Unsolved

This post is more than 5 years old

7 Posts

4279

April 26th, 2006 15:00

ACL Problem with Dell 3324 Managed Switch

This is what I need to do: Basically the entire company PC’s, including our department PC’s pass though an HP 4000 switch in our department building on their way to the company firewall.  We have 4 servers in our department that I want to control traffic flow to, i.e. Only requests from department PCs will be fowarded to these servers. I have moved the department Servers to the Dell 3324 swich on ports E1 – E4 respectivly, and attached a cable between Port E22 on the Dell to an open Port on the HP switch.

Here is the basic configuration:

I have an ACL on Dell, PORT E22 that allows only our department MAC ID’s to pass. This is working correctly, and no other pc other than our Department PC’s can access the servers attached to the Dell switch.  Now I want to further control which MAC IDs are allowed to access specidfic servers attached to the Dell Switch.

Server 1 is attached to Port E1

Server 2 is attached to Port E2

Server 3 is attached to Port E3

Server 4 is attached to Port E4

Here is the problem I am experiencing.

I have craeted an ACL that only allows certain MAC ID’s to access Port E1, but when I apply it to Port E1 access to that server is denied to everyone. 

Here is my configuration:

ACL 100 - Bonud to Port E24

ACE 1 Permit Source MAC ID 00:00:00:00:00:00 Destination ID: 00:00:00:00:00

 

ACL 200 - Bound to Port E1

ACE 2 Permit Source MAC ID: SPECIFIC MAC ID Destionation ID: MAC ID OF SERVER 1

If I remove ACL 200 all PC’s that are permitted to enter the Dell switch are allowed to access Server 1, if I bind ACL 200 no PC is allowed to access Server 1, not even the allowed MAC ID mentioned in the ACL.

 

Any help would be greatly appriciated.

 

 

 

2 Intern

 • 

128 Posts

April 27th, 2006 13:00

When your permitting your specific hosts, are you using an all zero mask ?

thanks

7 Posts

April 27th, 2006 14:00

Thanks for your reply. No I am not using 00's at all, the ACL 100 actually contains a list of specific MAC ID's.   One question: I understand that the 3324 only allows ACL rules to work on ingress traffic.  In my case does ingress traffic apply to both Port E24 (traffic from the network), and E1 (Traffic which has entered the swich, from the network and is now traveling to the server attached to port E1)

 

No Events found!

Top