Does Cat6 SUP720 support port acl?

Hi
We have a network using Cat4 and Cat6 for server connections.
We have decided to use acl on the l2 ports to block certain traffics.
It works fine on the cat4, but it does not work on cat6.
Is it a supported feature on cat6?
Thanks

Hey,
Are you using Cat OS or IOS on Sup 720?
I think on Cat OS you cannot use the ACL on L2 ports.
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_8_1/confg_gd/acc_list.htm#wp1020508
HTH,
-amit singh

Similar Messages

  • Does Verizon Wireless support Port forwarding.

    The 4510L has port forwarding. But the IP address ports are all stealth. I know VW has to take security measures for spam and hackers but this is just a little over kill here. The IP addresses they use are from wdspco.org. At lest in my area. Come on VW where is a tech support that are not sale reps. This feature should be part of the ISP service. It should not be an issue to allow simple port forwarding for the NOC. I know the public IP address is not routable. Its not going to cost more to route.

        We would love to support you with your Env3, jeffrey8066!
    What can we do to help?
    TamaraH_VZW
    Follow us on Twitter @VZWSupport

  • Run port ACL command from SCVMM

    I am trying to centrally manage all my port ACLs for VM net adapters from VMM but I am not able to run the command.
    I
    try to run the command from"Add-VMNetworkAdapterExtendedAcl"SCVMM
    PowerShell terminal:
    PS C:\Users\Administrator> Add-VMNetworkAdapterExtendedAcl -VMName "Web-VM1" -Action "allow" -Direction "Outbound"
    80 "TCP" -Weight 1 -Stateful $true
    And
    get the following:
    Add-VMNetworkAdapterExtendedAcl : The cmdlet cannot find a specified class. Verify that the relevant feature is
    enabled on the operating system.
    At line:1 char:1
    + Add-VMNetworkAdapterExtendedAcl -VMName "Web-VM1" -Action "allow" -Directio ...
    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo          : NotSpecified: (:) [Add-VMNetworkAdapterExtendedAcl], VirtualizationOperationFailedExcept
       ion
        + FullyQualifiedErrorId : Microsoft.HyperV.PowerShell.Commands.AddVMNetworkAdapterExtendedAclCommand
    Any ideas? Is there a similar command for SCVMM?
    SamG

    You are running a Hyper-V cmlet, not an SCVMM cmdlet.  Is the Hyper-V powershell module installed?
    as far as I know, SCVMM does not support port ACLs at this time.
    Brian Ehlert
    http://ITProctology.blogspot.com
    Learn. Apply. Repeat.
    Disclaimer: Attempting change is of your own free will.

  • Does the SLM224G switch support port-based VLAN's?

    I am looking for a simple solution to create two LAN's. One for my own and one for my customers, who will be able to use desktop PC's with internet access. I have only one internet connection (DSL over ISDN) and wil not getting another just for my customers.
    My own network should not be accessible or visible to users who are using the customers-PC's. The other way around is allowed, but not really necessary. My setup requires me to hook up the switch to the (ISP) router, and that router just has one LAN port not able to do anything related to VLAN's.
    I read about port-based VLAN's here, where it is stated that creating seperate LAN's is just putting ports into VLAN's on the switch, nothing else needs to be done... However, they used a NetGear smart switch.
    I checked out Cisco's SLM224G as it is affordable, has 24 ports (instead of 8 for the NetGear) and should support VLAN's. I have read a lot about VLAN's, including:
    "- Port-based VLAN's means that you can reconfigure ports to be in different VLAN's. Port-based VLAN's do not confirm 802.1q VLAN support.
    - 802.1q VLAN's means that you can tag VLAN's with 802.1q headers to create a trunk between two devices that carries frames for multiple VLAN's. 802.1q VLAN's confirm that there is also Port-based VLAN support."
    I known from the spec sheets that the SLM224G supports 802.1q (tagged) trunking. So it should, given found text above, also support port-based VLAN's.
    My question is whether it indeed will support port-based VLAN's?
    Am I able to use it directly behind my ISP's router and create two seperate LAN's?
    If so, one extra question: how are the PC's behind the switch (inside the two VLAN's) get their IP-adresses from the ISP-router? Or will it service only one of the two LAN's and should I install a DHCP-server in the other LAN?
    Any information is very welcome!
    Thank you.

