<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL Adding a access-group to a interface not selectable ?? in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45408#M3292</link>
    <description>&lt;P&gt;Hello,&amp;nbsp; I believe this to be a CLI command line bug.&lt;/P&gt;&lt;P&gt;I have done this before successfully but can't remember how you do this&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;ip access-list extended 100&lt;BR /&gt;remark Block_CapWap&lt;BR /&gt;sequence 10 deny udp any any eq 5246&lt;BR /&gt;sequence 20 deny udp any any eq 5247&lt;BR /&gt;sequence 30 permit ip any any&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;BUT!&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try and add it to the Inf it doesn't add it but drops me into building the ACL&lt;/P&gt;&lt;P&gt;See:&lt;/P&gt;&lt;P&gt;(config)#interface ethernet 2/1/3&lt;/P&gt;&lt;P&gt;config-if-e1000-2/1/3)#ip access-list extended Block_CapWap&lt;BR /&gt;SW(config-ext-nacl)#&lt;/P&gt;&lt;P&gt;****Here you can see it applied to a working interface.***&lt;/P&gt;&lt;P&gt;ip access-list extended 100&lt;BR /&gt;remark Block_CapWap&lt;BR /&gt;sequence 10 deny udp any any eq 5246&lt;BR /&gt;sequence 20 deny udp any any eq 5247&lt;BR /&gt;sequence 30 permit ip any any&lt;/P&gt;&lt;P&gt;Show Int e 1/1/23&lt;/P&gt;&lt;P&gt;interface ethernet 1/1/23&lt;BR /&gt;port-name WiFi CGP_Ticket_EX~&lt;BR /&gt;loop-detection&lt;BR /&gt;dual-mode 750&lt;BR /&gt;ip access-group Block_CapWap in&lt;BR /&gt;spanning-tree 802-1w admin-edge-port&lt;BR /&gt;inline power power-by-class 4&lt;BR /&gt;stp-bpdu-guard&lt;BR /&gt;trust dscp&lt;BR /&gt;sflow forwarding&lt;BR /&gt;sflow sample 4096&lt;BR /&gt;snmp-server enable traps mac-notification&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;JM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jun 2022 18:31:10 GMT</pubDate>
    <dc:creator>JayWM</dc:creator>
    <dc:date>2022-06-29T18:31:10Z</dc:date>
    <item>
      <title>ACL Adding a access-group to a interface not selectable ??</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45408#M3292</link>
      <description>&lt;P&gt;Hello,&amp;nbsp; I believe this to be a CLI command line bug.&lt;/P&gt;&lt;P&gt;I have done this before successfully but can't remember how you do this&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;ip access-list extended 100&lt;BR /&gt;remark Block_CapWap&lt;BR /&gt;sequence 10 deny udp any any eq 5246&lt;BR /&gt;sequence 20 deny udp any any eq 5247&lt;BR /&gt;sequence 30 permit ip any any&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;BUT!&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I try and add it to the Inf it doesn't add it but drops me into building the ACL&lt;/P&gt;&lt;P&gt;See:&lt;/P&gt;&lt;P&gt;(config)#interface ethernet 2/1/3&lt;/P&gt;&lt;P&gt;config-if-e1000-2/1/3)#ip access-list extended Block_CapWap&lt;BR /&gt;SW(config-ext-nacl)#&lt;/P&gt;&lt;P&gt;****Here you can see it applied to a working interface.***&lt;/P&gt;&lt;P&gt;ip access-list extended 100&lt;BR /&gt;remark Block_CapWap&lt;BR /&gt;sequence 10 deny udp any any eq 5246&lt;BR /&gt;sequence 20 deny udp any any eq 5247&lt;BR /&gt;sequence 30 permit ip any any&lt;/P&gt;&lt;P&gt;Show Int e 1/1/23&lt;/P&gt;&lt;P&gt;interface ethernet 1/1/23&lt;BR /&gt;port-name WiFi CGP_Ticket_EX~&lt;BR /&gt;loop-detection&lt;BR /&gt;dual-mode 750&lt;BR /&gt;ip access-group Block_CapWap in&lt;BR /&gt;spanning-tree 802-1w admin-edge-port&lt;BR /&gt;inline power power-by-class 4&lt;BR /&gt;stp-bpdu-guard&lt;BR /&gt;trust dscp&lt;BR /&gt;sflow forwarding&lt;BR /&gt;sflow sample 4096&lt;BR /&gt;snmp-server enable traps mac-notification&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;JM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 18:31:10 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45408#M3292</guid>
      <dc:creator>JayWM</dc:creator>
      <dc:date>2022-06-29T18:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: ACL Adding a access-group to a interface not selectable ??</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45410#M3293</link>
      <description>&lt;P&gt;Hmm now I haven't used ACL on a Ruckus switch, but what strikes me is that when you see the, then it is a access group that have been applied on the interface, so maybe it is like Cisco, where you create an access list, but apply it as an access group ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 20:06:06 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45410#M3293</guid>
      <dc:creator>Xfeldt</dc:creator>
      <dc:date>2022-06-29T20:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACL Adding a access-group to a interface not selectable ??</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45429#M3294</link>
      <description>&lt;P&gt;Yep, that’s the answer. You can see it in the config. If in doubt, try using Cisco commands - most vendors ape them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 16:14:21 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45429#M3294</guid>
      <dc:creator>Squozen</dc:creator>
      <dc:date>2022-06-30T16:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACL Adding a access-group to a interface not selectable ??</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45522#M3311</link>
      <description>&lt;P&gt;Hey all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We do also use the ip access-group command to apply ACLs. Here's an example from our Security guide:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BenBeck_0-1657299631465.png" style="width: 723px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2840i0DA4157F94C2CA61/image-dimensions/723x317?v=v2" width="723" height="317" role="button" title="BenBeck_0-1657299631465.png" alt="BenBeck_0-1657299631465.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Some additional references:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.commscope.com/bundle/fastiron-08090-securityguide/page/GUID-1B76BE6F-8F28-43DB-A59E-2A36DA553539.html" target="_blank"&gt;https://docs.commscope.com/bundle/fastiron-08090-securityguide/page/GUID-1B76BE6F-8F28-43DB-A59E-2A36DA553539.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.commscope.com/bundle/fastiron-08090-securityguide/page/GUID-6BD70996-ADEB-4B59-A701-F52072F2C90C.html" target="_blank"&gt;https://docs.commscope.com/bundle/fastiron-08090-securityguide/page/GUID-6BD70996-ADEB-4B59-A701-F52072F2C90C.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 17:03:34 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ACL-Adding-a-access-group-to-a-interface-not-selectable/m-p/45522#M3311</guid>
      <dc:creator>BenBeck</dc:creator>
      <dc:date>2022-07-08T17:03:34Z</dc:date>
    </item>
  </channel>
</rss>

