habz99 Posted November 21, 2016 Posted November 21, 2016 Hi, I have an HP Procurve 5412zl switch that I want to add the following ACL's on as we have having issues with Meraki SM communicating with our ios devices and Meraki suggest the we add the following to our ACL: Destination_IP: 50.115.86.96/27, 185.17.255.128/25, 185.92.120.0/25, 217.89.128.0/24 Ports: 993 Protocol: TCP Direction: outbound Destination_IP: 50.115.86.96/27, 185.17.255.128/25, 185.92.120.0/25, 217.89.128.0/24 Ports: 60000-61000 TCP outbound Destination_IP: 17.0.0.0/8 Ports: 443, 2195-2196, 5223 TCP outbound Destination_IP: Any Ports: 5228-5230 TCP outbound Destination_IP: Any Ports: 80, 443 TCP outbound HP 5412zl does not have a gui for configuration of ACLs. At least not through the web interface. So I need to be able to do it from command line. Thanks
Davit2005 Posted November 21, 2016 Posted November 21, 2016 These are all external IPs?? Why are you setting up on the core switch?? 1
habz99 Posted November 22, 2016 Author Posted November 22, 2016 i have inherited the network and it is setup like this, yes they are external IP's.
Davit2005 Posted November 22, 2016 Posted November 22, 2016 Sure the company do not want these on an external facing firewall?? Normally internal switches would jus be containing ACL for internal networks. 1
habz99 Posted November 22, 2016 Author Posted November 22, 2016 Our LEA who manage the firewall have configured the relevant on their side (but the traffic is not reaching that far) i now need to add these ip's etc. to the ACL. As the switch does not have a gui for configuration of ACLs. I need to be able to do it from command line... do you know how? my knowledge of ACL is basic.
Davit2005 Posted November 22, 2016 Posted November 22, 2016 Yes I done one at last place for Internal traffic to stop access to servers. Can you paste a copy of the existing switch config but remove any passwords etc. So we can see what may be blocking the traffic. Also give us an idea of how to advise you of where to apply the ACL to i.e. vLan, interface etc.. I will post the ACL I configured, it was a vLAN based ACL so may not be what you are after. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now