<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: ACL applying over VLAN in ExtremeSwitching (Other)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10343#M1371</link>
    <description>as VLAN-1 is used for uplink, but VLAN-2 and VLAN-3 users should communicate.</description>
    <pubDate>Tue, 13 Mar 2018 12:52:00 GMT</pubDate>
    <dc:creator>Alok_Shukla</dc:creator>
    <dc:date>2018-03-13T12:52:00Z</dc:date>
    <item>
      <title>ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10338#M1366</link>
      <description>We have three VLAN's all are inter-VLAN routing.&lt;BR /&gt;
VLAN-1= 10.3.1.0&lt;BR /&gt;
VLAN-2= 10.3.2.0&lt;BR /&gt;
VLAN-3= 10.3.5.0&lt;BR /&gt;
My boss wants to VLAN-2 and 3 should not communicate with VLAN-1, so that's we implement a policy to disable traffic forwarding to VLAN-1.&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="20de3869ed914b83a5ee46919b85c26d_RackMultipart20180313-123421-13boxvu-policy_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/529iB9049A81C0E9C956/image-size/large?v=v2&amp;amp;px=999" role="button" title="20de3869ed914b83a5ee46919b85c26d_RackMultipart20180313-123421-13boxvu-policy_inline.jpg" alt="20de3869ed914b83a5ee46919b85c26d_RackMultipart20180313-123421-13boxvu-policy_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
After applying this policy over VLAN-1 in ingress direction, VLAN-2 and VLAN-3 is not communicating.&lt;BR /&gt;
&lt;BR /&gt;
I want VLAN-2 and VLAN-3 Should communicate each other.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10338#M1366</guid>
      <dc:creator>Alok_Shukla</dc:creator>
      <dc:date>2018-03-13T12:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10339#M1367</link>
      <description>Easier option would be to disable ip forwarding for vlan 1</description>
      <pubDate>Tue, 13 Mar 2018 12:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10339#M1367</guid>
      <dc:creator>Andre_Brits_Kan</dc:creator>
      <dc:date>2018-03-13T12:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10340#M1368</link>
      <description>usually vlans are used to separate traffic. So from pure switching point and no bad cable based vlan translations they dont see each other.  May be you implemented some routing. if so follow the proposal from alok.</description>
      <pubDate>Tue, 13 Mar 2018 12:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10340#M1368</guid>
      <dc:creator>Immo_Wetzel</dc:creator>
      <dc:date>2018-03-13T12:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10341#M1369</link>
      <description>I don't want to disable ipforwarding of vlan-1&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10341#M1369</guid>
      <dc:creator>Alok_Shukla</dc:creator>
      <dc:date>2018-03-13T12:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10342#M1370</link>
      <description>if vlan 1 should not communicate with vlan 2 what are you doing with ip forwarding ?  switching will be done anyway or do you talk about an additional uplink ?</description>
      <pubDate>Tue, 13 Mar 2018 12:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10342#M1370</guid>
      <dc:creator>Immo_Wetzel</dc:creator>
      <dc:date>2018-03-13T12:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10343#M1371</link>
      <description>as VLAN-1 is used for uplink, but VLAN-2 and VLAN-3 users should communicate.</description>
      <pubDate>Tue, 13 Mar 2018 12:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10343#M1371</guid>
      <dc:creator>Alok_Shukla</dc:creator>
      <dc:date>2018-03-13T12:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10344#M1372</link>
      <description>dont get you. if vlan 2 and vlan 3 should be able to use the uplink. but the uplink connected hosts should not reach vlan 2 and 3 you need a firewall.   if vlan2 and vlan 3 should not reach the uplink just disable ipforwarding for vlan 1 cos there is no need for.</description>
      <pubDate>Tue, 13 Mar 2018 12:52:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10344#M1372</guid>
      <dc:creator>Immo_Wetzel</dc:creator>
      <dc:date>2018-03-13T12:52:00Z</dc:date>
    </item>
    <item>
      <title>RE: ACL applying over VLAN</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10345#M1373</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
you have:&lt;BR /&gt;
&lt;BR /&gt;
- VLAN-1= 10.3.1.0/24 &lt;BR /&gt;
- VLAN-2= 10.3.2.0/24&lt;BR /&gt;
- VLAN-3= 10.3.5.0/24&lt;BR /&gt;
&lt;BR /&gt;
and you want to block traffic from VLAN-2 to VLAN-1&lt;BR /&gt;
then you should apply ACL on VLAN-2 on ingress like bellow:&lt;BR /&gt;
&lt;BR /&gt;
entry V1_block { if match all {&lt;BR /&gt;
 destination-address 10.3.1.0/24;&lt;BR /&gt;
 } then {&lt;BR /&gt;
 count traffic_to_v1;&lt;BR /&gt;
 deny;&lt;BR /&gt;
}}&lt;BR /&gt;
&lt;BR /&gt;
Similar example will be for VLAN-3.&lt;BR /&gt;
&lt;BR /&gt;
--&lt;BR /&gt;
Jarek</description>
      <pubDate>Tue, 13 Mar 2018 17:41:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/acl-applying-over-vlan/m-p/10345#M1373</guid>
      <dc:creator>Jarek</dc:creator>
      <dc:date>2018-03-13T17:41:00Z</dc:date>
    </item>
  </channel>
</rss>

