<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic access list on a vlan interface wont work! in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149630#M34665</link>
    <description>&lt;P&gt;I have a core switch "&lt;SPAN&gt;HP 8206"&lt;/SPAN&gt; connected through vlan 2 to an isp router which in turn connects me to my branch on subnet 192.168.2.1/24 through an isp router, im trying to control my vlan 1 traffic 192.168.1.1/24 to vlan 2 through an access list on the vlan 1 interface but it simply isn't working even after trying ip access-group acl in,out,vlan please help&lt;/P&gt;&lt;P&gt;ip access-group extended test&lt;BR /&gt;Deny ip 192.168.1.25 255.255.255.255 192.168.2.7 255.255.255.255&lt;BR /&gt;Permit ip any any&lt;/P&gt;&lt;P&gt;vlan 1&lt;BR /&gt;name "Server-VLAN"&lt;BR /&gt;untagged Trk45&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip access-group test in&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;vrrp vrid 1&lt;BR /&gt;virtual-ip-address 192.168.1.1&lt;BR /&gt;priority 255&lt;BR /&gt;enable&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2021 15:38:03 GMT</pubDate>
    <dc:creator>dmsman</dc:creator>
    <dc:date>2021-09-23T15:38:03Z</dc:date>
    <item>
      <title>access list on a vlan interface wont work!</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149630#M34665</link>
      <description>&lt;P&gt;I have a core switch "&lt;SPAN&gt;HP 8206"&lt;/SPAN&gt; connected through vlan 2 to an isp router which in turn connects me to my branch on subnet 192.168.2.1/24 through an isp router, im trying to control my vlan 1 traffic 192.168.1.1/24 to vlan 2 through an access list on the vlan 1 interface but it simply isn't working even after trying ip access-group acl in,out,vlan please help&lt;/P&gt;&lt;P&gt;ip access-group extended test&lt;BR /&gt;Deny ip 192.168.1.25 255.255.255.255 192.168.2.7 255.255.255.255&lt;BR /&gt;Permit ip any any&lt;/P&gt;&lt;P&gt;vlan 1&lt;BR /&gt;name "Server-VLAN"&lt;BR /&gt;untagged Trk45&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip access-group test in&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;vrrp vrid 1&lt;BR /&gt;virtual-ip-address 192.168.1.1&lt;BR /&gt;priority 255&lt;BR /&gt;enable&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 15:38:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149630#M34665</guid>
      <dc:creator>dmsman</dc:creator>
      <dc:date>2021-09-23T15:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: access list on a vlan interface wont work!</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149631#M34666</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2050312"&gt;@dmsman&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;This ACL should deny traffic sourced from single IP&amp;nbsp;&lt;SPAN&gt;192.168.1.25 to single IP&amp;nbsp;192.168.2.7, the rest is allowed. Is it really what you need to achieve? Just block IP traffic between those two single IP addresses?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 05:51:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149631#M34666</guid>
      <dc:creator>Ivan_B</dc:creator>
      <dc:date>2021-09-22T05:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: access list on a vlan interface wont work!</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149641#M34667</link>
      <description>&lt;P&gt;no this isn't the full acl this is just an example , the thing is the traffic is stil going as the acl isnt there&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 07:43:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149641#M34667</guid>
      <dc:creator>dmsman</dc:creator>
      <dc:date>2021-09-22T07:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: access list on a vlan interface wont work!</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149663#M34668</link>
      <description>&lt;P&gt;You need to be sure your hosts in Vlan 1 are using&amp;nbsp;&lt;SPAN&gt;192.168.1.1 as default gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Another issue, sorry, I've overlooked it - you are using subnet masks in the ACL while you must use wildcard masks instead:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ip access-group extended test
Deny ip 192.168.1.25 0.0.0.0 192.168.2.7 0.0.0.0
Permit ip any any&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus, if you want to block the whole subnet and the subnet has /24 mask (255.255.255.0), then the correct wildcard mask will be 0.0.0.255&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 11:26:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7149663#M34668</guid>
      <dc:creator>Ivan_B</dc:creator>
      <dc:date>2021-09-22T11:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: access list on a vlan interface wont work!</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7150062#M34672</link>
      <description>&lt;P&gt;-please is there a way to find hits on the access list on the vlan when i use access-group in or out? i could only find hits using&amp;nbsp;&lt;EM&gt;show statistics aclv4&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;vlan&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;x&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;vlan&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;-what is the difference between access-group in/out/vlan?&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Sep 2021 06:01:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/access-list-on-a-vlan-interface-wont-work/m-p/7150062#M34672</guid>
      <dc:creator>dmsman</dc:creator>
      <dc:date>2021-09-26T06:01:34Z</dc:date>
    </item>
  </channel>
</rss>

