Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

applying an access list to a switch - direction

Posted on 2016-08-10
5
Medium Priority
?
33 Views
Last Modified: 2016-08-30
Experts,

ON a Cisco switch I have:

Interface vlan 300
ip address 10.10.10.1 255.255.255.0

I have host 10.10.10.100

I want that host to be denied from reaching host 10.20.20.20.

access-list 100 deny ip host 10.10.10.100 host 10.20.20.20
access-list 100 permit ip any any


Question: When i go to apply acl 100 to the vlan, it would be applied OUT?
0
Comment
Question by:trojan81
  • 2
  • 2
5 Comments
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 41751417
Can we assume these two hosts are on separate VLANs? Is this a layer 3 switch? Are you permitting inter-vlan communication directly on the switch?

MO
0
 
LVL 31

Accepted Solution

by:
Predrag earned 1000 total points (awarded by participants)
ID: 41751465
The way you wrote ACL on swith in should be in IN direction (in router engine inside switch from VLAN)

Interface vlan 300
ip access-group 300 in
0
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 1000 total points (awarded by participants)
ID: 41751809
^^ agree

but should it not be?

ip access-group 100 in

P
0
 
LVL 31

Expert Comment

by:Predrag
ID: 41751856
Yes, it should.
;)
0
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 41776022
Author abandoned question. Solution provided by Pedrag appears to be the best.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses
Course of the Month10 days, 13 hours left to enroll

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question