    Thanks for your responce, mr. Carr.
    I have read more about vlan's and their setup. I think the article about port based vlan's was lacking some information about the router/firewall. May be it was set up to work with different vlan's from the start. Strangely, in the text it is said that nothing needs to be set up besides the (Netgear) vlan-capable switch.
    So, from your response and other texts I learned I needed a vlan-capable router. I have to say that I need to be able to manage a server on the LAN from the outside (internet). I already tried to set up a Cisco/Linksys WRT54G router behind the ISP's (ZyXel) single LAN-ported router and that would not work at all (even when the Linksys was set in router-mode). I lost the connection to internet setting it up that way. I even tried to setup the Linksys in the DMZ of the ZyXel, with no luck. I was unable to set that up with working internet-access form the LAN. So I was not too happy with the suggestion to set up a (second) vlan-capable gigabit router behind the ISP's router....
    Eventually, I bridged the ZyXel to get rid of the double NAT/gateway mode of the two routers as routing mode did not work on the Linksys. The Linksys is now getting the WAN-ip from the ISP on it's WAN port and I furthermore used DD-WRT's firmware to enable the build-in vlan-capabilities of the Linksys.
    Now I have set up the Linksys with two vlan's and I bought the SLM224G as an inexpensive manageable 24-port vlan-capable switch to provide the number of ports I needed. I devided the SLM in two vlan's and used two wires from the Linksys to the SLM. So the SLM does support port-based vlan's by simply setting up two ranges of ports with different PVID settings. Trunking and 802.1q tagging isn't needed that way. I know I could have used two dumb switches to get two separate subnetted networks, but this way I get just enough ports in a single device where I have ample space to put it.
    Anyway, thanks for helping me understanding the way vlan-capable switches work.

  • Does 760ga-p43 (fx) supports port multiplier for sata?

    1) I have a 760ga-p43 (fx) and I couldn`t find anywhere if it supports port multiplier for sata.
    Does someone have any idea?
    2) I tried a delock 70146 and I couldn`t make it see also the sata on motherboards and the sata on the pci card. For lack of information on that msi "user guide" I tried any combination on AHCI, ide and sata, but it was a blind trying. It would be great a little help on what to look for.
    Thanks,
    Radu

    what exactly do not works properly?
    list full system specifications, see >>Posting Guide<<

  • Does QPM 4.1 support Named ACLs

        Could any help with this, i downloaded a trial version of QPM and i am trying to import a QoS policy from our switches and its failing as the ACLs used for classification on the switches are Named ACLs. Does QPM support Named ACLs or not?

    A lot of it stems from the large and complex nature of the models we employ. Hardly a week goes by that we don't grind to a halt due to a bug in jpox. That then leeds to the thorny problem of trying to discuss the problem on the jpox forums, where there are basically only two members that know the product well enough to help... Net result, they are overwhelmed, and from one of them it comes across in the rudeness of replies. This puts people off, including us.
    I contrast this with the Hibernate and Spring communities, which I have personally been involved with and found to be both thriving and rewarding.
    A bit of QA and respecteful support will be wonderfull. We are happy to pay a company for that because of the man hours it saves. I sincerely hope that Kodo JDO works out for us.

  • Does adding tcp udp ports on the nat exempt accesslist which is binded to nat 0 statement remove the entire nat 0 statement itself?

    Hi Experts,
    Is the above statement true?. I learnt later that adding tcp and udp ports on the nat 0 statements are supported . But does it take away the entire nat statement? Please answer my question at the earliest.
    Regards
    Krishna

    Krishna,
    "NAT exemption (nat 0 access-list command)—NAT exemption allows both translated and remote hosts to initiate connections. Like identity NAT, you do not limit translation for a host on specific interfaces; you must use NAT exemption for connections through all interfaces. However, NAT exemption does enable you to specify the real and destination addresses when determining the real addresses to translate (similar to policy NAT), so you have greater control using NAT exemption. However unlike policy NAT, NAT exemption does not consider the ports in the access list. NAT exemption also does not support connection settings, such as maximum TCP connections."
    Reference
    So, since the documentation clearly says that this rule does not consider any ports in the ACL, then one should not be testing unsupported configurations.
    If one adds an ACL with specific ports, then unexpected results may be expected.
    My suggestion, dont add any ACL entry with specific ports to your NAT exempt statement.
    Thanks.
    Portu.
    Please rate any helpful posts

  • While configuring speed 1000 i am getting error as sw2-storage-vdc(config-if)# speed 1000 ERROR: Ethernet2/6: Configuration does not match the port capability.

