All of those items are already done. Here is a copy of what I have in my iptables. I don't see anything, do you?
Code:
Chain INPUT (policy ACCEPT 607K packets, 68M bytes)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:1C:26:64:12:61
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MAC 60:33:4B:1D:12:08
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:16:CB:B8:10:D8
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 MAC 70:1A:04:4E:55:B7
850 74376 ACCEPT tcp -- * * 10.10.50.102 0.0.0.0/0 tcp dpt:56565
0 0 ACCEPT tcp -- * * 10.10.50.102 0.0.0.0/0 tcp dpt:22
0 0 ACCEPT tcp -- * * 10.10.50.102 0.0.0.0/0 tcp dpt:80
0 0 ACCEPT tcp -- * * 10.10.50.101 0.0.0.0/0 tcp dpt:80
31 1512 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:56565
4327 173K DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
Chain FORWARD (policy DROP 1557K packets, 135M bytes)
pkts bytes target prot opt in out source destination
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:1C:26:64:12:61
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 34:15:9E:76:53:BD
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:1E:C2:B4:AA:83
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:1C:B3:B7:DF:D9
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:23:14:17:5D:70
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:13:02:B6:8D:06
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:26:BB:05:1A:77
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:25:D3:E6:79:33
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 60:33:4B:1D:12:08
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 60:33:4B:1D:12:08
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 MAC 00:26:08:E9:E5:78
158K 97M ACCEPT 47 -- * * 0.0.0.0/0 0.0.0.0/0
14M 12G ACCEPT all -- eth0 eth1 0.0.0.0/0 0.0.0.0/0
12M 2831M ACCEPT all -- eth1 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan26 eth1 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth1 vlan26 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan26 eth5 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth5 vlan26 0.0.0.0/0 0.0.0.0/0
128K 22M ACCEPT all -- vlan172 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan172 eth2 0.0.0.0/0 0.0.0.0/0
172K 163M ACCEPT all -- eth0 vlan172 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth2 vlan172 0.0.0.0/0 0.0.0.0/0
589K 83M ACCEPT all -- vlan199 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan199 eth2 0.0.0.0/0 0.0.0.0/0
908K 972M ACCEPT all -- eth0 vlan199 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth2 vlan199 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan26 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan26 eth2 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth0 vlan26 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth2 vlan26 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan5 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan5 eth2 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth0 vlan5 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth2 vlan5 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan5 eth1 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth1 vlan5 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan173 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan173 eth2 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth0 vlan173 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth2 vlan173 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan201 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan201 eth2 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth0 vlan201 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth2 vlan201 0.0.0.0/0 0.0.0.0/0
23M 4775M ACCEPT all -- vlan202 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan202 eth2 0.0.0.0/0 0.0.0.0/0
31M 34G ACCEPT all -- eth0 vlan202 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth2 vlan202 0.0.0.0/0 0.0.0.0/0
212K 20M ACCEPT all -- vlan205 eth0 0.0.0.0/0 0.0.0.0/0
282K 323M ACCEPT all -- eth0 vlan205 0.0.0.0/0 0.0.0.0/0
280K 126M ACCEPT all -- vlan206 eth0 0.0.0.0/0 0.0.0.0/0
283K 216M ACCEPT all -- eth0 vlan206 0.0.0.0/0 0.0.0.0/0
28610 3600K ACCEPT all -- eth3 eth1 10.10.200.0/24 10.10.15.20
0 0 ACCEPT all -- eth1 eth3 10.10.15.20 10.10.200.0/24
1285 748K ACCEPT all -- eth3 eth1 10.10.200.0/24 10.10.50.102
0 0 ACCEPT all -- eth1 eth3 10.10.50.102 10.10.200.0/24
0 0 ACCEPT all -- eth3 eth1 10.10.200.0/24 10.10.50.104
0 0 ACCEPT all -- eth1 eth3 10.10.50.104 10.10.200.0/24
0 0 ACCEPT all -- eth3 eth1 10.10.200.0/24 10.10.50.65
0 0 ACCEPT all -- eth1 eth3 10.10.50.65 10.10.200.0/24
0 0 ACCEPT all -- eth3 eth1 10.10.200.0/24 10.10.15.21
0 0 ACCEPT all -- eth1 eth3 10.10.15.21 10.10.200.0/24
0 0 ACCEPT all -- eth3 eth1 10.10.201.0/24 10.10.0.0/16
0 0 ACCEPT all -- eth1 eth3 10.10.0.0/16 10.10.201.0/24
0 0 ACCEPT all -- eth3 eth1 10.10.200.0/24 10.10.109.0/24
0 0 ACCEPT all -- eth1 eth3 10.10.109.0/24 10.10.200.0/24
0 0 ACCEPT all -- eth3 eth1 10.10.109.0/24 10.10.50.102
0 0 ACCEPT all -- eth1 eth3 10.10.50.102 10.10.109.0/24
0 0 ACCEPT all -- eth3 eth1 10.10.109.0/24 10.10.15.0/24
0 0 ACCEPT all -- eth1 eth3 10.10.15.0/24 10.10.109.0/24
0 0 ACCEPT all -- vlan50 eth0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth0 vlan50 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- vlan50 eth1 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- eth1 vlan50 0.0.0.0/0 0.0.0.0/0
I am not new to this, I have been working with this type of network for 10 years. I have never run in to an issue like this before.
So to clarify, we have a Ubuntu server, our switches are configured correctly, on the Ubuntu server we are utilizing vlans. vlan5 cannot talk to vlan202.
Bookmarks