<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VLAN Interface IP protection - Opened Ports in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675407#M1092959</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Q1) How can I block ports such as 443 on the VLAN x interface IP?&lt;/P&gt;&lt;P&gt;1) I tried ACL on the Inbound &amp;amp; Outbound of the VLAN x but it does not work.&lt;/P&gt;&lt;P&gt;2) Physical router (who hosts the VLAN X interface IP) has been configured to allow port 443 BUT on the different VLAN the management VLAN. This allowed port 443 on the physical router management is used for the web management not for VLAN x.&lt;/P&gt;&lt;P&gt;Any advice, please&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Aug 2022 14:37:47 GMT</pubDate>
    <dc:creator>Serpent2010</dc:creator>
    <dc:date>2022-08-25T14:37:47Z</dc:date>
    <item>
      <title>VLAN Interface IP protection - Opened Ports</title>
      <link>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675407#M1092959</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Q1) How can I block ports such as 443 on the VLAN x interface IP?&lt;/P&gt;&lt;P&gt;1) I tried ACL on the Inbound &amp;amp; Outbound of the VLAN x but it does not work.&lt;/P&gt;&lt;P&gt;2) Physical router (who hosts the VLAN X interface IP) has been configured to allow port 443 BUT on the different VLAN the management VLAN. This allowed port 443 on the physical router management is used for the web management not for VLAN x.&lt;/P&gt;&lt;P&gt;Any advice, please&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 14:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675407#M1092959</guid>
      <dc:creator>Serpent2010</dc:creator>
      <dc:date>2022-08-25T14:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Interface IP protection - Opened Ports</title>
      <link>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675413#M1092960</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/309008"&gt;@Serpent2010&lt;/a&gt; define an ACL permitting/denying the relevant traffic then assign that ACL to the http server - "ip http access-class ACL-NAME" that should restrict http/https server traffic on the device.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 14:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675413#M1092960</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-08-25T14:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Interface IP protection - Opened Ports</title>
      <link>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675420#M1092961</link>
      <description>&lt;P&gt;Thanks for the quick reply, and that's working for the physical box http/https config but it does not work for the interface VLAN X IP.&lt;/P&gt;&lt;P&gt;In other words, the ACL will work perfectly for the management VLAN but it does not work for the VLAN x&lt;/P&gt;&lt;P&gt;I can redo the test to double check, if you want me to do that&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 14:51:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675420#M1092961</guid>
      <dc:creator>Serpent2010</dc:creator>
      <dc:date>2022-08-25T14:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Interface IP protection - Opened Ports</title>
      <link>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675446#M1092966</link>
      <description>&lt;P&gt;If the traffic is direct to VLAN then ACL not work, the ACL work for traffic pass through VLAN SVI no traffic direct to VLAN SVI.&lt;BR /&gt;you need CoPP OR&amp;nbsp;&lt;BR /&gt;check the ip route, see the traffic come from and apply ACL IN in the next-hop not in VLAN SVI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 15:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675446#M1092966</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-08-25T15:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Interface IP protection - Opened Ports</title>
      <link>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675465#M1092967</link>
      <description>&lt;P&gt;You are correct and I will work on your suggestion, it is very interesting,&amp;nbsp; to see if it will work as expected.&lt;/P&gt;&lt;P&gt;Many thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 16:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675465#M1092967</guid>
      <dc:creator>Serpent2010</dc:creator>
      <dc:date>2022-08-25T16:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN Interface IP protection - Opened Ports</title>
      <link>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675472#M1092968</link>
      <description>&lt;P&gt;You are so so welcome&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2022 16:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-interface-ip-protection-opened-ports/m-p/4675472#M1092968</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-08-25T16:31:26Z</dc:date>
    </item>
  </channel>
</rss>

