applying an access list to a switch - direction

Experts,

ON a Cisco switch I have:

Interface vlan 300
ip address 10.10.10.1 255.255.255.0

I have host 10.10.10.100

I want that host to be denied from reaching host 10.20.20.20.

access-list 100 deny ip host 10.10.10.100 host 10.20.20.20
access-list 100 permit ip any any


Question: When i go to apply acl 100 to the vlan, it would be applied OUT?
trojan81Asked:
Who is Participating?
 
Predrag JovicConnect With a Mentor Network EngineerCommented:
The way you wrote ACL on swith in should be in IN direction (in router engine inside switch from VLAN)

Interface vlan 300
ip access-group 300 in
0
 
Michael OrtegaSales & Systems EngineerCommented:
Can we assume these two hosts are on separate VLANs? Is this a layer 3 switch? Are you permitting inter-vlan communication directly on the switch?

MO
0
 
Pete LongConnect With a Mentor Technical ConsultantCommented:
^^ agree

but should it not be?

ip access-group 100 in

P
0
 
Predrag JovicNetwork EngineerCommented:
Yes, it should.
;)
0
 
Michael OrtegaSales & Systems EngineerCommented:
Author abandoned question. Solution provided by Pedrag appears to be the best.
0
All Courses

From novice to tech pro — start learning today.