    storage-vdc(config-if)# show module
    Mod  Ports  Module-Type                         Model              Status
    2    32     1/10 Gbps Ethernet Module           N7K-F132XP-15      ok
    sw1-gd78(config-if)# sh module
    Mod  Ports  Module-Type                         Model              Status
    2    48     1/2/4/8 Gbps FC Module              DS-X9248-96K9      ok
    4    8      10 Gbps FCoE Module                 DS-X9708-K9        ok
    7    0      Supervisor/Fabric-2a                DS-X9530-SF2AK9    active *
    8    0      Supervisor/Fabric-2a                DS-X9530-SF2AK9    ha-standby
    10   22     4x1GE IPS, 18x1/2/4Gbps FC Module   DS-X9304-18K9      ok
    Mod  Sw              Hw      World-Wide-Name(s) (WWN)
    2    5.2(2)          1.1     20:41:00:0d:ec:fb:8a:00 to 20:70:00:0d:ec:fb:8a:00
    4    5.2(2)          0.107   --
    7    5.2(2)          1.8     --
    8    5.2(2)          1.8     --
    10   5.2(2)          1.3     22:41:00:0d:ec:fb:8a:00 to 22:52:00:0d:ec:fb:8a:00
    sw1-gd78(config-if)# sh run int ethernet4/6
    !Command: show running-config interface Ethernet4/6
    !Time: Mon Feb 20 22:56:12 2012
    version 5.2(2)
    interface Ethernet4/6
      no shutdown
    sw1-gd78(config-if)# no shut
    sw1-gd78(config-if)# speed 1000
    ERROR: Ethernet4/6: Configuration does not match the port capability.
    sw1-gd72# sh int ethernet4/6 capabilities
    Ethernet4/6
      Model:                 DS-X9708-K9
      Type (SFP capable):    10Gbase-SR
      Speed:                 1000,10000
      Duplex:                full
      Trunk encap. type:     802.1Q
      Channel:               yes
      Broadcast suppression: percentage(0-100)
      Flowcontrol:           rx-(off/on/desired),tx-(off/on/desired)
      Rate mode:             dedicated
      QOS scheduling:        rx-(2q4t),tx-(1p3q4t)
      CoS rewrite:           yes
      ToS rewrite:           yes
      SPAN:                  yes
      UDLD:                  yes
      Link Debounce:         yes
      Link Debounce Time:    yes
      MDIX:                  no
      Port Group Members:    none
      TDR capable:           no
      FabricPath capable:    yes
      Port mode:             Switched
    sw1-gd72# sh int ethernet4/6 transceiver details
    Ethernet4/6
        transceiver is present
        type is 10Gbase-SR
        name is CISCO-FINISAR
        part number is FTLX8571D3BCL-CS
        revision is C
        serial number is FNS12090EMJ
        nominal bitrate is 10300 MBit/sec
        Link length supported for 50/125um OM2 fiber is 82 m
        Link length supported for 50/125um OM3 fiber is 300 m
        Link length supported for 62.5/125um fiber is 26 m
        cisco id is --
        cisco extended id number is 4
               SFP Detail Diagnostics Information (internal calibration)
                                         Alarms                  Warnings
                                    High        Low         High          Low
      Temperature   36.21 C        75.00 C     -5.00 C     70.00 C        0.00 C
      Voltage        3.29 V         3.63 V      2.97 V      3.46 V        3.13 V
      Current        8.11 mA       11.80 mA     4.00 mA    10.80 mA       5.00 mA
      Tx Power       -2.65 dBm       1.49 dBm  -11.30 dBm   -1.50 dBm     -7.30 dBm
      Rx Power       -2.21 dBm       1.99 dBm  -13.97 dBm   -1.00 dBm     -9.91 dBm
      Transmit Fault Count = 0
      Note: ++  high-alarm; +  high-warning; --  low-alarm; -  low-warning

    Ankit,
    You are trying to set speed 1000 on a 10g sfp.
    type is 10Gbase-SR
    You will need to insert a 1gig sfp and then you will be able to set the speed.
    Also, I noticed that you posted first with interface 2/6 and the output you gave me was for 4/6. Are you sure you're in the right interface?

  • Does oracle10g is supported by XML editor XML Spy??

