<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict VLAN Routing in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830806#M8569</link>
    <description>Hello,&lt;BR /&gt;I know that the 3400 can work with ACL, but I never try it. I hear that's complicated. Here my VLAN config.&lt;BR /&gt;&lt;BR /&gt;IP Netz  Name  VLAN-ID&lt;BR /&gt;172.18.8.0/21 Zen-VLAN-1 1&lt;BR /&gt;10.100.100.0/24 Adm-VLAN-100 100 10.100.101.0/24 GMP-VLAN-101 101&lt;BR /&gt;10.100.102.0/24 Fin-VLAN-102 102&lt;BR /&gt;10.100.103.0/24 GF-VLAN-103 103&lt;BR /&gt;10.100.104.0/24 IT-VLAN-104 104&lt;BR /&gt;10.100.105.0/24 SRV-VLAN-105 105&lt;BR /&gt;&lt;BR /&gt;Default Gateway    xxx.yyy.zzz.1&lt;BR /&gt;&lt;BR /&gt;I add the following IP Addresse to the main Switch&lt;BR /&gt;vlan 100 ip address 10.100.100.1/24&lt;BR /&gt;vlan 101 ip address 10.100.101.1/24&lt;BR /&gt;vlan 102 ip address 10.100.102.1/24&lt;BR /&gt;vlan 103 ip address 10.100.103.1/24&lt;BR /&gt;vlan 104 ip address 10.100.104.1/24&lt;BR /&gt;vlan 105 ip address 10.100.105.1/24&lt;BR /&gt;That is also the default Gateway for the VLAN's&lt;BR /&gt;&lt;BR /&gt;VALN 100-104 routed to VLAN 105 and back,  but no routing between VLAN 100-104.&lt;BR /&gt;&lt;BR /&gt;Can anyone provide examples ACL for denied the VLAN Routing.&lt;BR /&gt;&lt;BR /&gt;;-)))) Big THX&lt;BR /&gt;Stefan Wuswoski&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Wed, 26 Jul 2006 06:26:49 GMT</pubDate>
    <dc:creator>Stefan Wusowski</dc:creator>
    <dc:date>2006-07-26T06:26:49Z</dc:date>
    <item>
      <title>Restrict VLAN Routing</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830803#M8566</link>
      <description>Hello, &lt;BR /&gt;my problem is to restrict the VLAN routing. When I add VLANs to a 3400 switch with IP Adresses and IP Routing is on, then all VLAN can connect in to all VLAN!? That right?&lt;BR /&gt;But I don't want that. I have a SRV VLAN and more  branch VLANs. I want all branch VLANs to SRV VLAN but no branch VLAN to branch VLAN. How can I configure that?&lt;BR /&gt;&lt;BR /&gt;THX&lt;BR /&gt;Stefan Wusowski</description>
      <pubDate>Wed, 26 Jul 2006 02:44:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830803#M8566</guid>
      <dc:creator>Stefan Wusowski</dc:creator>
      <dc:date>2006-07-26T02:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VLAN Routing</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830804#M8567</link>
      <description>Have you tried using ACL's to prevent traffic from one IP subnet from getting to another?&lt;BR /&gt;&lt;BR /&gt;I am sure the 3400cl supports this (Quick check on the procurve website confirms this...) &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Jul 2006 05:07:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830804#M8567</guid>
      <dc:creator>Jonathan Axford</dc:creator>
      <dc:date>2006-07-26T05:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VLAN Routing</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830805#M8568</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;The 3400 is an intellegent switch, so it has Access control lists (ACLs)which can provide IP layer 3 filtering based on source/destination IP address/subnet and source/destination TCP/UDP port number.&lt;BR /&gt;&lt;BR /&gt;If you can provide your IP addresses for your Vlans, and what exactly the restricyions you need , then we can break it out for you with ACLs.&lt;BR /&gt;&lt;BR /&gt;Good Luck !!!</description>
