- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: Access Lists and Vlans with 5300xl
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 06:53 AM
тАО05-21-2003 06:53 AM
Access Lists and Vlans with 5300xl
Hopefully someone can help me with the following problem.
We've got 2 vlans on a switch:
Vlan 1: 192.168.78.0
Vlan 2: 192.168.77.0
Right now I can do anything from vlan 1 to vlan 2 and vica versa.
I want to deny all traffic except telnet from vlan 1 to vlan 2 (port 23). To realise this i've made an extended acl '100' with the following rule:
permit tcp 192.168.77.0 0.0.0.255 192.168.78.0 0.0.0.255 eq 23
and i've binded the access list to outbound traffic of vlan 1.
But telnet doesn't work.
Do i forget something
Does anyone has experience with acl on hp switches?
Or have some examples for me?
I've already studied the manual.
Martijn Mol
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 06:59 AM
тАО05-21-2003 06:59 AM
Re: Access Lists and Vlans with 5300xl
permit tcp 192.168.77.0 0.0.0.255 192.168.78.0 0.0.0.255 eq 23
has to be permit tcp 192.168.78.0 0.0.0.255 192.168.77.0 0.0.0.255 eq 23
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 06:59 AM
тАО05-21-2003 06:59 AM
Re: Access Lists and Vlans with 5300xl
permit tcp 192.168.77.0 0.0.0.255 192.168.78.0 0.0.0.255 eq 23
has to be permit tcp 192.168.78.0 0.0.0.255 192.168.77.0 0.0.0.255 eq 23
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 10:26 AM
тАО05-21-2003 10:26 AM
Re: Access Lists and Vlans with 5300xl
vlan 1
ip access-group 100 in
This means: "When traffic comes to this switch in VLAN 1, check the list." Your setting only checks traffic that leaves the switch from VLAN 1.
Those "in" and "out" specifications are not checked when the traffic flows (from one VLAN to another) inside the switch. They are checked only when the traffic enters or leaves the switch.
Other choice would be
vlan 2
ip access-group 100 out
but this would not be as efficient (why route some traffic if it will eventually be dropped).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2003 01:33 AM
тАО05-22-2003 01:33 AM
Re: Access Lists and Vlans with 5300xl
If i want to telnet from vlan 1 to vlan 2 than that's data that leaves vlan 1, so i thought that was outbound traffic for vlan 1.
Good you please try to explain me?
Kind regards,
Martijn Mol
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2003 03:01 AM
тАО05-22-2003 03:01 AM
Re: Access Lists and Vlans with 5300xl
So the point to think is : who'll decide ?
VLAn 1' job is not to decide who's after (VLAN2or another), but to transmit packets.
AS Markku explained, the tool that is the most concerned by this access list, is VLAN that is receiving data and has to decide if it can get in or not.
HP has configurations examples that may be helpful for your understanding :
http://www.hp.com/rnd/support/config_examples/93xx_6308.htm
It's quite well explained.
hth
J
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2003 03:27 AM
тАО05-22-2003 03:27 AM
Re: Access Lists and Vlans with 5300xl
how to put it, access-lists are not kind of used when a packet is routed inside the 5300XL switch. The access-lists are only applied when the data enters ("ip access-group xxx in") or leaves ("ip access-group xxx out") the switch.
Example:
Ports A1-A6 are in VLAN 1 (network A), ports A13-18 are in VLAN 2 (network B).
We have:
vlan 1
ip access-group 100 in
ip access-group 101 out
vlan 2
ip access-group 102 out
Meaning:
List 100 is checked on packets that enter the switch from ports A1-A6.
List 101 is checked on packets that leave the switch from ports A1-A6.
List 102 is checked on packets that leave the switch from ports A13-A18.
Now, if a packet from network A is routed to network B, two lists are applied: list 100 and list 102.
When a host in network B (VLAN 2) replies to a host in network A (VLAN 1), only list 101 is used.
If a packet is coming from some other VLAN, like VLAN 3 and going to network B (VLAN 2), only list 102 is used.
Access-lists are only consulted for routed traffic (IP routing must be enabled) or traffic destined to the switch itself.
Hope this helps some more. Check also the examples, if there are some for access-lists.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2003 03:35 AM
тАО05-22-2003 03:35 AM
Re: Access Lists and Vlans with 5300xl
When saying (in ip access-group command) "in" that really means packet coming into the switch, and out is meaning packets going out of the switch.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-06-2003 06:26 AM
тАО06-06-2003 06:26 AM
Re: Access Lists and Vlans with 5300xl
I have it working now!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-06-2003 08:15 AM
тАО06-06-2003 08:15 AM
Re: Access Lists and Vlans with 5300xl
glad it works ! :]]
Why not assigning points to Markku, who did most of the job ?
J