Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I am setting up some ACLs on our HP 5412zl to block a VLAN from all other VLANs and just want to see which method is best. I have the basic ACL working but I'm not sure the best place to apply the rest. In this ACL I am allowing only DHCP through but want all other traffic to be denied unless it's going out the Internet. Note that this configuration uses external DNS servers. We have about 10 different VLANs throughout our district and in this initial configuration I am only denying access to one (10.5.1.0/24). My main question is it better to apply each VLAN in this ACL or an ACL on that VLAN? Do I need to put all 10 VLAN deny statements in this ALLOW_DHCP_ONLY access-list or use one on each separate VLAN blocking access from the one VLAN that shouldn't be accessing others?

 

ip access-list extended "ALLOW_DHCP_ONLY"
10 permit udp 0.0.0.0 255.255.255.255 eq 68 0.0.0.0 255.255.255.255 eq 67
20 deny ip 0.0.0.0 255.255.255.255 10.5.1.0 0.0.0.255
30 permit ip 0.0.0.0 255.255.255.255 0.0.0.0 255.255.255.255

Posted

For the least amount of admin overhead / management / policy processing, put the ACL on the single vlan that you want to block access to.

The best practice is to put the rule nearest the destination.

For example you want to block vlan 1 and allow 2 and 3;

If I am in vlan 2 and try to contact vlan 3 no policy needs to be processed.

If you put the policy on vlan 2 and 3, the switch needs to processes the policy just to do nothing.

 

I hope I explained that clear enough.

 

Cheers.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...