Solved

Configuring Inter VLAN ACL on HP Switch

Posted on 2013-10-23
6
649 Views
Last Modified: 2013-11-13
Hi,

I have an HP E5412zl in routed mode with various VLANs.

I have a scenario where I have VLAN 1, 2 and 3.

I'm trying to restrict VLAN 1 so that it can't communicate with the subnets on VLAN2 and VLAN3. However, I still want VLAN 2 and 3 to be able to communicate with VLAN1 when needed.

With the above configuration VLAN 1 should only be able to access the internet, not VLAN 2 and 3.

I know the basic syntax for creating named extended ACLs but I can't seem to get it right in applying it to the VLANs and making it work like the above.

Thanks.
0
Comment
Question by:RFVDB
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 50

Expert Comment

by:Don Johnston
ID: 39596651
Here's the problem:

In order for VLAN 2 and 3 to be able to talk to VLAN 1, then the traffic from VLAN 1 must be able to get to VLAN 2 and 3.  Therefor VLAN 1 must be able to talk to VLANs 2 & 3.

Now there's a work-around to this, but it's not perfect.  You can allow TCP traffic from 1 to 2 & 3 only if it's a response.  And you can do the same with ICMP echo replies.  But there's not much you can do about UDP traffic.

So if you don't have any UDP traffic, you're all set.
0
 

Author Comment

by:RFVDB
ID: 39598047
Hi donjohnston,

Yeah, I don't think UDP traffic is really a concern security wise. I don't think hackers can really do anything with just UDP.

I'm trying to create a DMZ on this VLAN on the switch.

So the Layer 3 HP switch can't do what a router/firewall can do with stateful inspection between subnets? I guess I'll take whatever it can do.

Thanks!
0
 

Author Comment

by:RFVDB
ID: 39602061
Is it using the "Established" ACL parameter, similar to the old Cisco ACLs? I've used that in the past years ago on Cisco routers, just not sure if that's an option on the HP switch or if there's something better.
0
Save the day with this special offer from ATEN!

Save 30% on the CV211 using promo code EXPERTS30 now through April 30th. The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 
LVL 50

Expert Comment

by:Don Johnston
ID: 39602574
Yes, that's how it's done.

And that's your only option (for this type of task) on an HP switch.
0
 

Author Comment

by:RFVDB
ID: 39603231
OK, do you know where I can find some good documentation on doing it on an HP switch?
0
 
LVL 50

Accepted Solution

by:
Don Johnston earned 500 total points
ID: 39603277
It's the exact format and syntax as Cisco ACL's.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Cybersecurity has become the buzzword of recent years and years to come. The inventions of cloud infrastructure and the Internet of Things has made us question our online safety. Let us explore how cloud- enabled cybersecurity can help us with our b…
This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question