Wired Intelligent Edge

 View Only
last person joined: yesterday 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution

OSPF and ACLs on HPE/Aruba 5400-series devices

This thread has been viewed 1 times
  • 1.  OSPF and ACLs on HPE/Aruba 5400-series devices

    Posted May 17, 2019 04:57 PM

    I've noticed interesting behavior when it comes to OSPF multicast traffic and ACLs on the 5400-series devices. It appears that you cannot block OSPF LSUs to 224.0.0.5 and 224.0.0.6 using either inbound or outbound ACLs on VLAN interfaces. I've tried many variations of my test ACLs (deny ip/deny udp/deny ospf...) as well as straight up denying all traffic and OSPF traffic continues to flow through the VLAN interfaces in question.

     

    However, if you apply the same ACL inbound to an uplink port that has an OSPF neighbor on the other end, the traffic is blocked. I haven't been able to find any documention where this is behavior is stated. I have other L2/L3 devices where applying the deny to the VLAN interface immedately blocks OSPF LSUs. 

     

    Now, in the end, I don't actually want to block OSPF traffic. But I found this behavior to be interesting and a little unexpected. Does anyone know of other types of traffic that is ignored by ACLs placed on VLAN interfaces? Thanks.