applying an access list to a switch - direction


ON a Cisco switch I have:

Interface vlan 300
ip address

I have host

I want that host to be denied from reaching host

access-list 100 deny ip host host
access-list 100 permit ip any any

Question: When i go to apply acl 100 to the vlan, it would be applied OUT?
Predrag JovicConnect With a Mentor Network EngineerCommented:
The way you wrote ACL on swith in should be in IN direction (in router engine inside switch from VLAN)

Interface vlan 300
ip access-group 300 in
Michael OrtegaSales & Systems EngineerCommented:
Can we assume these two hosts are on separate VLANs? Is this a layer 3 switch? Are you permitting inter-vlan communication directly on the switch?

Pete LongConnect With a Mentor Technical ConsultantCommented:
^^ agree

but should it not be?

ip access-group 100 in

Predrag JovicNetwork EngineerCommented:
Yes, it should.
Michael OrtegaSales & Systems EngineerCommented:
Author abandoned question. Solution provided by Pedrag appears to be the best.
