Switches, Hubs, and Modems
1752610 Members
3876 Online
108788 Solutions
New Discussion юеВ

Re: ACL

 
Evgeniy Paukov
Occasional Advisor

ACL

Good afternoon! It is established HP procurve 2650, two computers A and B. How to adjust ACL list thus what from computer A on computer B there was no access, and with B on A was? Thanks
9 REPLIES 9
OLARU Dan
Trusted Contributor

Re: ACL

OK.

2650 has routing capabilities?

If yes,

i1. ip routing
i2. define ip subnets for the vlan interfaces, and assign ipas to these interfaces
i3. put ip acls on the vlan interfaces that have ipa assigned
i4. put the 2 pcs in 2 different vlans/subnets
i4'. make sure the pcs have ipas
i4". check back here if you [still] have any problems

else

i5. no can do

endif

i6. get better @ english

Are you programmer, btw?

Cheers,
Dan
Evgeniy Paukov
Occasional Advisor

Re: ACL

Computers are in different VLAN. The matter is that at creation of a rule for one vlan (A) for example "deny 0.0.0.0 0.0.0.0", from another vlan (A) it is impossible to come in vlan (B), and I need to come. How it is possible to make?
Matt Hobbs
Honored Contributor

Re: ACL

The 2650 does not support ACLs. This is not possible.
Evgeniy Paukov
Occasional Advisor

Re: ACL

OK.
And on 5304?
Matt Hobbs
Honored Contributor

Re: ACL

5300 series supports fairly basic ACLs, but if your requirement is so that computer A cannot access computer B, but computer B can access computer A - then you need support the 'established' command in the ACL's. Only the newer 5400/3500 products support this feature along with many other more advanced ACL options.

'established' looks for new TCP connections so it can determine the direction of where the connection is coming from.
Evgeniy Paukov
Occasional Advisor

Re: ACL

What can you advise as to act to me?
Evgeniy Paukov
Occasional Advisor

Re: ACL

And 5304 will support given type ACL?
Mohieddin Kharnoub
Honored Contributor

Re: ACL

Hi

If you can manage a 3500/5400 then i'm with Matt's suggestion.

Otherwise, with the 5300 you can do it like this:

- Create a Vlan for PC-A with a proper IP address.
- Create another Vlan for PC-B with a proper IP address
- Enable IP Routing on the 5300.
- Now PC-A can talk to PC-B and vise versa
- Apply an ACL allows PC-A Vlan to talk to PC-B Vlan.
- Apply an ACL denies PC-B Vlan to talk to PC-A Vlan.

I think in that way you can achieve your goal.

Good Luck !!!
Science for Everyone
Evgeniy Paukov
Occasional Advisor

Re: ACL

Thanks.
I shall try and I shall write here ├Р┬┐├Р┬╛├Р┬╗├С ├С ├Р┬╕├Р┬╗├Р┬╛├С ├С or not