      <pubDate>Wed, 26 Jul 2006 05:54:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830805#M8568</guid>
      <dc:creator>Mohieddin Kharnoub</dc:creator>
      <dc:date>2006-07-26T05:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VLAN Routing</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830806#M8569</link>
      <description>Hello,&lt;BR /&gt;I know that the 3400 can work with ACL, but I never try it. I hear that's complicated. Here my VLAN config.&lt;BR /&gt;&lt;BR /&gt;IP Netz  Name  VLAN-ID&lt;BR /&gt;172.18.8.0/21 Zen-VLAN-1 1&lt;BR /&gt;10.100.100.0/24 Adm-VLAN-100 100 10.100.101.0/24 GMP-VLAN-101 101&lt;BR /&gt;10.100.102.0/24 Fin-VLAN-102 102&lt;BR /&gt;10.100.103.0/24 GF-VLAN-103 103&lt;BR /&gt;10.100.104.0/24 IT-VLAN-104 104&lt;BR /&gt;10.100.105.0/24 SRV-VLAN-105 105&lt;BR /&gt;&lt;BR /&gt;Default Gateway    xxx.yyy.zzz.1&lt;BR /&gt;&lt;BR /&gt;I add the following IP Addresse to the main Switch&lt;BR /&gt;vlan 100 ip address 10.100.100.1/24&lt;BR /&gt;vlan 101 ip address 10.100.101.1/24&lt;BR /&gt;vlan 102 ip address 10.100.102.1/24&lt;BR /&gt;vlan 103 ip address 10.100.103.1/24&lt;BR /&gt;vlan 104 ip address 10.100.104.1/24&lt;BR /&gt;vlan 105 ip address 10.100.105.1/24&lt;BR /&gt;That is also the default Gateway for the VLAN's&lt;BR /&gt;&lt;BR /&gt;VALN 100-104 routed to VLAN 105 and back,  but no routing between VLAN 100-104.&lt;BR /&gt;&lt;BR /&gt;Can anyone provide examples ACL for denied the VLAN Routing.&lt;BR /&gt;&lt;BR /&gt;;-)))) Big THX&lt;BR /&gt;Stefan Wuswoski&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Jul 2006 06:26:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830806#M8569</guid>
      <dc:creator>Stefan Wusowski</dc:creator>
      <dc:date>2006-07-26T06:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VLAN Routing</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830807#M8570</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Your configuration will be:&lt;BR /&gt;&lt;BR /&gt;1- Create a standard access list:&lt;BR /&gt;----------------------------------&lt;BR /&gt;3400(config)# access-list 1 deny 10.100.100.1/24&lt;BR /&gt;3400(config)# access-list 1 deny 10.100.101.1/24&lt;BR /&gt;3400(config)# access-list 1 deny 10.100.102.1/24&lt;BR /&gt;3400(config)# access-list 1 deny 10.100.103.1/24&lt;BR /&gt;3400(config)# access-list 1 deny 10.100.104.1/24&lt;BR /&gt;3400(config)# access-list 1 permit any&lt;BR /&gt;&lt;BR /&gt;2- Apply it to vlans 100 to 104:&lt;BR /&gt;---------------------------------&lt;BR /&gt;3400(config)# vlan 100 ip access-group 1 in&lt;BR /&gt;3400(config)# vlan 101 ip access-group 1 in&lt;BR /&gt;3400(config)# vlan 102 ip access-group 1 in&lt;BR /&gt;3400(config)# vlan 103 ip access-group 1 in&lt;BR /&gt;3400(config)# vlan 104 ip access-group 1 in&lt;BR /&gt;&lt;BR /&gt;3- Verify your configuration by Show access-list.&lt;BR /&gt;&lt;BR /&gt;I hope that will be enough to help :)&lt;BR /&gt;&lt;BR /&gt;Don't forget to assign points, &lt;BR /&gt;&lt;BR /&gt;Good Luck !!!</description>
      <pubDate>Wed, 26 Jul 2006 07:02:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/restrict-vlan-routing/m-p/3830807#M8570</guid>
      <dc:creator>Mohieddin Kharnoub</dc:creator>
      <dc:date>2006-07-26T07:02:40Z</dc:date>
    </item>
  </channel>
</rss>

