Extreme Control with ERS: Accept traffic upon active VLAN + MAC
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
08-30-2019 02:08 PM
Hello community,
I´m new to Extreme control.
Can somebody explain step by step how to create the following rule with Control and BOSS/VOSS-Devices:
Customer wants to accept traffic, If VLAN ID already (!) configure on a specific port matches e.g. 100 AND MAC-addresse connected to this port matches a predefined MAC-List.
Customer does not want to change VLAN-ID, if MAC matches, but configure VLAN on port does not match.
In this case, access should be rejected.
Thanks in advance!
I´m new to Extreme control.
Can somebody explain step by step how to create the following rule with Control and BOSS/VOSS-Devices:
Customer wants to accept traffic, If VLAN ID already (!) configure on a specific port matches e.g. 100 AND MAC-addresse connected to this port matches a predefined MAC-List.
Customer does not want to change VLAN-ID, if MAC matches, but configure VLAN on port does not match.
In this case, access should be rejected.
Thanks in advance!
5 REPLIES 5
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
08-30-2019 03:30 PM
This is very unique approach.
you can define locations (set of switch and port).
Then you can create rule: if the mac is in group G100 and the location is L100 then apply vlan100. If the mac is in group G101 and location is L101 then apply vlan101. Otherwise reject.
with the approach above you can define the list of ports in management instead of in the CLI.
in advance: location groups can be synchronized by workflow from ERS switches...
other approach is to explain the customer that his approach is “not best practise and not optimal for troubleshooting (you need to check CLI and GUI”.
you can define locations (set of switch and port).
Then you can create rule: if the mac is in group G100 and the location is L100 then apply vlan100. If the mac is in group G101 and location is L101 then apply vlan101. Otherwise reject.
with the approach above you can define the list of ports in management instead of in the CLI.
in advance: location groups can be synchronized by workflow from ERS switches...
other approach is to explain the customer that his approach is “not best practise and not optimal for troubleshooting (you need to check CLI and GUI”.
Regards
Zdeněk Pala
