<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Isolating clients in the same VLAN/service from each other (FabricEngine/NAC) in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/isolating-clients-in-the-same-vlan-service-from-each-other/m-p/94472#M2034</link>
    <description>&lt;P&gt;You can create PVLANs with ETREEs on VOSS through a Radius VSA response. This is very straight forward and can be done while a device is logging in. For isolated ports make sure you do this on auto-sense ports or configure isolated ports through other means.&lt;/P&gt;&lt;P&gt;Radius VSA:&amp;nbsp;&lt;/P&gt;&lt;P&gt;create=vlan¦pvlan, pv=Primary VLANID, sv=[secondary VLANID], vni=[ISID], ev= [EGRESS-VLAN-tag], vn=[vlan-name], vnin=[isid-name]&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 16:52:07 GMT</pubDate>
    <dc:creator>Roger_Lapuh</dc:creator>
    <dc:date>2023-01-23T16:52:07Z</dc:date>
    <item>
      <title>Isolating clients in the same VLAN/service from each other (FabricEngine/NAC)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/isolating-clients-in-the-same-vlan-service-from-each-other/m-p/94458#M2032</link>
      <description>&lt;P&gt;How would you go about this when using Extremecontrol?&lt;BR /&gt;What kind of policies would you be pushing?&lt;BR /&gt;I'm currently not sure whether L2 or L3 would be appropriate.&lt;BR /&gt;Something generic would be great, so you don't need to specify different policies with different IP subnets for each service.&lt;/P&gt;&lt;P&gt;Maybe some generic L2 rule would be possible but I couldn't come up with one yet. Like only allowing access to the MAC address of the def GW, but it's more complicated than that (broadcasts, multicasts, etc.)&lt;BR /&gt;&lt;BR /&gt;I know there is the possibility of private VLANs, but that has always seemed very complex to me.&lt;/P&gt;&lt;P&gt;Or is there some setting that I can just click enabled that I have missed?&lt;/P&gt;&lt;P&gt;Of course in any case exceptions need to be possible like excluding some TCP/UDP ports from the ban.&lt;BR /&gt;&lt;BR /&gt;Thanks for any feedback.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 23:29:40 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/isolating-clients-in-the-same-vlan-service-from-each-other/m-p/94458#M2032</guid>
      <dc:creator>jeronimo</dc:creator>
      <dc:date>2023-01-19T23:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Isolating clients in the same VLAN/service from each other (FabricEngine/NAC)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/isolating-clients-in-the-same-vlan-service-from-each-other/m-p/94472#M2034</link>
      <description>&lt;P&gt;You can create PVLANs with ETREEs on VOSS through a Radius VSA response. This is very straight forward and can be done while a device is logging in. For isolated ports make sure you do this on auto-sense ports or configure isolated ports through other means.&lt;/P&gt;&lt;P&gt;Radius VSA:&amp;nbsp;&lt;/P&gt;&lt;P&gt;create=vlan¦pvlan, pv=Primary VLANID, sv=[secondary VLANID], vni=[ISID], ev= [EGRESS-VLAN-tag], vn=[vlan-name], vnin=[isid-name]&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 16:52:07 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/isolating-clients-in-the-same-vlan-service-from-each-other/m-p/94472#M2034</guid>
      <dc:creator>Roger_Lapuh</dc:creator>
      <dc:date>2023-01-23T16:52:07Z</dc:date>
    </item>
  </channel>
</rss>

