Solved

Configuring Inter VLAN ACL on HP Switch

Posted on 2013-10-23
6
641 Views
Last Modified: 2013-11-13
Hi,

I have an HP E5412zl in routed mode with various VLANs.

I have a scenario where I have VLAN 1, 2 and 3.

I'm trying to restrict VLAN 1 so that it can't communicate with the subnets on VLAN2 and VLAN3. However, I still want VLAN 2 and 3 to be able to communicate with VLAN1 when needed.

With the above configuration VLAN 1 should only be able to access the internet, not VLAN 2 and 3.

I know the basic syntax for creating named extended ACLs but I can't seem to get it right in applying it to the VLANs and making it work like the above.

Thanks.
0
Comment
Question by:RFVDB
  • 3
  • 3
6 Comments
 
LVL 50

Expert Comment

by:Don Johnston
ID: 39596651
Here's the problem:

In order for VLAN 2 and 3 to be able to talk to VLAN 1, then the traffic from VLAN 1 must be able to get to VLAN 2 and 3.  Therefor VLAN 1 must be able to talk to VLANs 2 & 3.

Now there's a work-around to this, but it's not perfect.  You can allow TCP traffic from 1 to 2 & 3 only if it's a response.  And you can do the same with ICMP echo replies.  But there's not much you can do about UDP traffic.

So if you don't have any UDP traffic, you're all set.
0
 

Author Comment

by:RFVDB
ID: 39598047
Hi donjohnston,

Yeah, I don't think UDP traffic is really a concern security wise. I don't think hackers can really do anything with just UDP.

I'm trying to create a DMZ on this VLAN on the switch.

So the Layer 3 HP switch can't do what a router/firewall can do with stateful inspection between subnets? I guess I'll take whatever it can do.

Thanks!
0
 

Author Comment

by:RFVDB
ID: 39602061
Is it using the "Established" ACL parameter, similar to the old Cisco ACLs? I've used that in the past years ago on Cisco routers, just not sure if that's an option on the HP switch or if there's something better.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 50

Expert Comment

by:Don Johnston
ID: 39602574
Yes, that's how it's done.

And that's your only option (for this type of task) on an HP switch.
0
 

Author Comment

by:RFVDB
ID: 39603231
OK, do you know where I can find some good documentation on doing it on an HP switch?
0
 
LVL 50

Accepted Solution

by:
Don Johnston earned 500 total points
ID: 39603277
It's the exact format and syntax as Cisco ACL's.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

861 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question