<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Layer-2 security (IP-address conflict etc). in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27796#M4121</link>
    <description>You add vlan "Wan-devices" to different STP-domains or you are misconfigured and you try to add private-vlans into one vlan?</description>
    <pubDate>Tue, 06 Jun 2017 23:18:00 GMT</pubDate>
    <dc:creator>Nick_Yakimenko</dc:creator>
    <dc:date>2017-06-06T23:18:00Z</dc:date>
    <item>
      <title>Layer-2 security (IP-address conflict etc).</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27795#M4120</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
The company i work for recently has a new network to maintain, this network consists of multiple Extreme Network switches which haven’t been configured right security wise (IMO).&lt;BR /&gt;
Me or my colleagues don’t have much experiance with Extreme switches so i hope any of you can help me/us.&lt;BR /&gt;
&lt;BR /&gt;
The case:&lt;BR /&gt;
- The switch (X670-G1) has three ports (20,21 and 22) which are connected to “carriers”.&lt;BR /&gt;
- The “carriers” provide VLAN(s) which are all combined into one VLAN (Port-specific Tag).&lt;BR /&gt;
- The VLANS(s) are customer locations beyond our control.&lt;BR /&gt;
- Layer-2 only, routing is done with a (Juniper) router connected to port 24.&lt;BR /&gt;
&lt;BR /&gt;
My problem with this setup:&lt;BR /&gt;
- The customers can configure any IP-address they want (possibly causing an IP conflict).&lt;BR /&gt;
- The customers can possibly exhaust the mac table.&lt;BR /&gt;
- ????&lt;BR /&gt;
The config:&lt;BR /&gt;
&lt;BR /&gt;
create vlan "WAN-devices"&lt;BR /&gt;
configure vlan WAN-devices tag 2&lt;BR /&gt;
disable igmp snooping vlan "WAN-devices"&lt;BR /&gt;
configure vlan WAN-devices add ports 24 tagged&lt;BR /&gt;
configure vlan WAN-devices add ports 21 tagged 251&lt;BR /&gt;
configure vlan WAN-devices add ports 21 tagged 252&lt;BR /&gt;
configure vlan WAN-devices add ports 21 tagged 253&lt;BR /&gt;
configure vlan WAN-devices add ports 21 tagged 254&lt;BR /&gt;
configure vlan WAN-devices add ports 21 tagged 255&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1372&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1373&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1374&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1375&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1376&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1377&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1378&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1379&lt;BR /&gt;
configure vlan WAN-devices add ports 22 tagged 1380&lt;BR /&gt;
configure vlan WAN-devices add ports 20 tagged 2001&lt;BR /&gt;
&lt;BR /&gt;
VLANS 25X, 13XX and 2001 are outside of my controll, all devices use the same (/25) subnet, the (Juniper) router&lt;BR /&gt;
acts as a gateway for the /25 subnet.&lt;BR /&gt;
My question:&lt;BR /&gt;
Can i do anywhing in the X670 switch to prevent the customers from using more than (1) IP-address and mac-address?&lt;BR /&gt;
The network consists of both static and DHCP IP-addresses. Any other advice is offcourse welcome!&lt;BR /&gt;
&lt;BR /&gt;
I really appreciate any help you can provide.&lt;BR /&gt;</description>
      <pubDate>Tue, 06 Jun 2017 20:43:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27795#M4120</guid>
      <dc:creator>Gilu_Debee</dc:creator>
      <dc:date>2017-06-06T20:43:00Z</dc:date>
    </item>
    <item>
      <title>RE: Layer-2 security (IP-address conflict etc).</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27796#M4121</link>
      <description>You add vlan "Wan-devices" to different STP-domains or you are misconfigured and you try to add private-vlans into one vlan?</description>
      <pubDate>Tue, 06 Jun 2017 23:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27796#M4121</guid>
      <dc:creator>Nick_Yakimenko</dc:creator>
      <dc:date>2017-06-06T23:18:00Z</dc:date>
    </item>
    <item>
      <title>RE: Layer-2 security (IP-address conflict etc).</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27797#M4122</link>
      <description>I think the second one is the case here since the router for all VLANS are routed by the router on port 24.</description>
      <pubDate>Tue, 06 Jun 2017 23:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27797#M4122</guid>
      <dc:creator>Gilu_Debee</dc:creator>
      <dc:date>2017-06-06T23:18:00Z</dc:date>
    </item>
    <item>
      <title>RE: Layer-2 security (IP-address conflict etc).</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27798#M4123</link>
      <description>Hi Gilu,&lt;BR /&gt;
&lt;BR /&gt;
I don't understand, since your X670 is working on L2 only, why are you asking about IP address conflict? It should be Juniper router problem not Extreme switch problem. Regarding MAC capacity, do you think 128K MAC capacity will give you problem?&lt;BR /&gt;
&lt;BR /&gt;
Anyway, why don't you put separate VLAN for each subnet and send them all to Juniper router so each VLAN will have their own gateway? It seem that you only do VLAN translation from many tags to single VLAN tag.&lt;BR /&gt;
&lt;BR /&gt;
Best regards,</description>
      <pubDate>Thu, 08 Jun 2017 00:14:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/layer-2-security-ip-address-conflict-etc/m-p/27798#M4123</guid>
      <dc:creator>Mrxlazuardin</dc:creator>
      <dc:date>2017-06-08T00:14:00Z</dc:date>
    </item>
  </channel>
</rss>

