User guide

16-20 E
XTREME
W
ARE
S
OFTWARE
U
SER
G
UIDE
A
CCESS
P
OLICIES
Figure 16-7: RIP access policy example
Assuming the backbone VLAN interconnects all the routers in the company (and,
therefore, the Internet router does not have the best routes for other local subnets), the
commands to build the access policy for the switch would be the following:
create access-profile nointernet ipaddress
config access-profile nointernet mode deny
config access-profile nointernet add 10.0.0.10/32
config rip vlan backbone trusted-gateway nointernet
EW_001
Internet
Backbone (RIP)
SalesEngsvrs
Switch being
configured
10.0.0.10 / 24
10.0.0.11 / 24
10.1.1.1 / 24 10.2.1.1 / 24
10.0.0.12 / 24
Internet
Engsvrs Sales