vlan access lists

Unanswered Question
Feb 23rd, 2007

Hi all, with a vlan when I add an access list, how do I know which is in and out when applying it ?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (2 ratings)
Loading.
Danilo Dy Fri, 02/23/2007 - 03:15

I think vlan interface in L3 switch logically represents the physical interface that is a member of the configured vlan. Therefore the following;

interface vlan100

ip access-group 100 in

is ingress to all physical interface which is configured with vlan100

interface vlan100

ip access-group 101 out

is egress to all physical interface which is configured with vlan100

but wait for experts to reply :)

rakmenon Fri, 02/23/2007 - 05:57

As mentioned the following are correct.

interface vlan1

ip access-group 1 in (indicates in)

interface vlan1

ip access-group 11 out (indicates out)

The case is different if its a VACL in that case the map is applied as soon as the frame reaches the switch(not the SVI).

let me know if this helps,if not pls clarify more on the question,

Rakesh

Actions

This Discussion