Get the App
SLTechnology News&Howtos  ›  Network Security  › 

How to configure ACG as a layer 2 transparent device

Shulou Source: shulou.com Published: 2022-06-01 05:23:20 10月04日 Update

1. User requirements

In order not to change the existing network topology environment, users intend to transparently deploy ACG devices layer 2 into the network environment.

2. Topological environment

3. Configuration ideas

ACG configuration idea: create a bridge interface and put the uplink and uplink physical interfaces into the bridge interface (bridge interface address can be configured or not)

ACG configuration steps:

Open ACG through a browser (default is based on https), and click the "Interface" option as follows:

Click the Network Interface option on the right-> Click New.

Start a number under "name", put the left ACG connection up and down interface into the bridge interface, and click "submit" as shown in the following figure:

Explanation: the reason why ping test is checked here is to facilitate testing (in ACG, you can also ping, in the menu "system Management"-> "system maintenance",-> "system Diagnostic tools"-> ping)

The submitted configuration is shown in the following figure:

Finally, on the menu "Internet behavior Management"-> "Policy configuration"-> "IPv4 Policy", create a policy that allows all traffic, as shown in the following figure:

S5500A configuration

[S5500A] int vlan 1

[S5500A-Vlan-interface1] ip add 192.168.1.1 24

[S5500A-Vlan-interface1]

[S5500A-Vlan-interface1] quit

S5500B configuration

[S5500B] int vlan 1

[S5500B-Vlan-interface1] ip add 192.168.1.2 24

Ping Test:

[S5500A] ping 192.168.1.2

PING 192.168.1.2: 56 data bytes, press CTRL_C to break

Reply from 192.168.1.2: bytes=56 Sequence=1 ttl=255 time=45 ms

Reply from 192.168.1.2: bytes=56 Sequence=2 ttl=255 time=30 ms

Reply from 192.168.1.2: bytes=56 Sequence=3 ttl=255 time=30 ms

Reply from 192.168.1.2: bytes=56 Sequence=4 ttl=255 time=30 ms

Reply from 192.168.1.2: bytes=56 Sequence=5 ttl=255 time=15 ms

-192.168.1.2 ping statistics-

5 packet (s) transmitted

5 packet (s) received

0.005% packet loss

Round-trip min/avg/max = 15-30-45 ms

4. Points for attention

The ipv4 policy in ACG needs to be opened, otherwise it will not be able to ping.

Tags: Configuration interface policy environment system test up and down ideas topology user network menu bridge management layer 2 device but not event reason right Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn MySQL Microsoft Huawei Shulou Technology