*entry vlan8{&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;destination-address 10.5.207.192/27;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry responsePrivate1{&lt;BR /&gt;if match all{&lt;BR /&gt;destination-address 10.0.0.0/8;&lt;BR /&gt;protocol TCP;&lt;BR /&gt;TCP-flags ACK;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry responsePrivate2{&lt;BR /&gt;if match all{&lt;BR /&gt;destination-address 10.0.0.0/8;&lt;BR /&gt;protocol TCP;&lt;BR /&gt;TCP-flags SYN_ACK;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry rete10 {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;destination-address 10.0.0.0/8;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;deny;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry rete172 {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/24;&lt;BR /&gt;destination-address 172.16.0.0/12;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;deny;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry rete192 {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;destination-address 192.168.0.0/16;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;deny;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry resto {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;} */&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2022 15:36:23 GMT</pubDate>
    <dc:creator>marconet_22</dc:creator>
    <dc:date>2022-11-30T15:36:23Z</dc:date>
    <item>
      <title>Ingress ACL Block traffic to Private networks and Enable establish from Private Network</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ingress-acl-block-traffic-to-private-networks-and-enable/m-p/93962#M21668</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;I am managing and testing an EXOS x435;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;Ingress ACL to VLAN8 to block all private traffic:&lt;/P&gt;&lt;P&gt;source VLAN8 destination All Private networks 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16&lt;/P&gt;&lt;P&gt;Apply rule to VLAN8 in Ingress (only), everything works.&lt;/P&gt;&lt;P&gt;but&lt;/P&gt;&lt;P&gt;I need to enable establish traffic from private networks to VLAN8.&lt;/P&gt;&lt;P&gt;I tried to set TCP-flags ACK and SYN_ACK but nothing, It doesn't work&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;THIS is the policy:&lt;/P&gt;&lt;P&gt;/*entry vlan8{&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;destination-address 10.5.207.192/27;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry responsePrivate1{&lt;BR /&gt;if match all{&lt;BR /&gt;destination-address 10.0.0.0/8;&lt;BR /&gt;protocol TCP;&lt;BR /&gt;TCP-flags ACK;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry responsePrivate2{&lt;BR /&gt;if match all{&lt;BR /&gt;destination-address 10.0.0.0/8;&lt;BR /&gt;protocol TCP;&lt;BR /&gt;TCP-flags SYN_ACK;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry rete10 {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;destination-address 10.0.0.0/8;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;deny;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry rete172 {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/24;&lt;BR /&gt;destination-address 172.16.0.0/12;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;deny;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry rete192 {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;destination-address 192.168.0.0/16;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;deny;&lt;BR /&gt;}&lt;BR /&gt;}&lt;BR /&gt;entry resto {&lt;BR /&gt;if {&lt;BR /&gt;source-address 10.5.207.192/27;&lt;BR /&gt;}&lt;BR /&gt;then&lt;BR /&gt;{&lt;BR /&gt;permit;&lt;BR /&gt;}&lt;BR /&gt;} */&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 15:36:23 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/ingress-acl-block-traffic-to-private-networks-and-enable/m-p/93962#M21668</guid>
      <dc:creator>marconet_22</dc:creator>
      <dc:date>2022-11-30T15:36:23Z</dc:date>
    </item>
  </channel>
</rss>

