- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- isolate an IGMP vlan
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-10-2017 07:29 AM - edited 01-19-2017 11:04 PM
01-10-2017 07:29 AM - edited 01-19-2017 11:04 PM
isolate an IGMP vlan
I have in a network one vlan igmp enabled, the streaming server and the clients are all connected to that vlan.
Nevertheless the core switch has an IP address (VRRP) in order to act as an IGMP querier.
Now I want to prevent that clients inside this subnet can reach the rest of my other network except one SIP server
Therefore I cam up with following access-list
ip access-list extended "IPTV" 10 permit ip 0.0.0.0 255.255.255.255 255.255.255.255 0.0.0.0 20 permit igmp 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255 30 permit udp 0.0.0.0 255.255.255.255 239.192.50.50 0.0.0.0 eq 2209 50 remark "VoIP_SIP to PBX" 50 permit udp 172.27.0.0 0.0.8.255 10.1.4.1 0.0.0.0 eq 5060 60 remark "VoIP_rtp to PBX" 60 permit udp 172.27.0.0 0.0.8.255 10.1.4.1 0.0.0.0 gt 24000 70 permit ip 172.27.0.0 0.0.8.255 172.25.0.0 0.0.8.255 100 permit ip 0.0.0.0 255.255.255.255 224.0.0.0 15.255.255.255 exit
As soon as I apply this ACL to the VLAN interface my streaming stops at the clients
vlan 600 ip access-group "iptv" vlan exit
something is wrong on my ACL but I do not see it...