Mario Publish time 2022-4-9 00:01:51

EG3230 ACL to Block inter-vlan routing

I created the DHCP, Sub-Interfaces on Te0/0
data/attachment/forum/202204/08/234035f2jbj22vsb8d2dzz.jpgdata/attachment/forum/202204/08/234035nnwupov36n0dvioi.jpg

Then created the ACLs, 100,101,102 for each Vlan to block each other
data/attachment/forum/202204/08/235459a01rqgiiu11no1e1.jpgdata/attachment/forum/202204/08/235459th82hm32aot8zx8p.jpgdata/attachment/forum/202204/08/235459hu5xgw5quzqzuyjg.jpgdata/attachment/forum/202204/08/235500hn30iz6q1kt2wowe.jpg

Then applied the Interface Access Control toTe0/0
data/attachment/forum/202204/08/235718ceq9qk43svku9sx6.jpg


I am still able to ping between several of the Vlans. Is there something I am missing?

GTAC-Patrick Publish time 2022-7-27 11:53:27

Edited by Patrick at 2022-7-27 23:53

Dear sir,

Sorry for the late replying.
After viewing your description and configuration, I found that you set the wrong wildcard-mask of ACL. The wildcard-mask should be 0.0.0.127 according to the submask 255.255.255.128, and 0.0.0.63 for 255.255.255.192 in the same way.

And It's recommended that using the inbound for the Extended ACL filter direction.

Best regards,
Patrick

masmith22@veriz Publish time 2022-7-28 06:35:14

Patrick replied at 2022-7-27 11:53
Dear sir,

Sorry for the late replying.


Thank you, will give this a try.

ict_infra@iccs. Publish time 2024-6-11 00:16:14

Mario replied at 2022-7-28 06:35
Thank you, will give this a try.

Hi, I have a similar scenario where ACLs are working as expected, blocking inter-VLAN routing to all sub-interface LANs. However, this time, I need to allow some devices on VLAN 10 (10.1.1.10) to communicate with VLAN 20 (20.1.1.10). For example, I have a service on VLAN 10 that needs to be accessed from VLAN 20.
I have set up ACLs on both VLAN interfaces to permit traffic between these VLANs, but it doesn't seem to be working. Both VLANs are unable to communicate, although they can ping the gateway of each VLAN.
I have attached an image for reference. Can you check and suggest what I might be missing?
data/attachment/forum/202406/11/001527ela4um15md5tbmlb.pngdata/attachment/forum/202406/11/001527jdq373d7qp3377pp.pngdata/attachment/forum/202406/11/001527g1nw4a817nsompaa.png

Pages: [1]
View full version: EG3230 ACL to Block inter-vlan routing