cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
284
Views
0
Helpful
2
Replies

Access Group In or Out

stalljoseph
Level 1
Level 1

Please give a down and dirty again on access-lists on VLAN interfaces on a 6500 core. Say I have VLAN 10, and want to apply an ACL on it, when would I apply an IN and when would I use the OUT.

Thanks,

2 Replies 2

bjw
Level 4
Level 4

I just went through this. The IN is used on an SVI (Vlan), IN or OUT are used on physical interfaces.

I am not sure why an SVI would be different from a physical interface. And I am not sure why out would not also be used on SVI interfaces.

Joe

Basically the in and out of access-group is from the perspective of the router/layer3 switch. So to examine packets from end stations on the interface/subnet you apply access-group in. And to examine packets going to end stations on the interface/subnet you apply the access-group out.

HTH

Rick

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card