Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Reg: ACLs

HI Experts,

In my lab setup i configured Cisco 3560 switch.

VLAN 20 and VLAN 30 i configured.

VLAN 20 interface IP :

VLAN 30 interface IP :

Inter-vlan communication is happening fine.

For testing for purpose i configured extended ACLs.

Here is my requirement:

i want stop communication from VLAN 30 to VLAN 20 but not vice-versa.

Here i configured like this:

access-list 111 deny ip

access-list 111 permit ip any any

applied ACL in VLAN 30 interface 'in' direction.

ip access-group 111 in

In this scenario, communication is stopping in both directions.

If i ping from one of the IP VLAN 20 to one of the ip of VLAN 30, i was gettng Requested time out. And if i ping from one of the IP VLAN 20 to VLAN 30 interface IP, i was able get pinging.

From VLAN 30 to VLAN 20, i was getting destination host unreachable from VLAN 30 ip( Its fine as its my requirement)

So, solution needed to communicate from VLAN 20 to VLAN 30.




Reg: ACLs


What if you do a reflexive ACL on the .20 vlan.

ip access-list extended test

permit ip reflect test-123

ip access-list extended inbound-packets

  evaluate test-123

interface fastethernet 0/1.20

ip access-group test out

ip access-group inbound-packets in

Please let me know the result of this.



Looking for some Networking Assistance? Contact me directly at I will fix your problem ASAP. Cheers, Julio Carvajal Segura