Link to home
Start Free TrialLog in
Avatar of Ian Taylor
Ian TaylorFlag for United Kingdom of Great Britain and Northern Ireland

asked on

Cisco ACL

Hello,

I need to implement an ACL to a VLAN and permit only two IP Address (VM's) to be able to access this vlan, how easy is this todo?

Switches are 3750X
Avatar of bamsi
bamsi
Flag of Philippines image

if its from a different VLAN coming to your VLAN interface the direction should be out

ip access-list extended ACCESS-LIST-NAME-OUT
 permit ip host x.x.x.x b.b.b.b c.c.c.c
 permit ip host y.y.y.y b.b.b.b c.c.c.c
!
interface Vlan10
 ip access-group ACCESS-LIST-NAME-OUT out

if you need to block traffic coming from inside the VLAN you just need to change the access group direction to in

ip access-list extended ACCESS-LIST-NAME-IN
 permit ip b.b.b.b c.c.c.c host x.x.x.x
 permit ip b.b.b.b c.c.c.c host y.y.y.y

interface Vlan10
 ip access-group ACCESS-LIST-NAME-IN in


x.x.x.x and y.y.y.y being your 2 IP
b.b.b.b c.c.c.c being your subnet and subnet mask
Avatar of Ian Taylor

ASKER

Thanks, so we are going to have to VM's in the same VLAN, would it be the IN or OUT CLI I use?
Hi - This is my Access-List I want to apply to the VLAN 7:

ip access-list extended svrmgmt
 deny   tcp any any fragments
 deny   udp any any fragments
 deny   icmp any any fragments
 deny   ip any any fragments
 permit udp any any eq bootps
 permit udp any any eq bootpc
 permit ip any 10.51.5.0 0.0.0.255
 permit ip any 10.51.10.0 0.0.0.255
 permit ip any 10.53.5.0 0.0.0.255
 permit ip any 10.53.10.0 0.0.0.255
 permit ip any host 10.51.10.115
 permit ip any host 10.51.10.116
 deny   ip any 10.51.0.0 0.0.255.255
 deny   ip any 10.53.0.0 0.0.255.255
 permit ip any any

The only devices (or hosts) we want access to VLAN7 are from VLAN10:

 permit ip any host 10.51.10.115
 permit ip any host 10.51.10.116

Does the ACL look correct?
Sorry, correction:

ip access-list extended svr-hvmgmt
 deny   tcp any any fragments
 deny   udp any any fragments
 deny   icmp any any fragments
 deny   ip any any fragments
 permit udp any any eq bootps
 permit udp any any eq bootpc
 permit ip any host 10.51.10.115
 permit ip any host 10.51.10.116
 deny   ip any 10.51.0.0 0.0.255.255
 deny   ip any 10.53.0.0 0.0.255.255
 permit ip any any
ASKER CERTIFIED SOLUTION
Avatar of Predrag Jovic
Predrag Jovic
Flag of Poland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
this really helped, thank u