troubleshooting Question

Extended ACL or VLAN ACLs to permit\deny VLAN Traffic?

Avatar of GridLock137
GridLock137Flag for United States of America asked on
RoutersSwitches / Hubs
11 Comments1 Solution6399 ViewsLast Modified:
good day everyone,

I have some traffic I need to block on a catalyst 6509 layer 3 switch between two VLANs. I have dealt with standard and extended ACLs before but not to block specific VLANs from accessing each other. The concept of VALCs is new to me, so I need some help with this one... It's simple but it's racking my brain:

Let's say I have VLAN 20 and VLAN 66, I want traffic between these two VLANs to reach each other but drop all aother traffic from the other 15 or so VLANs I have confirgured on this switch, the catch is VLAN 20 is also Outbound traffic that cannot be blocked, for instance it runs internet traffic through there as well. Is there Any way I can accomplish this?

This is what I have tried so far by applying it on the VLAN Interface in the Out and In direction:


Applied to interface VLAN20 -
 
Access-list 150 permit ip 10.66.0.0 0.0.0.255 10.20.0.0 0.0.0.255
access-list 150 Permit ip any any

(allowing the invisible implicit deny at the bottom to block all else)

Applied to interface VLAN66-

Access-list 155 permit ip 10.20.0.0 0.0.0.255 10.66.0.0 0.0.0.255
permit ip any any

(allowing the invisible implicit deny at the bottom to block all else)

I have the ip any any there after my second try, when i applied on the permit ACL 150 & 155 i was blocked from reaching the WWW.

Any help on this would be deeply appreciated, thank you EE

GL137
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 11 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 11 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros