Services are interrupted after a traffic policy is configured in a VLAN

Created: Dec 30, 2019 06:19:55Latest reply: Dec 30, 2019 06:20:16 68 1 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello, everyone.

As shown in the networking diagram, Huawei switches are used to replace Cisco switches. PC1 and PC2 need to communicate with each other at Layer 2 in VLAN 100. PC1 and PC2 are allowed to access the external network segment 172.16.0.0/16 but not other network segments. The network segment of PC1 and PC2 is 192.168.1.0/24. On the Cisco switch, configure the VLANIF interface to allow 192.168.1.0/24 to access 172.16.0.0/16 and discard other packets. The ACL configuration is as follows. After the same configuration is performed on the Huawei switch, the two PCs cannot access the Internet.

Please help me solve this problem. Thank you!

The networking is as follows:

network

The configuration is as follows:

acl number 3000

rule 10 permit ip source 192.168.1.0 0.0.0.255 destination 172.16.0.0 0.0.255.255

rule 15 deny ip

traffic classifier test

if-match acl 3000

traffic behavior test

permit

traffic policy test

classifier test behavior test

vlan 100

traffic-policy test inbound


  • x
  • convention:

Featured Answers
DDSN
Admin Created Dec 30, 2019 06:20:16 Helpful(0) Helpful(0)

Hi, WDNJSQ.
The ACL configured on the VLANIF interface of the Cisco switch filters packets forwarded at Layer 3 (forwarding based on the Layer 3 routing table) but does not filter packets forwarded at Layer 2 (forwarding based on the MAC address table). Huawei switches do not support ACL-based packet filtering on VLANIF interfaces, but support packet filtering on VLANs. Packets forwarded at both Layer 2 and Layer 3 are filtered out on Huawei switches. Therefore, packets that are not permitted are filtered out. The configuration does not permit the packets between users on the same network segment. As a result, users in VLAN 100 cannot communicate with each other.
You can add an ACL rule to allow the communication between the network segments of the VLAN. For example: rule 15 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
  • x
  • convention:

All Answers
DDSN
DDSN Admin Created Dec 30, 2019 06:20:16 Helpful(0) Helpful(0)

Hi, WDNJSQ.
The ACL configured on the VLANIF interface of the Cisco switch filters packets forwarded at Layer 3 (forwarding based on the Layer 3 routing table) but does not filter packets forwarded at Layer 2 (forwarding based on the MAC address table). Huawei switches do not support ACL-based packet filtering on VLANIF interfaces, but support packet filtering on VLANs. Packets forwarded at both Layer 2 and Layer 3 are filtered out on Huawei switches. Therefore, packets that are not permitted are filtered out. The configuration does not permit the packets between users on the same network segment. As a result, users in VLAN 100 cannot communicate with each other.
You can add an ACL rule to allow the communication between the network segments of the VLAN. For example: rule 15 permit ip source 192.168.1.0 0.0.0.255 destination 192.168.1.0 0.0.0.255
  • x
  • convention:

Comment

Reply
You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

My Followers

Login and enjoy all the member benefits

Login and enjoy all the member benefits

Login