A port-access role for AOS-CX switches has this policy applied to it:
plaintext
Copy code
port-access policy mypolicy
10 class ip zoneC action drop
20 class ip zoneA action drop
100 class ip zoneB
The classes have this configuration:
plaintext
Copy code
class ip zoneC
10 match tcp 10.2.0.0/16 eq https
class ip zoneA
10 match ip any 10.1.0.0/16
class ip zoneB
10 match ip any 10.0.0.0/8
The company wants to permit clients in this role to access 10.2.12.0/24 with HTTPS. What should you do?
Comprehensive Detailed Explanation
The requirement is to permit HTTPS traffic from clients to the 10.2.12.0/24 subnet.
ZoneC is configured to drop all HTTPS traffic to the 10.2.0.0/16 subnet. Therefore, the first match in the zoneC class (priority 10) will drop the desired traffic.
To override this behavior, you must add a higher-priority rule (lower rule number) to zoneC that explicitly matches 10.2.12.0/24 and permits the traffic.
Thus, adding the rule 5 match any 10.2.12.0/24 eq https to zoneC ensures the desired traffic is permitted while maintaining the drop behavior for the rest of 10.2.0.0/16.
Reference
AOS-CX Role-Based Access Control documentation.
Understanding class priority and policy rule ordering in AOS-CX.
Dominic
3 months agoHollis
3 months agoSuzi
3 months agoDenise
3 months agoKara
3 months agoVerda
4 months agoLettie
4 months agoKenda
4 months agoEmilio
4 months agoMillie
4 months agoChan
5 months agoRory
5 months agoNoah
5 months agoSherill
5 months agoEssie
11 months agoTerrilyn
11 months agoVal
11 months agoLemuel
9 months agoKristofer
9 months agoLai
9 months agoJosefa
9 months agoTamekia
9 months agoRaelene
10 months agoFannie
10 months agoBeckie
11 months agoEdda
11 months agoStephanie
11 months agoBo
11 months agoRaul
12 months agoVivienne
10 months agoPaz
11 months agoHerman
11 months agoTerrilyn
12 months ago