NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Pete0302's avatar
Pete0302
Aspirant
Oct 26, 2018

Example ACL to block IGMP packets on Port

Hi

 

I'm having trouble setting up an ACL to block inbound IGMP traffic on port 7.

I can see others have had this problem in the past but no solutions were posted. Even if i deny all on port 7 the IGMP packets are still getting through. I'd really appreciate it if someone could help me with this, The packets getting trough are IGMP Src 0.0.0.0 and dest 224.0.0.1

2 Replies

  • Sorry should have mentioned, the switch in question is a M4300-8X8F


     


     

    • LaurentMa's avatar
      LaurentMa
      NETGEAR Expert

      Hi Pete0302

       

      Let me try to create these ACLs with you: 

       

      • Log into the M4300-8X8F CLI, enter the Enable mode then these commands:

      (M4300-8X8F) #config
      (M4300-8X8F) (Config)#access-list 101 deny ip any 224.0.0.1 0.255.255.0
      (M4300-8X8F) (Config)#access-list 101 permit ip any any
      (M4300-8X8F) (Config)#ip access-list Rule102
      (M4300-8X8F) (Config-ipv4-acl)#deny igmp any host 224.0.0.1
      (M4300-8X8F) (Config-ipv4-acl)#permit ip any any
      (M4300-8X8F) (Config-ipv4-acl)#exit

       

       

      • Apply the rules to inbound traffic on port 1/0/7: 

      (M4300-8X8F) (Config)#interface 1/0/7
      (M4300-8X8F) (Interface 1/0/7)#ip access-group 101 in 1
      (M4300-8X8F) (Interface 1/0/7)#ip access-group Rule102 in 2
      (M4300-8X8F) (Interface 1/0/7)#exit
      (M4300-8X8F) (Config)#exit

       

      Let us know how it goes!

      Regards,

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More