Solved

Access-lists on Cisco 3550 switches

Posted on 2010-11-16
5
709 Views
Last Modified: 2012-08-13
Below is a digram of my network.  Right now all networks can talk to each other.  For example, if I am on a server in the 10.4.0.0 network, from there I can RDP into a server in the 10.5.0.0 network.  I need to create a access-list so these networks can't talk to each other.  I am using VTP, thats why all switches share a common VLAN.  Can someone provide me with an access-list example to accomplish this.  thanks.


Switch Diagram
0
Comment
Question by:denver218
  • 3
  • 2
5 Comments
 
LVL 24

Expert Comment

by:Ken Boone
ID: 34149012
So if you are on vlan 30 you do not want to get to vlan 40 or vlan 50?  Is that correct?  Should vlan 30 be allowed to get to the internet or any other networks?
0
 
LVL 4

Author Comment

by:denver218
ID: 34149161
Yes if I am on vlan 30, I don't want to see vlan 40 or 50.  I do want all network to have access to the internet.  Thanks.
0
 
LVL 4

Author Comment

by:denver218
ID: 34149268
I do have an Cisco ASA5510 on this network.  Should I just create an access-list on the inside for this on the ASA5510 instead of creating the access-list on switches?
0
 
LVL 24

Accepted Solution

by:
Ken Boone earned 500 total points
ID: 34149305

Here is the ACL for vlan 30 - this blocks access to vlan 40 and 50 and allows everything else.
ip access-list extended vlan30-acl
deny ip any 10.5.0.0 0.0.255.255
deny ip any 10.6.0.0 0.0.255.255
permit ip any any


Then on
interface vlan30
access-group vlan30-acl in


No you need to it on the switch instead of the asa.
0
 
LVL 4

Author Closing Comment

by:denver218
ID: 34149477
That worked.  Thanks
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to choose hardware firewall 5 45
extend vlan through a layer 3 connection 31 148
clear arp 1 30
VLAN Overused monitor 4 17
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question