Hello friends, I write these lines because an issue with mac acl. I have a Cisco 6513 and I want to configure a simple mac acl to permit the traffic between a virtual machine (VM) and a rackeable server (RS) and block the traffic between my network and RS. So, this is the parameters:
VM: connected to Cisco 6513 in 4/15 - mac add a.b.c.d - ip add 10.0.0.1/16
RS: connected to Cisco 6513 in 6/48 - mac add w.x.y.z - ip add 10.0.0.2/16
My Computer: connected to an access switch - mac j.k.l.m - ip add 188.8.131.52/16
Once the configuration was finished, I tried to ping from my computer and got replies! Well, I though it was because the equipments were in differents modules, and I changed the RS from 6/48 to 4/38, but my acl didn't work.
Any ideas of what can I do? or maybe my acl is incorrect, or I migh use something special on Cisco 6513 in order to make the acl work.
Thanks a lot for your answers!
P.D.: I must said that I tried the same scenario on my test access switch (Cisco 3560) and the acl work perfectly
When I add the mac acl on the interface where the RS is installed (on the 3560) I can't ping the RS from the network, just from the VM. In the other hand, when I put "no mac access-list" on the interface, the ping work perfectly from the network (and, of course, from the VM).
There's not other acl on the 3560 or some like that, I assume this happens because the mac acl views the bytes from ethernet and takes the mac when des-encapsulates the packet, that's why doesn't matter what kind of IP packet I send, I've never been able to reach RS beacuse of the mac acl.
How I said, it's the same scenario but in access layer
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...