Posted on February 20, 2019 8:48 am
 |  Asked by Nilesh Bhadane
 |  112 views
0
0
Print Friendly, PDF & Email

Hi,

I want to drop/ discard packets(traffic) from a specific host on a particular physical interface on Arista device.

How to do it?

Thanks,
Nilesh

0
Posted by Yashwanth Veluri
Answered on February 20, 2019 8:56 am

Hello Nilesh,

This can be done using the deny rule in access-lists.

Please find more information regarding access-lists: https://www.arista.com/en/um-eos/eos-section-23-2-access-control-lists#ww1148961

0
Answered on February 20, 2019 8:59 am

Hi Nilesh,

You can configure an IP access list with a deny rule for the specific IP and apply it on the ingress physical interface.

For example:
To discard packets coming from host 10.1.1.1 on interface et 1:

Configure the access list:
ip access-list test
10 deny ip host 1.1.1.1 any
–> deny any packets with source IP 1.1.1.1
20 permit ip any any

Apply to the ingress interface et 1:
interface Ethernet1
ip access-group test in

This rule would now be applied only on interface et 1.

Post your Answer

You must be logged in to post an answer.