simontibbitts Fri, 09/04/2009 - 06:34
User Badges:
  • Silver, 250 points or more


It is possible to do it on a switch. The only thing is it filters for all VLANs.

If you are looking to do it on a router then I have just tested in my lab and it works fine. Tested on 12.4(21) - works fine:

interface FastEthernet0/1

no ip address

duplex auto

speed auto


interface FastEthernet0/1.101

encapsulation dot1Q 101

ip address

ip access-group 101 in


access-list 101 deny tcp any any eq telnet

access-list 101 permit ip any any

Hope that helps



This Discussion