<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with SSH ACL policy on older switch models in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/issue-with-ssh-acl-policy-on-older-switch-models/m-p/97588#M22104</link>
    <description>&lt;DIV&gt;I am creating a new SSH ACL policy. I've already started rolling it out and applying it to various EXOS switches across our estate.&amp;nbsp; It has been absolutely fine on the X460-G2-48p-10GE4-Base units, but it is not working correctly on any of the X460-48p models I've tried it on:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;DIV&gt;vi My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;i&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;entry AllowTheseSubnets {&lt;/DIV&gt;&lt;DIV&gt;if match any {&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;source-address 10.0.0.0 /24 ;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;source-address 10.0.1.0 /24 ;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;} then {&lt;/DIV&gt;&lt;DIV&gt;permit;&lt;/DIV&gt;&lt;DIV&gt;}&lt;/DIV&gt;&lt;DIV&gt;}&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;It is displayed when issuing a simple 'ls':&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;DIV&gt;Slot-1 SW1.1 # ls&lt;/DIV&gt;&lt;DIV&gt;-rw-r--r--&amp;nbsp; &amp;nbsp; 1 admin&amp;nbsp; &amp;nbsp; admin&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;966 Oct 17 14:52 My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;&amp;lt;output omitted&amp;gt;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.2 #&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;... but it is not recognized if I try to apply it to something:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;DIV&gt;Slot-1 SW1.2 #&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.2 # configure ssh2 access-profile My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;Error: Policy /config/My_SSH_Policy.pol.pol does not exist on file system&lt;/DIV&gt;&lt;DIV&gt;Configuration failed on backup Node, command execution aborted!&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.3 #&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.3 #&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.3 # check pol My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Error:&amp;nbsp; Policy My_SSH_Policy.pol does not exist on file&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.4 #&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Why is it not recognized on the X460-48p models ?&lt;/DIV&gt;</description>
    <pubDate>Tue, 17 Oct 2023 16:00:35 GMT</pubDate>
    <dc:creator>MartinS</dc:creator>
    <dc:date>2023-10-17T16:00:35Z</dc:date>
    <item>
      <title>Issue with SSH ACL policy on older switch models</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/issue-with-ssh-acl-policy-on-older-switch-models/m-p/97588#M22104</link>
      <description>&lt;DIV&gt;I am creating a new SSH ACL policy. I've already started rolling it out and applying it to various EXOS switches across our estate.&amp;nbsp; It has been absolutely fine on the X460-G2-48p-10GE4-Base units, but it is not working correctly on any of the X460-48p models I've tried it on:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;DIV&gt;vi My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;i&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;entry AllowTheseSubnets {&lt;/DIV&gt;&lt;DIV&gt;if match any {&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;source-address 10.0.0.0 /24 ;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;source-address 10.0.1.0 /24 ;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;} then {&lt;/DIV&gt;&lt;DIV&gt;permit;&lt;/DIV&gt;&lt;DIV&gt;}&lt;/DIV&gt;&lt;DIV&gt;}&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;It is displayed when issuing a simple 'ls':&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;DIV&gt;Slot-1 SW1.1 # ls&lt;/DIV&gt;&lt;DIV&gt;-rw-r--r--&amp;nbsp; &amp;nbsp; 1 admin&amp;nbsp; &amp;nbsp; admin&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;966 Oct 17 14:52 My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;&amp;lt;output omitted&amp;gt;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.2 #&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;... but it is not recognized if I try to apply it to something:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;DIV&gt;Slot-1 SW1.2 #&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.2 # configure ssh2 access-profile My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;Error: Policy /config/My_SSH_Policy.pol.pol does not exist on file system&lt;/DIV&gt;&lt;DIV&gt;Configuration failed on backup Node, command execution aborted!&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.3 #&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.3 #&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.3 # check pol My_SSH_Policy.pol&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Error:&amp;nbsp; Policy My_SSH_Policy.pol does not exist on file&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Slot-1 SW1.4 #&amp;nbsp;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Why is it not recognized on the X460-48p models ?&lt;/DIV&gt;</description>
      <pubDate>Tue, 17 Oct 2023 16:00:35 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/issue-with-ssh-acl-policy-on-older-switch-models/m-p/97588#M22104</guid>
      <dc:creator>MartinS</dc:creator>
      <dc:date>2023-10-17T16:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with SSH ACL policy on older switch models</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/issue-with-ssh-acl-policy-on-older-switch-models/m-p/97596#M22107</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;the error message looks like that you shoud not ud .pol:&lt;BR /&gt;&amp;gt; Slot-1 SW1.2 # configure ssh2 access-profile My_SSH_Policy.pol&lt;BR /&gt;&amp;gt; Error: Policy /config/&lt;STRONG&gt;My_SSH_Policy.pol.pol&lt;/STRONG&gt; does not exist on file system&lt;BR /&gt;&amp;gt; Configuration failed on backup Node, command execution aborted!&lt;/P&gt;&lt;P&gt;Whats happend if you try (without .pol):&lt;BR /&gt;configure ssh2 access-profile My_SSH_Policy&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Axel&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 13:41:19 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/issue-with-ssh-acl-policy-on-older-switch-models/m-p/97596#M22107</guid>
      <dc:creator>ar1</dc:creator>
      <dc:date>2023-10-18T13:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with SSH ACL policy on older switch models</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/issue-with-ssh-acl-policy-on-older-switch-models/m-p/97600#M22108</link>
      <description>&lt;P&gt;When I try that it works!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 11:48:53 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/issue-with-ssh-acl-policy-on-older-switch-models/m-p/97600#M22108</guid>
      <dc:creator>MartinS</dc:creator>
      <dc:date>2023-10-19T11:48:53Z</dc:date>
    </item>
  </channel>
</rss>

