<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICX 7850 egress ACL not supported with untagged vlans? in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7850-egress-ACL-not-supported-with-untagged-vlans/m-p/30354#M1607</link>
    <description>&lt;P style="margin: 0;"&gt;I do not have a definitive answer for you, but it seems like some kind of technical limitation on initial support for ICX7850. I can see that note in 8090 and 8092 documentation. 8095 has a pretty large re-write from an ACL standpoint and I do not see that limitation mentioned in 8095 documentation. ACLs will generally be applied at the vlan level starting from 8095 forward. It may be worth giving 8095d a shot for this specific use case.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jun 2021 20:36:50 GMT</pubDate>
    <dc:creator>BenBeck</dc:creator>
    <dc:date>2021-06-21T20:36:50Z</dc:date>
    <item>
      <title>ICX 7850 egress ACL not supported with untagged vlans?</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7850-egress-ACL-not-supported-with-untagged-vlans/m-p/30353#M1606</link>
      <description>&lt;P style="margin: 0;"&gt;Can anyone explain why this is the case?&amp;nbsp; From the 08.0.92e documentation:&amp;nbsp;&lt;/P&gt; 
&lt;BLOCKQUOTE&gt; 
 &lt;P style="margin: 0;"&gt;On ICX 7850 devices only, configuration of egress ACLs is blocked on any virtual interface with an associated VLAN that contains an untagged port.&lt;/P&gt; 
&lt;/BLOCKQUOTE&gt; 
&lt;P style="margin: 0;"&gt;And sure enough, when I try:&lt;/P&gt; 
&lt;BLOCKQUOTE&gt; 
 &lt;P style="margin: 0;"&gt;(config-vif-1234)# ip access-group acl-name out&lt;BR /&gt;Error: Egress ACL on VE is not supported when vlan has untagged ports&lt;/P&gt; 
&lt;/BLOCKQUOTE&gt; 
&lt;P style="margin: 0;"&gt;It works fine on all other models we have (7450, 7650, 7750) as this is a normal thing for us.&amp;nbsp; Why not here?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 20:23:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7850-egress-ACL-not-supported-with-untagged-vlans/m-p/30353#M1606</guid>
      <dc:creator>howardtopher</dc:creator>
      <dc:date>2021-06-21T20:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7850 egress ACL not supported with untagged vlans?</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7850-egress-ACL-not-supported-with-untagged-vlans/m-p/30354#M1607</link>
      <description>&lt;P style="margin: 0;"&gt;I do not have a definitive answer for you, but it seems like some kind of technical limitation on initial support for ICX7850. I can see that note in 8090 and 8092 documentation. 8095 has a pretty large re-write from an ACL standpoint and I do not see that limitation mentioned in 8095 documentation. ACLs will generally be applied at the vlan level starting from 8095 forward. It may be worth giving 8095d a shot for this specific use case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 20:36:50 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7850-egress-ACL-not-supported-with-untagged-vlans/m-p/30354#M1607</guid>
      <dc:creator>BenBeck</dc:creator>
      <dc:date>2021-06-21T20:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7850 egress ACL not supported with untagged vlans?</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7850-egress-ACL-not-supported-with-untagged-vlans/m-p/30355#M1608</link>
      <description>&lt;P style="margin: 0;"&gt;Thanks for this.&amp;nbsp; We try to run the same version of code everywhere so we're on 8092e on around 900 switches right now.&amp;nbsp; However, this case is a new install and doesn't have production traffic on it yet so I just installed 8095d.&amp;nbsp; You're correct that the ACL is now in the vlan and not the router interface, but it accepted the "out" direction ACL.&amp;nbsp; Once I get a server connected to the switch I'll be able to test it, but looks good so far.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 21:10:02 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7850-egress-ACL-not-supported-with-untagged-vlans/m-p/30355#M1608</guid>
      <dc:creator>howardtopher</dc:creator>
      <dc:date>2021-06-21T21:10:02Z</dc:date>
    </item>
  </channel>
</rss>

