<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with ACLs. in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721067#M24704</link>
    <description>Simpelest way is NOT to configure routing between the gest VLAN and the default vlan.&lt;BR /&gt;Then you don't need to fiddle with ACL's.&lt;BR /&gt;&lt;BR /&gt;- Only the firewall needs an ip-adress in this vlan.&lt;BR /&gt;- If the switch is configured for routing, don't give it an ip-adress in this guest vlan.&lt;BR /&gt;- Don't give any other switch an ip-adress in this guest vlan.&lt;BR /&gt;&lt;BR /&gt;The switches will forward packets on layer-2 to other ports in the same vlan as if it was a physical separate network.&lt;BR /&gt;&lt;BR /&gt;NB! you may want to add another vlan to make your access-point reachable for management.&lt;BR /&gt;Offcourse your AP's must support this.&lt;BR /&gt;</description>
    <pubDate>Fri, 03 Dec 2010 08:17:30 GMT</pubDate>
    <dc:creator>Pieter 't Hart</dc:creator>
    <dc:date>2010-12-03T08:17:30Z</dc:date>
    <item>
      <title>Problems with ACLs.</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721066#M24703</link>
      <description>Any help would be most appreciated. I have a 5406zl and 2600 switch configured with multiple VLANs.  We have a perimeter firewall on the default vlan (id:1) and have recently introduced a Wireless/Guest VLAN (id:30).  &lt;BR /&gt;&lt;BR /&gt;What I would like to do, is to restrict all access from the Wireless/Guest VLAN to only the perimeter firewall and beyond.  &lt;BR /&gt;&lt;BR /&gt;So effectively, if the firewall is on 192.168.1.1 and the Guest VLAN is 192.168.10.0 I want all traffic coming from the 192.168.10.0 network to be restricted to the firewall on 192.168.1.1 and not be able to access anything else on the default vlan.&lt;BR /&gt;&lt;BR /&gt;Any help would be most appreciated.&lt;BR /&gt;&lt;BR /&gt;Thanks for looking.</description>
      <pubDate>Thu, 02 Dec 2010 16:56:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721066#M24703</guid>
      <dc:creator>MrMacro</dc:creator>
      <dc:date>2010-12-02T16:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with ACLs.</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721067#M24704</link>
      <description>Simpelest way is NOT to configure routing between the gest VLAN and the default vlan.&lt;BR /&gt;Then you don't need to fiddle with ACL's.&lt;BR /&gt;&lt;BR /&gt;- Only the firewall needs an ip-adress in this vlan.&lt;BR /&gt;- If the switch is configured for routing, don't give it an ip-adress in this guest vlan.&lt;BR /&gt;- Don't give any other switch an ip-adress in this guest vlan.&lt;BR /&gt;&lt;BR /&gt;The switches will forward packets on layer-2 to other ports in the same vlan as if it was a physical separate network.&lt;BR /&gt;&lt;BR /&gt;NB! you may want to add another vlan to make your access-point reachable for management.&lt;BR /&gt;Offcourse your AP's must support this.&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Dec 2010 08:17:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721067#M24704</guid>
      <dc:creator>Pieter 't Hart</dc:creator>
      <dc:date>2010-12-03T08:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with ACLs.</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721068#M24705</link>
      <description>I like your bit of lateral thinking... however, though I don't doubt that your method doesn't work, I managed to implement the appropriate ACLs, but thanks for your help.</description>
      <pubDate>Mon, 06 Dec 2010 21:57:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721068#M24705</guid>
      <dc:creator>MrMacro</dc:creator>
      <dc:date>2010-12-06T21:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with ACLs.</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721069#M24706</link>
      <description>As it was not the solution to your question, 10 points is a bit high.&lt;BR /&gt;But thanks very much, you flipped me over the 2500 points and changed my hat from wizzard to royalty.</description>
      <pubDate>Tue, 07 Dec 2010 07:32:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/problems-with-acls/m-p/4721069#M24706</guid>
      <dc:creator>Pieter 't Hart</dc:creator>
      <dc:date>2010-12-07T07:32:49Z</dc:date>
    </item>
  </channel>
</rss>

