Gateway ACL's not working (can ping denied interfaces)
Hardware in use:
Gateway (router) : Er707 M2
Core Switch: SG3428
PoE switch: SG2210MP
WAP: EA615
Switch: ES205G
Controller : OC200
Hello:
I have configured my network as per this guide. But using only a single management vlan.
ie: gateway is 10.10.10.2 and devices are on 10.10.50.1/24 (also note devices have after readoption been asigned a static ip)
Is there any reason why gateway ACL's would not work with this config?
Whether or not i connect a device to a gateway Lan port (with a Vlan configured as interface on gateway & PVID set correctly) or a switch port .
Note: 2 separate vlan interfaces are being used here 10.10.100.1/24 & 10.10.110.1/24
ACL's with a deny in either direction simply do not function.
I am able to ping in both directions always.
Is there any reason why this would be?
Is it because...of
--> Mangement Vlan configured on switch?
-->
--> Easy managed switch has been intergrated into network?
or....
note:
*switch ACL's work as intended but all are off for testing gateway ACL)
and as per guide...
*static route on switch is 0.0.0.0/0 --> 10.10.10.2 (static gateway ip)
*Static transmission route set as 10.10.50.0/24 next hop --> 10.10.10.1
I do require some stateful ACL's in my network.
Please advise.
Thanykou in advance.