    All:
    I have installed XMLSpy 2004 R3 professional edition and trying to Connect Oracle XML DB.
    But I am getting error that "Invalid userId or Password".
    I am trying to connect to:
    Oracle Database 10g Enterprise Edition Release 10.1.0.2.0 - Production
    With the Partitioning, OLAP and Data Mining options
    Does XML Spy supports Oracle 10g? if so which version?
    ANd Plz let me know the steps to Connect..
    I appreciate your help and Thanks in Advance.....
    Srikanth

    You first create a special user for XML DB in this case xml_dev with password masterkey:
    CREATE USER xml_dev IDENTIFIED BY masterkey
    TEMPORARY TABLESPACE temp
    DEFAULT TABLESPACE users;
    GRANT connect, resource, dba, xdbadmin TO xml_dev;
    CONN xml_dev/masterkey@LOR;
    Create some repository folders:
    DECLARE
    v_return BOOLEAN;
    BEGIN
    v_return := dbms_xdb.createFolder('/home/DEV/');
    v_return := dbms_xdb.createFolder('/home/DEV/xsd/');
    v_return := dbms_xdb.createFolder('/home/DEV/lom/');
    COMMIT;
    END;
    Then connect with http or WebDav with port 8080 (maybe what you are missing) :
    http://<server>:8080/home/DEV/xsd/
    In XML Spy just put the URL user and password, in this case:
    http://<server>:8080/home/DEV/xsd/
    User: xml_dev
    Pass: masterkey
    Varify that you have the http server (apache) running on the server.

  • Port-ACL's on a 3750 - question

    I have a 3750 that is connected to another network via a layer-2 type connection. I have a specific set of tcp and udp ports that I want to allow access to via this switch. In taking a look at the documentation I see that I can apply Port ACL's directly to layer-2 interfaces, but that it will only work "inbound" to the switch.
    Will this work:
    If I have (bad ascii net diagram):
    [hosta]--[rtr]--[switcha]-WAN-[switchb]
    I want to put an ACL on the l2 uplink from switchB to the wan (WAN is a metro-ethernet type l2 wan extension - rtr is a router) that only allows hosta to hit tcp ports 1000,2000 and 3000 on hosts sitting on switchb. I want to allow hosts on switchb to do whatever they want to hosta. Is it as simple as:
    ip access-list 101 permit tcp any any eq 1000
    ip access-list 101 permit tcp any any eq 2000
    ip access-list 101 permit tcp any any eq 3000
    and then applying that ACL onto the l2 uplink interface on switchb? Thinking that since Port ACL's only affect "inbound" direction - allowing inbound connections on the l2 uplink gets the packets onto my hosts on switchb, and there is nothing preventing the return traffic or new tcp connections from hosts on switchb -> hosta...?
    Thanks!
    -Frank

    Yes frank, Your idea seems to be okei.
    As per document, You can configure only one type of per-user ACLs on a Catalyst 3750 switch port: router ACLs or port ACLs. Router ACLs apply to Layer 3 interfaces, and port ACLs apply to Layer 2 interfaces. If a port is configured with a port-based ACL, the switch rejects any attempt to configure a router-based ACL on the same port. However, if a port is configured with a router-based ACL and then a port-based ACL, the port-based ACL overwrites the router ACL.
    while applying to the interface connecting to l2 port give "in" direction, but anyway out is not supported in l2 interfaces.
    so nothing looks preventig the return traffic.

  • Does Stratus/RTMFP support P2P behind the same NAT/Router?

    Does Stratus/RTMFP support peers behind the same NAT/Router?
    (such that both peers have the same public IP address)
    That is: if two computers (each running Flash) are behind the same NAT, and connect to Stratus to get peerID;
    do we expect they can connect p2p?
    Or will each one get/see just the public IP address:port of the other?
    My initial tests indicate that this scenario fails [ICMP Destination Unreachable (port unreachable)]
    Is this just a limitation of my local router? does this work for others?
    Does Status expect the local router to detect/decode/resolve this situation?
    If the solution requires 10.1 groups, is there support to detect/diagnose when/if the peer is on the same LAN?

