02-23-2007 02:30 AM - edited 03-05-2019 02:32 PM
Hi all, with a vlan when I add an access list, how do I know which is in and out when applying it ?
02-23-2007 03:15 AM
I think vlan interface in L3 switch logically represents the physical interface that is a member of the configured vlan. Therefore the following;
interface vlan100
ip access-group 100 in
is ingress to all physical interface which is configured with vlan100
interface vlan100
ip access-group 101 out
is egress to all physical interface which is configured with vlan100
but wait for experts to reply :)
02-23-2007 05:41 AM
^^ I'm no expert, but you are correct.
02-23-2007 05:57 AM
As mentioned the following are correct.
interface vlan1
ip access-group 1 in (indicates in)
interface vlan1
ip access-group 11 out (indicates out)
The case is different if its a VACL in that case the map is applied as soon as the frame reaches the switch(not the SVI).
let me know if this helps,if not pls clarify more on the question,
Rakesh
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: