cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
382
Views
5
Helpful
3
Replies

ACL on Vlan interface

pwallace
Level 1
Level 1

I am trying to apply an acl on my vlan interfaces that would allow the vlan to initiate tcp traffic. When I apply it I am unable to surf the web from the vlan but I can tftp from the vlan .

3 Replies 3

Harold Ritter
Cisco Employee
Cisco Employee

This is normal behavior. The first packet coming from the station on the VLAN would not be considered as established.

On the other hand, the established keyword could be configured on an outbound ACL applied to the same VLAN. This would only allow TCP traffic initiated from the VLAN to reenter that same VLAN.

Hope this helps,

Harold Ritter
Sr Technical Leader
CCIE 4168 (R&S, SP)
harold@cisco.com
México móvil: +52 1 55 8312 4915
Cisco México
Paseo de la Reforma 222
Piso 19
Cuauhtémoc, Juárez
Ciudad de México, 06600
México

Got it! Thanks! this pointed me in the right direction and I was able to ge the acl like I wanted thanks!

pwallace,

Please help the NetPro community by rating Harold's extrememly helpful post.

Thanks. :)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: