kai zhang
asked on
established acl in cisco 3560
I use cisco3560
I want to vlan A access vlan B with tcp protocol, and vlan B could not access vlan A. vlan A and vlan B could access internet.
vlan A: 10.10.10.1/24 , vlan B: 10.10.20.1/24
ip access-list extend test
permit tcp any 10.10.20.0 0.0.0.255 established
permit ip any any
interface vlan A
ip access-group test out
interface vlan B
ip access-group test in
but it seemed not worked, both can access internet , and access each other,
it's my configuration problem ?
I want to vlan A access vlan B with tcp protocol, and vlan B could not access vlan A. vlan A and vlan B could access internet.
vlan A: 10.10.10.1/24 , vlan B: 10.10.20.1/24
ip access-list extend test
permit tcp any 10.10.20.0 0.0.0.255 established
permit ip any any
interface vlan A
ip access-group test out
interface vlan B
ip access-group test in
but it seemed not worked, both can access internet , and access each other,
it's my configuration problem ?
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
The solution is pretty clear and mr Atlas_shuddered confirm the same point.