This post is more than 5 years old

9 Posts

24080

February 8th, 2013 07:00

Setting VLAN ACL will block all traffic inside the vlan

Hi,

I've testing a PowerConnect 7024 Switch, made some vlans and would like to test traffic between 2 PCs connecting to the default vlan. So i put one PC on Port 1 and the other one on Port 2.

I've only applied a permit ICMP any any Rule onto this vlan. This implies a deny all rule.


But now, i cannot ssh from one PC to another?

the ACL is an ibound IP AC, but i thought this does not affect traffic in the vlan? Or am i'm think wrong?

9 Posts

February 11th, 2013 01:00

Hi,

Thanks for your advice, I've read all of the articles above.

Before posting the configuration, I would like to theretically clear out how ACL work.

If I set an inbound IP ACL based on a vlan and I have two or more clients in that network - will they communicate with each other ignoring the ACL? I suggested, they will apply, when a packet ENTERS the network, but the clients are already INSIDE this network. So the switch would.. well he would switch and not route?

At the moment, i have set an ACL that only permits ICMP. I could ping the clients, but nothing more. Is this the correct behaviour?

No Events found!

Top