- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Vlan ACL
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-25-2010 09:02 AM
тАО01-25-2010 09:02 AM
Vlan ACL
I am trying to figure out a Vlan ACL. What I want is pretty simple I think. I have a HP 5308xl and I want to allow vlan 1 access to vlan 2 but no access from vlan 2 to vlan 1. Vlan 1 has the range 102.168.8.0 - 192.168.15.255 do I use an inbound or outbound statement, deny or permit? Also how do I handle the range do I use separate statements for each?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-26-2010 01:33 AM
тАО01-26-2010 01:33 AM
Re: Vlan ACL
You want an inbound access list applied to VLAN 2 (the way to remember the direction is that it is always with respect to the switch not the hosts)
Basically your acl will say:
deny (vlan 2 range) any
permit any any
Take a look at the manual pages here on how to do wildcard for your vlan 2 range (if you get stuck just ask again :) )
http://ftp.hp.com/pub/networking/software/6400-5300-4200-3400-AdvTrafficMgmt-Oct2006-59906051-Chap09.pdf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-26-2010 05:23 AM
тАО01-26-2010 05:23 AM
Re: Vlan ACL
this configuration permit any communication from vlan 1 to 2, but visa versa is deny.
just copy these and paste it as it is.
ip access-list extended VLAN_2
Permit ip 192.168.8.0/21 any
Permit TCP any 192.168.8.0/21 established
Permit ICMP any 192.168.8.0/21 echo-reply
Deny ICMP any any echo
Deny TCP any any eq telnet
Permit ip any any
VLAN 2
ip access-group VLAN_2 VLAN
ip access-group VLAN_2 in
Regards,
A.S
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-27-2010 02:42 AM
тАО01-27-2010 02:42 AM
Re: Vlan ACL
Abdullah, I'm not sure how your ACL works, it's applied on VLAN 2 and the first line of the ACL :
"Permit ip 192.168.8.0/21 any" is allowing access from hosts with a source address of 192.168.8.0/21 to any address ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-27-2010 06:39 AM
тАО01-27-2010 06:39 AM