Description:

Switches of the GS-3xxx series support Static Routing. In some scenarios the communication between the networks has to be prevented.

This article describes how the communication between networks can be prevented by using the Access Control List (ACL).


Requirements:


Scenario:


Procedure:

1) Open the webinterface of the device, go to the menu Access Control → Access Control List and click the "Plus icon"to create a new Access Control Entry (ACE).

 

2) Edit the following parameters and click Apply afterwards:

If needed you can also limit the communication from the source network to a specific port via the option Ingress Port.

3) Create a new entry and prohibit communication between the source network 20.20.20.0/24 (SIP Address and SIP Mask) to the destination network 10.10.10.0/24 (DIP Address and DIP Mask).

The communication is only prevented from source to destination network but not vice versa. Thus if the communication is to be prevented between two networks two entries have to be created.

4) Go to the menu Maintenance → Configuration → Save Startup-config, check the radio button startup-config and click Save Configuration to save the configuration as Startup Configuration.

After rebooting the switch the Startup Configuration will be loaded. If it doesn't exist, the default configuration will be loaded and the switch uses factory default settings.