Comware

 View Only
Expand all | Collapse all

A-Series: Isolate Switch Management Traffic in L3 Environment

This thread has been viewed 0 times
  • 1.  A-Series: Isolate Switch Management Traffic in L3 Environment

    Posted Nov 09, 2011 07:10 AM
    Hi! We have several A5800-48G Switches in an IRF Configuration and want to isolate the Management Traffic to the Switches using a separate VLAN routet via the Firewall. As the A5800 has several Virtual Interfaces with IP Addresses, the switch management can be reached in those VLANs which should not be allowed. Questions: Must we use ACLs to achieve this or is there an 'easier' possibility? How could we isolate the traffic using ACLs in an easy way (we normally don't want ACLs on routing switches...)? Any ideas? With regards Manfred
    #ManagementVLAN


  • 2.  RE: A-Series: Isolate Switch Management Traffic in L3 Environment

    Posted Nov 09, 2011 05:24 PM

    I dont know about easier, but you want really separated management interfaces you could put them in an own VRF (called vpn-instance in the 5800).