troubleshooting Question

Proper ACL for guest wireless traffic

Avatar of Raymond Norton
Raymond Norton asked on
Switches / HubsNetworkingSecurity
2 Comments1 Solution152 ViewsLast Modified:
Info:
Aruba 3810
Vlans 801,802,803

Vlan 802 is our guest wireless subnet. I need to allow it to pull DNS from 801, pull dhcp from the switch, but not have any other access to 801 or 802 and go directly to the Internet, allowing all protocols. I only have access to the switch and am unable to test, so need to be sure I have things set up correctly. Does this accomplish what I need, based on the included config?

ip access-list extended "Guest Vlan Access"
     10 permit tcp 10.10.0.0 0.0.255.255 eq 53 172.17.0.0 0.0.255.255 log
     20 deny ip 10.10.0.0 0.0.255.255 172.17.0.0 0.0.255.255 log
     30 deny ip 10.10.0.0 0.0.255.255 10.13.0.0 0.0.255.255 log
     40 permit ip 10.10.0.0 0.0.255.255 0.0.0.0 255.255.255.255



Config:
vlan 801
   name "VLAN801"
   untagged 13
   ip address 172.17.1.2 255.255.0.0
   exit
vlan 801
   name "VLAN801"
   untagged 13
   ip address 172.17.1.2 255.255.0.0
   exit
vlan 802
   name "VLAN802"
   untagged 15
   ip access-group "Guest Vlan Access" out
   ip address 10.10.250.2 255.255.0.0
   dhcp-server
   exit

vlan 803
   name "VLAN803"
   untagged 16
   ip address 10.13.253.1 255.255.0.0
   dhcp-server
   exit
ASKER CERTIFIED SOLUTION
Raymond NortonWAN Admin

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 2 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 2 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros