ACL between VLANs
Posted on 2003-10-30
I've got 4 VLANs. I got a 3350 Layer 3 switch.
My goal is to block icmp for VLAN 3.
I want to block all icmp traffic from going to VLAN 3 (nobody on VLAN 1,2 and 4 can ping VLAN 3).
I want to block all pcs in VLAN 3 from pinging each other).
I want my PC in VLAN 1, 10.50.20.2 to be able to ping the server 10.10.2.20 on VLAN 3 only.
Can you put the ACL, and how you would apply the ACL to the VLAN, with the in and out :)
How many ACL can I have with a VLAN? I notice that I can only one. I created the ACL, access-list 101 deny icmp any any. I applied this to VLAN 3. Then I created this ACL, access-list 101 permit icmp host 10.50.20.2 host 10.10.2.20. I applied to VLAN 3. I notice that only the last ACL is applied. Why is this?