Wireless Access

last person joined: 16 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

VLAN based session acl issue ArubaOS 8.5.0.0

This thread has been viewed 5 times
  • 1.  VLAN based session acl issue ArubaOS 8.5.0.0

    Posted Jul 19, 2019 07:42 AM

    Hi,

     

    I have an issue with session ACL assigned to a VLAN on a trunk port (port-channel). Controller model 7210, OS 8.5.0.0 The ACL is applied only to the traffic originated FROM the VLAN, but any traffic TO the VLAN is allowed. Maybe it is the intended behavior, can anyone confirm this?

    Command on trunk port with all VLANs trusted:

    'ip access-group vlan 30 session "ACL-name"'

    Any traffic towards a host in the VLAN is permitted, ACL works only for traffic coming from the VLAN.

     

    Regards,

    Balazs

     



  • 2.  RE: VLAN based session acl issue ArubaOS 8.5.0.0

    EMPLOYEE
    Posted Jul 19, 2019 08:25 AM
    Before answering your question, are you trying to apply this ACL to wired or wireless traffic? I am asking because it is better to apply an ACL to a role, rather than a VLAN, because it is more granular..


  • 3.  RE: VLAN based session acl issue ArubaOS 8.5.0.0

    Posted Jul 19, 2019 08:33 AM

    Hi Cjoseph,

     

    It is for wired traffic. 



  • 4.  RE: VLAN based session acl issue ArubaOS 8.5.0.0
    Best Answer

    EMPLOYEE
    Posted Jul 19, 2019 09:19 AM

    Okay.

     

    If you put an ACL on a port/VLAN, it typically applies to traffic that is coming into the controller.  You can type "show acl hits" on the MD to see how many times your ACL is actually hit.



  • 5.  RE: VLAN based session acl issue ArubaOS 8.5.0.0

    Posted Jul 19, 2019 09:36 AM

    Thanks for the answer. I guess it is not desired to use a controller as a "wired" firewall. Is there any suggestion for FW functionality for wired traffic? (e.g. controlling in and out traffic also) Or Aruba design recommends handling wired VLAN separation on other device instead of the controller?



  • 6.  RE: VLAN based session acl issue ArubaOS 8.5.0.0

    EMPLOYEE
    Posted Jul 19, 2019 09:43 AM

    That is not the primary use case but it is possible.  The simplest example is If you can separate the physical in/out you can apply the ACL to the "in" port and probably accomplish what you need.



  • 7.  RE: VLAN based session acl issue ArubaOS 8.5.0.0

    Posted Jul 19, 2019 09:59 AM

    Yes, that is the workaround for now, filtering inbound on the "uplink" VLAN and also inbound on the "protected" VLANs. Just would have been better to control the rules per VLAN...

     

    Thanks for the quick help, anyway :)

     

    Regards,

    Balazs