Mailing List Archive

Good advice on Access Control Lists on ExtremeWare
Hello,

Anyone have good advice on using ACLs on ExtremeWare, namely the BD 6808
MSM64i. I know it's old but have one left and never had ACLs on it just
used Cisco's around it. Now would like to put some security on it directly
as we plan to upgrade end of this year or next to ExtremeXOS supported gear.

Would like to accomplish:

1. BCP38
2. Block couple ports switch wide
3. Limit telnet/ssh to switch on all IPs assigned. (With Cisco this is easy)

For example with #3 if you have layer 3 VLANs now every gateway IP has
access to switch via telnet/ssh. With Cisco you could apply ACL to VTY and
it's done.

For example with #2 block tcp/udp 135,137,138.139.445.

For example with #1 prevent spoofing, and etc on ingress and egress.

Also, it would be helpful if someone couple provide an example or provide
links to good resources.
I've read the reference command guide but not sure I understand correctly.

Thanks,

Any advice is appreciate for sure!
Re: Good advice on Access Control Lists on ExtremeWare [ In reply to ]
On Mon, 21 Apr 2014, root net wrote:

> I've read the reference command guide but not sure I understand
> correctly.

One thing that is not obvious, is that the ACL is applied per port, and
doesn't have vlan significance. So watch out for that if you're trying to
provide L2 services that shouldn't be ACLed.

--
Mikael Abrahamsson email: swmike@swm.pp.se
_______________________________________________
extreme-nsp mailing list
extreme-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/extreme-nsp