Announcement Banner
UNSOLVED

orybatzki

updated

9 years ago

O

orybatzki

1 Rookie

•

11 Posts

0

3327

December 12th, 2017 06:00

IP ACL problems N-Series switch

Hi,

defining a rule following the description on page 711 User Guide the swich notes

"% Invalid input detected at '^' marker."

for the following acl

permit every 10.10.10.0 0.0.1.255 10.50.10.0 0.0.0.255

The marker points to the first 1 of the first ip address. Trying ip instead of every produces problems so I decided to try every. The documentation notes for "every"

"every: Match any protocol (don’t care)"

Any idea what went wrong and where the difference is between every and ip?

Olav

  • DELL-Josh Cr

    Community Manager

    •

    9734 Posts

    •

    44224 Points

    2447

    0

    Posted December 12th, 2017 10:00

    Hi,

    What firmware version are you on? Does it allow you to do permit every without an ip range after? 

  • orybatzki

    1 Rookie

    •

    11 Posts

    2447

    0

    Posted December 13th, 2017 05:00

    Hi,

    firmware version is 6.3.3.10. A short test shows that a

    permit every

    is accepted by the swich. A permit anything is the same as no acl, so not of interest. I'm interested to permit tcp, udp, and icmp. On Cisco systems "ip" does this but I'm not sure for the Dell system.

  • DELL-Josh Cr

    Community Manager

    •

    9734 Posts

    •

    44224 Points

    2447

    0

    Posted December 13th, 2017 09:00

    Can you try

    permit tcp,udp,icmp 10.10.10.0 0.0.1.255 10.50.10.0 0.0.0.255

     

    or

    permit tcp 10.10.10.0 0.0.1.255 10.50.10.0 0.0.0.255

    permit udp 10.10.10.0 0.0.1.255 10.50.10.0 0.0.0.255

    permit icmp 10.10.10.0 0.0.1.255 10.50.10.0 0.0.0.255

  • orybatzki

    1 Rookie

    •

    11 Posts

    2447

    0

    Posted December 13th, 2017 09:00

    This is what I want to try tomorrow. There is another problem at this point, the complete access-list blocks the VLAN internal traffic and is one reason to look at the every statement. The example given is only one line of the access-list.

    A short test of your first example does not work but this is only a shorter way to define the second example.

    As far as I have an result I let you know.

  • orybatzki

    1 Rookie

    •

    11 Posts

    2447

    0

    Posted December 15th, 2017 02:00

    Hi,

    I tested it. Defining rules for tcp, udp, and icmp works but only for connections to different subnet/vlans. if I add the access-list to the vlan all subnet internal traffic will be blocked. Any idea what happens?

    The complete access-list looks as follow

    ip access-list acl912-out
    !
    permit tcp 10.10.10.0 0.0.1.255 10.10.10.0 0.0.1.255
    permit udp 10.10.10.0 0.0.1.255 10.10.10.0 0.0.1.255
    permit icmp 10.10.10.0 0.0.1.255 10.10.10.0 0.0.1.255
    !
    !
    permit ip host 192.168.78.78 10.10.10.0 0.0.1.255
    !
    permit ip host 192.168.1.150 10.10.10.0 0.0.1.255
    permit ip host 192.168.1.250 10.10.10.0 0.0.1.255
    !
    permit tcp 10.10.0.0 0.0.255.255 10.10.10.0 0.0.1.255
    permit udp 10.10.0.0 0.0.255.255 10.10.10.0 0.0.1.255
    permit icmp 10.10.0.0 0.0.255.255 10.10.10.0 0.0.1.255
    !
    permit ip 10.51.1.0 0.0.0.255 10.10.10.0 0.0.1.255
    !
    permit tcp host 192.168.9.99 10.10.10.0 0.0.1.255
    !
    permit tcp host 10.100.1.21 10.10.10.0 0.0.1.255
    permit tcp host 10.100.1.22 10.10.10.0 0.0.1.255
    permit tcp host 192.168.8.31 10.10.10.0 0.0.1.255
    permit tcp host 192.168.8.32 10.10.10.0 0.0.1.255
    !
    permit tcp host 192.168148.10 10.10.10.0 0.0.1.255
    !
    permit tcp host 192.168.1.101 10.10.10.0 0.0.1.255
    !
    permit tcp host 192.168.8.174 10.10.10.0 0.0.1.255
    !
    exit

    I added the first 3 rules to see if they prevent the subnet internal traffic blocking.

  • DELL-Josh Cr

    Community Manager

    •

    9734 Posts

    •

    44224 Points

    2447

    0

    Posted December 15th, 2017 07:00

    What happens if you add the acl to a port?

  • orybatzki

    1 Rookie

    •

    11 Posts

    2447

    0

    Posted December 18th, 2017 04:00

    It's not possible to assign the ACL to a port. It is a L3 instance with a lot of VLANs/subnet where I want to restrict the incoming and outgoing traffic to the specific VLAN/subnet. Beside that, I have no free port for testing purposes. I will see if I can test it on a different system but this will take some time.