This post is more than 5 years old
9 Posts
0
24080
February 8th, 2013 07:00
Setting VLAN ACL will block all traffic inside the vlan
Hi,
I've testing a PowerConnect 7024 Switch, made some vlans and would like to test traffic between 2 PCs connecting to the default vlan. So i put one PC on Port 1 and the other one on Port 2.
I've only applied a permit ICMP any any Rule onto this vlan. This implies a deny all rule.
But now, i cannot ssh from one PC to another?
the ACL is an ibound IP AC, but i thought this does not affect traffic in the vlan? Or am i'm think wrong?
No Events found!


hoeschler
9 Posts
0
February 11th, 2013 01:00
Hi,
Thanks for your advice, I've read all of the articles above.
Before posting the configuration, I would like to theretically clear out how ACL work.
If I set an inbound IP ACL based on a vlan and I have two or more clients in that network - will they communicate with each other ignoring the ACL? I suggested, they will apply, when a packet ENTERS the network, but the clients are already INSIDE this network. So the switch would.. well he would switch and not route?
At the moment, i have set an ACL that only permits ICMP. I could ping the clients, but nothing more. Is this the correct behaviour?