Solved

Access-lists on Cisco 3550 switches

Posted on 2010-11-16
5
704 Views
Last Modified: 2012-08-13
Below is a digram of my network.  Right now all networks can talk to each other.  For example, if I am on a server in the 10.4.0.0 network, from there I can RDP into a server in the 10.5.0.0 network.  I need to create a access-list so these networks can't talk to each other.  I am using VTP, thats why all switches share a common VLAN.  Can someone provide me with an access-list example to accomplish this.  thanks.


Switch Diagram
0
Comment
Question by:denver218
  • 3
  • 2
5 Comments
 
LVL 24

Expert Comment

by:Ken Boone
ID: 34149012
So if you are on vlan 30 you do not want to get to vlan 40 or vlan 50?  Is that correct?  Should vlan 30 be allowed to get to the internet or any other networks?
0
 
LVL 4

Author Comment

by:denver218
ID: 34149161
Yes if I am on vlan 30, I don't want to see vlan 40 or 50.  I do want all network to have access to the internet.  Thanks.
0
 
LVL 4

Author Comment

by:denver218
ID: 34149268
I do have an Cisco ASA5510 on this network.  Should I just create an access-list on the inside for this on the ASA5510 instead of creating the access-list on switches?
0
 
LVL 24

Accepted Solution

by:
Ken Boone earned 500 total points
ID: 34149305

Here is the ACL for vlan 30 - this blocks access to vlan 40 and 50 and allows everything else.
ip access-list extended vlan30-acl
deny ip any 10.5.0.0 0.0.255.255
deny ip any 10.6.0.0 0.0.255.255
permit ip any any


Then on
interface vlan30
access-group vlan30-acl in


No you need to it on the switch instead of the asa.
0
 
LVL 4

Author Closing Comment

by:denver218
ID: 34149477
That worked.  Thanks
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DNS on-premise and on-cloud 15 119
New Aruba 2930f switches in lab.  Do they need to be configured to work? 21 105
Cisco iWAN 8 73
Problem to router 7 17
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now