03-02-2021 12:17 PM
Have a Cisco SG350-10 10 on 2.5.5.47
If you make ACL for IPv4 with last rule
Priority Action Logging Protocol IP Address Wildcard Mask IP Address Wildcard Mask
2147483647 Deny Disabled Any (IP) Any Any Any Any
and make a IPv4 rule with TCP port range 5129-5130 allow
then make a IPv6 ACL
Priority Action Logging Protocol IP Address IP Address Flow Label
1 Permit Disabled Any Any Any Any
Bind for GE2 input ACL your IPv4 and IPv6 rules it blocks port 5130.
09-11-2021 05:14 PM
I have a Cisco SG350X-24PD with firmware 2.5.5.47 and I have exactly the same issue.
IPv4 ACL:
Priority | Action | Logging | Time Range | Protocol | Source IP Address | Destination IP Address | Source Port | Destination Port | Flag Set | DSCP | IP Precedence | ICMP Type | ICMP Code | IGMP Type | |||
Name | State | IP Address | Wildcard Mask | IP Address | Wildcard Mask | ||||||||||||
... | … | ||||||||||||||||
8 | Permit | Disabled | TCP | Any | Any | Any | Any | Any | 50000-51000 |
binding that ACL to a port or VLAN will allow connect using the ports in that range
then create an IPv6 ACL:
Priority | Action | Logging | Time Range | Protocol | Source | Destination | Source Port | Destination Port | Flow Label | Flag Set | DSCP | IP Precedence | ICMP Type | ICMP Code | |||
Name | State | IP Address | Prefix | IP Address | Prefix | ||||||||||||
1 | Permit | Disabled | Any | Any | Any | Any |
binding both ACLs to the port or VLAN will block the ports in that range.
09-11-2021 05:43 PM
09-12-2021 06:18 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide