Unfortunately, this was not successful, except that the networks that were connected afterwards were blocked. It seems that the acl does not work on the switch's own ip address.
Here are more information about the configuration.
interface ethernet1/1/12 description "XXXXX" no shutdown no switchport ip vrf forwarding 12 ip address XXX.XXX.XXX.XXX/31 ipv6 address XXXX:XXXX:XXXX:XXXX::X/127 flowcontrol receive on ip access-group 179 in ntp disable
I have tested on another dell switch with SSH. A VLAN where SSH is open. And an ACL that is supposed to restrict this. The ACLs there also do not restrict the IPs assigned on the switch itself, although the drop-count goes up.
ip ssh server vrf 2
interface vlan2 vlan-name Test description "Test" no shutdown ip vrf forwarding 2 ip address 192.168.1.1/24 ip access-group test in no ip dhcp snooping
DellOS10# show ip access-lists in Ingress IP access-list test Active on interfaces : vlan2 seq 11 permit tcp host 192.168.1.2 host 192.168.1.1 eq 22 log count (1266 packets) seq 21 deny tcp any host 192.168.1.1 eq 22 log count (227 packets) seq 22 deny ip any any
DELL-Chris H
7 Practitioner
•
9682 Posts
•
48046 Points
0
0
Posted March 10th, 2025 19:35
Max1332345,
From looking at the configuration, what I would suggest is to start by removing the
seq 30 permit ip any any
and then see if it works.
Let me know what you see and if this helps.
DELL-Chris H
Social Media and Communities Professional
Dell Technologies | Enterprise Support Services
#IWork4Dell
Did I answer your query? Please click on ‘Mark as Accepted Answer’. ‘Thumbs up’ the posts you like!