cancel
Showing results for 
Search instead for 
Did you mean: 

Block SNMP traffic to devices

Block SNMP traffic to devices

David_Cotos
New Contributor
Hello all, I'm a bit of a exos newb and need assistance. Is there a way to create an ACL to specifically block SNMP traffic to a device connected to a port?

I was thinking of using the GUI route and set up a dynamic ACL. Would this be a good idea or not recommended?

Any thoughts?

David
1 ACCEPTED SOLUTION

Kawawa
Extreme Employee
Hi David,

Here's a guide on how to create Dynamic ACLs using Chalet (EXOS GUI): https://documentation.extremenetworks.com/chalet/Chalet/t_configuring-acls.shtml

Here's an example of your rule:

feab55f45d4940f7b3d1f15141fe08c4_d0322a79-0740-459a-b77f-b59971f8745a.png



NOTE: If you do not specific protocol udp and simply add the destination-port,t he ACL will throw an error as this port could equally belong to a TCP socket.

Note: What you're trying to do involves installing an egress ACL. if you have other rules currently utilizing the egress ACL slices, you might run into a situation where you see the following, which simply means there's no available resources to install the new rule. Generally, there's more ingress ACL slices available should you wish to use that instead:

feab55f45d4940f7b3d1f15141fe08c4_d3d44c7e-80b7-43d8-9b18-22caca9ef27f.png



You can edit the ACL and enter new conditions as and when you please.

I hope this answers your question.

View solution in original post

2 REPLIES 2

David_Cotos
New Contributor
This is great, thank you for the information!

Kawawa
Extreme Employee
Hi David,

Here's a guide on how to create Dynamic ACLs using Chalet (EXOS GUI): https://documentation.extremenetworks.com/chalet/Chalet/t_configuring-acls.shtml

Here's an example of your rule:

feab55f45d4940f7b3d1f15141fe08c4_d0322a79-0740-459a-b77f-b59971f8745a.png



NOTE: If you do not specific protocol udp and simply add the destination-port,t he ACL will throw an error as this port could equally belong to a TCP socket.

Note: What you're trying to do involves installing an egress ACL. if you have other rules currently utilizing the egress ACL slices, you might run into a situation where you see the following, which simply means there's no available resources to install the new rule. Generally, there's more ingress ACL slices available should you wish to use that instead:

feab55f45d4940f7b3d1f15141fe08c4_d3d44c7e-80b7-43d8-9b18-22caca9ef27f.png



You can edit the ACL and enter new conditions as and when you please.

I hope this answers your question.
GTM-P2G8KFN