I am preparing to implement a new network service in which the WAN and Internet traffic will be coming in on a single drop. This connection is connected to a Procurve 2915-8-PoE switch.
This switch is configured so that the Internet traffic goes to the firewall on one port and the WAN traffic on another. However, it appears that I can only apply the ACL to an interface port and not a VLAN. Because of the switch is still vulnerable to the outside. I disabled telnet and the web interface, but SSH access isn't enough protection. I thought about the management vlan, but I will need to be able to access the swtich from other locatoins.
If there any way I can block external users from being able to log into the switch while still allowing internal access?
#ACLs