<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL on VLAN in VRF (flex-uni) in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/acl-on-vlan-in-vrf-flex-uni/m-p/120422#M3081</link>
    <description>&lt;P&gt;did you try inVSN filter instead?&lt;/P&gt;</description>
    <pubDate>Fri, 03 Oct 2025 08:58:37 GMT</pubDate>
    <dc:creator>Roger_Lapuh</dc:creator>
    <dc:date>2025-10-03T08:58:37Z</dc:date>
    <item>
      <title>ACL on VLAN in VRF (flex-uni)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/acl-on-vlan-in-vrf-flex-uni/m-p/120415#M3080</link>
      <description>&lt;P&gt;So we have a flex-uni port on one switch,&amp;nbsp;with i-sid mapped to VLAN on another which is routing the traffic (in a dedicated VR).&lt;/P&gt;&lt;P&gt;All of that works, now the question is, how do I filter it, on the routing switch i.e. assign an access control list to it?&lt;/P&gt;&lt;P&gt;So ingress swithc has the flex-uni port&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;interface gi 1/1
flex-uni enable
i-sid 12345 
  untagged port 1/1&lt;/LI-CODE&gt;&lt;P&gt;The routing switch uses&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;vlan i-sid 99 12345

interface vlan 99
  vrf router1
  ...

i-sid 12345
  c-vid 567 port 1/25
# i.e. there's also a flex-uni for with that i-sid on the routing switch (in case that's important)&lt;/LI-CODE&gt;&lt;P&gt;I tried&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;filter acl 101 type inVlan name "ipv4 and arp only"
filter acl vlan 101 99
filter acl ace 101 11 name "allow ipv4"
filter acl ace action 101 11 permit count
filter acl ace ethernet 101 11 ether-type eq ip
filter acl ace 101 11 enable&lt;/LI-CODE&gt;&lt;P&gt;But counters stay at 0.&lt;BR /&gt;I also tried dropping some traffic but that didn't work.&amp;nbsp;&lt;BR /&gt;Leading me to the conclusion that I'm missing something basic.&lt;/P&gt;&lt;P&gt;This seems to easy to fail &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Please advise.&lt;/P&gt;&lt;P&gt;Platform is 5520, FE 9.0&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 18:38:37 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/acl-on-vlan-in-vrf-flex-uni/m-p/120415#M3080</guid>
      <dc:creator>jeronimo</dc:creator>
      <dc:date>2025-10-01T18:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACL on VLAN in VRF (flex-uni)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/acl-on-vlan-in-vrf-flex-uni/m-p/120422#M3081</link>
      <description>&lt;P&gt;did you try inVSN filter instead?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 08:58:37 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/acl-on-vlan-in-vrf-flex-uni/m-p/120422#M3081</guid>
      <dc:creator>Roger_Lapuh</dc:creator>
      <dc:date>2025-10-03T08:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACL on VLAN in VRF (flex-uni)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/acl-on-vlan-in-vrf-flex-uni/m-p/120423#M3082</link>
      <description>&lt;P&gt;Not yet. Usually I don't try random things but would like to understand why one doesn't work and something else must be chosen.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 09:19:11 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/acl-on-vlan-in-vrf-flex-uni/m-p/120423#M3082</guid>
      <dc:creator>jeronimo</dc:creator>
      <dc:date>2025-10-03T09:19:11Z</dc:date>
    </item>
  </channel>
</rss>

