<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fabric Engine with Mgmt CLIP and NAT Firewall in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-engine-with-mgmt-clip-and-nat-firewall/m-p/93487#M1947</link>
    <description>&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;You either use mgmt VLAN or mgmt CLIP.&lt;/P&gt;&lt;P&gt;If you use CLIP, there is no need to add a VLAN on the firewall, just a route would be needed (+ security policies).&lt;/P&gt;&lt;P&gt;Be carefull with Natting mgmt interface because it is the one used for Radius and XIQ-SE snmp communication.&lt;/P&gt;&lt;P&gt;You can also work with the same mgmgt VLAN for all your switches but again, the NATting could cause trouble with Radius and XIQ-SE snmp communication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
    <pubDate>Mon, 24 Oct 2022 07:22:25 GMT</pubDate>
    <dc:creator>Miguel-Angel_RO</dc:creator>
    <dc:date>2022-10-24T07:22:25Z</dc:date>
    <item>
      <title>Fabric Engine with Mgmt CLIP and NAT Firewall</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-engine-with-mgmt-clip-and-nat-firewall/m-p/93474#M1946</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If the general rule is to use CLIP as management interface for Fabric Engine with Segmented Management Interface when using L3 BEB or L3 non-fabric how can a connection be established using a NAT enabled Firewall?&lt;/P&gt;&lt;P&gt;Would we add a Mgmt VLAN and add it to the uplink to the Firewall so that it can be NATd?&lt;/P&gt;&lt;P&gt;I think this is the only option and would allow access to the CPU using a mgmt VLAN. We can have multiple management interfaces after all. With L3 enabled switch the mgmt VLAN would not be accessible from other local VLAN IP interfaces.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2022 16:10:30 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-engine-with-mgmt-clip-and-nat-firewall/m-p/93474#M1946</guid>
      <dc:creator>RobertD1</dc:creator>
      <dc:date>2022-10-21T16:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Fabric Engine with Mgmt CLIP and NAT Firewall</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-engine-with-mgmt-clip-and-nat-firewall/m-p/93487#M1947</link>
      <description>&lt;P&gt;Robert,&lt;/P&gt;&lt;P&gt;You either use mgmt VLAN or mgmt CLIP.&lt;/P&gt;&lt;P&gt;If you use CLIP, there is no need to add a VLAN on the firewall, just a route would be needed (+ security policies).&lt;/P&gt;&lt;P&gt;Be carefull with Natting mgmt interface because it is the one used for Radius and XIQ-SE snmp communication.&lt;/P&gt;&lt;P&gt;You can also work with the same mgmgt VLAN for all your switches but again, the NATting could cause trouble with Radius and XIQ-SE snmp communication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mig&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 07:22:25 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-engine-with-mgmt-clip-and-nat-firewall/m-p/93487#M1947</guid>
      <dc:creator>Miguel-Angel_RO</dc:creator>
      <dc:date>2022-10-24T07:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Fabric Engine with Mgmt CLIP and NAT Firewall</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-engine-with-mgmt-clip-and-nat-firewall/m-p/93498#M1948</link>
      <description>&lt;P&gt;Thanks Mig&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 12:40:08 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/fabric-engine-with-mgmt-clip-and-nat-firewall/m-p/93498#M1948</guid>
      <dc:creator>RobertD1</dc:creator>
      <dc:date>2022-10-24T12:40:08Z</dc:date>
    </item>
  </channel>
</rss>

