[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

ACL question

Posted on 2003-10-28
2
Medium Priority
?
202 Views
Last Modified: 2011-08-18
Hi guys,

Whats the differnce between ip access-group 101 in and ip access-group 101 out?

Cheers,
Blue Print
0
Comment
Question by:blueprint123
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 13

Accepted Solution

by:
td_miles earned 150 total points
ID: 9638766
"in" applies the access list to traffic "entering" the interface from an external source
"out" applies the access list to traffic leaving the interface from your router

as an example, if you have the access list:

access-list 101 permit ip w.x.y.z any
access-list 101 deny ip any any

==========
you could then apply this:
interface ethernet0
  ip access-group 101 in

which would permit any traffic from the device w.x.y.z that is connected to the ethernet0 interface (eg. via a switch) to enter the ethernet0 interface of the router. All other traffic would be denied.
==========
if you applied it:
interface ethernet0
  ip access-group 101 out

it would allow any traffic that was from the device w.x.y.z to LEAVE the ethernet0 interface. This traffic would have to be either generated locally by the router, or have entered the router from another interface and have been routed to ethernet0.
==========

In summary, think of the "in" and "out" in relation to the viewpoint of that router interface and an external device. If the external device is sending traffic to the router, then the traffic is "inbound". If the router is sending traffic to the other device, then the traffic is "outbound".

0
 
LVL 7

Expert Comment

by:NicBrey
ID: 9639932
Just to add to td_miles comment:
Outgoing  ACL's  do not apply to traffic generated by the router itself. So, if you deny outgoing ICMP for example, you would still be able tto ping from the router console.
0

Featured Post

[Webinar] Lessons on Recovering from Petya

Skyport is working hard to help customers recover from recent attacks, like the Petya worm. This work has brought to light some important lessons. New malware attacks like this can take down your entire environment. Learn from others mistakes on how to prevent Petya like worms.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question