    Thanks for the info, sounds like RTMFP supports this, and hopefully the AFP code does the right thing.
    [so, officially, the original question is answered]
    Note: In one instance, i'm running two browsers on the same host,
    so even the inner/LAN addresses would be the same. Therefore, if A sends to B's inner/LAN address,
    the [Windows] OS network layer *should* recognize that and 'hairpin' without leaving the host, or crossing the firewall.
    (I say "should" because Unix generally does that, but I'll have to check to see about Windoze).
    [And such packets are probably invisible to Wireshark also, so how do i verify what's happening?
    oh sure, just reconfigure to boot Linux... ]
    So glad you explained that the client tries all three pathways; if it works as you say,
    then I can probably ignore the ICMP error from the local router (or, as you say, teach it to do the hairpin).
    Can you confirm that P2P will work between browsers (say Chrome to Firefox) on a single Windows host?
    [I really want to know if I'm failing because of network configuration or application code/error;
    at this point, I am able to correctly exchange the peerIds, and start the NetSteam.play,
    but the two sides do not appear to be exchanging audio/video]

  • Does Palm Pre Support Bluetooth SPP Profile?

    I am a developer for a software company.  I write all the application software mainly for Windows Mobile to control our hardware in the field using Bluetooth SPP Profile, or Serial Port over Bluetooth.  Some clients have asked if they can use their Palm Pre phones to control our hardware.  
    Does Palm Pre support SPP?
    Post relates to: Palm IIIc

    At this itme the PRE does not support the SPP profile.
    These are the profiles currently enabled on the PRE;
    HSP 1.1, HFP 1.5, PBA, A2DP, AVRC, PAN
    version 2.1+EDR
    For reference purposes, click on the following link for the support page for your device on the kb.palm.com webpage.
    http://kb.palm.com/wps/portal/kb/na/pre/p100eww/sprint/home/page_en.html
    There are links on the page to the user guide, troubleshooting, how to's, downloads, etc.

  • Does ISR 2801 support PLAR?

    as I said in the title, does ISR 2801 support PLAR? i want to connect 2 IP phone directy to 2 FXO ports on VIC in 2801, using the connection plar opx command for each FXO port. is this possible? (i tried that on test 2621 router, and it works fine)

    ok, but that doesn't answer my question. I've been told that 2801 does not support PLAR, but other 2800 series routers do (2801 will have that ability in the future IOS releases).
    Once again, does 2801 support "connection plar opx" command?
    thank you

  • Does the Airport support Airprint

    Does the Airport support Airprint?
    I have severa IOS Devices and wuld like to use an existing Printer (HP USB) from these devices.
    Would it be possible to access this Printer via Airprint if i Buy an Airport Extreme and connect the Printer to the USB Port?

    Sorry, but just connecting a non-AirPrint printer to the USB port of an AirPort base station will not make it AirPrint capable. Yes there are a number of Apps available to print from iOS devices.

  • HT201269 Hi I want to back up my photos from my iPhone 5. How can I do this? I have an iPad mini but cannot sync to an iPhone as iPad does not have USB port. Can you help please x

    Hi I want to back up my photos from my iPhone 5. How can I do this? I have an iPad mini but cannot sync to an iPhone as iPad does not have USB port. Can you help please

    You have to back them up to a computer. You would import them either to iPhoto or to the Photos app in your PC:
    http://support.apple.com/kb/ht4083
    Cheers,
    GB

Maybe you are looking for

  • Can I use a VGA to Mini DVI adapter for a LCD monitor for a macbook??

    Hello! First off, I love this site. Secondly, I have a macbook 10.6.6 and a LCD moniter with a VGA input. I see on the apple site there is the "Mini DisplayPort to VGA Adapter" and "Apple Mini DVI to VGA Adapter". both seem compatible but I want to p

  • Cover Flow View - NOT working

    Hello, I have a problem with the cover flow view on iTunes. I don't know when this when happened but it was there before I updated to iTunes 10. This is how it looks: http://www.kwisvragen.com/itunesproblem/coverflowitunes.tiff It's only under Music,

  • Mask a particular column - very urgent

    Hi Team, I am using Oracle 10g, But i have only schema level access. How to mask the sensitive data in Columns like Salary Name,Bank account can be updated with a different values...like XXXX ?. Thanks in Advance Regards FEnto

  • How to call BAPI_TRANSACTION_COMMIT for more than one bapi?

    Hi all, i have this web dynpro app, which needs to call multiple bapis. if i import like this: bapi1_model bapi2_model bapi_transaction_commit_model and execute them like this: bapi1 commit bapi2 commit data wont get write to database. how to import

  • How do i delete a screen saver?

    i just downloaded a screen saver a few weeks ago, but then decided i didn't want it i went into my library and then in the screen saver folder, and deleted it when i went back in system preferences, it was still there, and it still works it was a 10