
C-13
Troubleshooting
Unusual Network Activity
Figure C-4. Example of Inadvertently Blocking a Gateway
To avoid inadvertently blocking the remote gateway for authorized traffic
from another network (such as the 20 Net in this example):
1.
Configure an ACE that specifically permits authorized traffic from the
remote network.
2.
Configure narrowly defined ACEs to block unwanted IP traffic that would
otherwise use the gateway. Such ACEs might deny traffic for a particular
application, particular hosts, or an entire subnet.
3.
Configure a “permit any” ACE to specifically allow any IP traffic to move
through the gateway.
Local Gateway Case.
If you use the switch as a gateway for traffic you want
routed between subnets, use these general steps to avoid blocking the gateway
for authorized applications:
1.
Configure gateway security first for routing with specific permit and deny
statements.
2.
Permit authorized traffic.
3.
Deny any unauthorized traffic that you have not already denied in step 1.
30 Net
IP: 30.29.16.1
(Deflt. Gateway)
Router X
10 Net
IP: 10.0.8.1
8212zl
10 Net -- VLAN 1
IP: 10.08.15
(Deflt. G’Way = 10.0.8.1)
Switch 1
20 Net -- VLAN 2
IP: 20.0.8.21
(Deflt. G’way = 20.0.8.1)
20 Net VLAN 2
IP: 20.0.8.1
(Deflt. G’way
for 20.0.8.1)
30.29.16.91
Switch 2
10 Net -- VLAN 1
IP: 10.0.8.16
(Deflt. G’way = 10.0.8.1)
Switch 1 cannot
access the 30 Net on
Router X because ACL
101 on the Switch
8212zl denies routed,
outbound IP traffic to
the 10 Net.
3500-5400-6200-8200-MCG-Jan08-K_13_01.book Page 13 Monday, January 28, 2008 10:04 AM
Содержание 3500yl Series
Страница 2: ......
Страница 26: ...xxiv 3500 5400 6200 8200 MCG Jan08 K_13_01 book Page xxiv Monday January 28 2008 10 04 AM...
Страница 730: ...20 Index 3500 5400 6200 8200 MCG Jan08 K_13_01 book Page 20 Monday January 28 2008 10 04 AM...
Страница 731: ......
Страница 732: ...Copyright 2005 2008 Hewlett Packard Development Company L P January 2008 Manual Part Number 5992 3059...