defining a rule following the description on page 711 User Guide the swich notes
"% Invalid input detected at '^' marker."
for the following acl
permit every 10.10.10.0 0.0.1.255 10.50.10.0 0.0.0.255
The marker points to the first 1 of the first ip address. Trying ip instead of every produces problems so I decided to try every. The documentation notes for "every"
"every: Match any protocol (don’t care)"
Any idea what went wrong and where the difference is between every and ip?
firmware version is 6.3.3.10. A short test shows that a
permit every
is accepted by the swich. A permit anything is the same as no acl, so not of interest. I'm interested to permit tcp, udp, and icmp. On Cisco systems "ip" does this but I'm not sure for the Dell system.
This is what I want to try tomorrow. There is another problem at this point, the complete access-list blocks the VLAN internal traffic and is one reason to look at the every statement. The example given is only one line of the access-list.
A short test of your first example does not work but this is only a shorter way to define the second example.
I tested it. Defining rules for tcp, udp, and icmp works but only for connections to different subnet/vlans. if I add the access-list to the vlan all subnet internal traffic will be blocked. Any idea what happens?
It's not possible to assign the ACL to a port. It is a L3 instance with a lot of VLANs/subnet where I want to restrict the incoming and outgoing traffic to the specific VLAN/subnet. Beside that, I have no free port for testing purposes. I will see if I can test it on a different system but this will take some time.
DELL-Josh Cr
Community Manager
•
9734 Posts
•
44224 Points
2447
0
Posted December 12th, 2017 10:00
Hi,
What firmware version are you on? Does it allow you to do permit every without an ip range after?