Big Challenge Big Challenge Big Challenge any body can solve ?

Unanswered Question
Oct 10th, 2007
User Badges:

ok .... i have this case:

i have AS5400 gateway & PGW 2200 i did mistake in the design & configuration for PGW2200 the best design for PGW needs only to talk with AS.

I configured only one interface for AS5400 but i put the interface for AS to talk with other nodes in the network it is not mistake but best design for security to make one interface dedicated for PGW2200 and other interface to talk with other nodes in the network and re-configure the PGW it very critical i don't need to follow this path.

Now i have one configured interface for AS and i need this interface to be dedicated for PGW2200 and at the same time can ping other nodes?. I don?t need any nodes to reach the PGW2200 except the AS.

I don?t know if VLAN or ACLs can solve that ? any idea plz.

Can you help me please?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Konstantin Dunaev Wed, 10/10/2007 - 01:06
User Badges:
  • Bronze, 100 points or more

if your AS and PGW are connected to some L2 switch, then it's easy to assign the different VLAN to those ports and then manage the access with help of ACL on L3 device.

or if you should have all devices in the same VLAN then other thing that could help it is a private VLAN, with AS in "primary" VLAN and PGW in "isolated secondary" VLAN.

or you just configure the accesslist on your PGW to allow connection only from AS.


This Discussion