11-20-2006 05:19 AM - edited 03-05-2019 12:55 PM
I need to apply access list to an interface Vlan10 saying the
We dont want this netork a.a.a.a coming on to our network.
SO I have access-list 8 deny a.a.a.a
access-list 8 permit any
and on the Vlan Interface 10
Interface Vlan 10
ip access-group 8 out
Is this correct?
Please help.
I also do not wanto to be able to ping a network b.b.b.b
On the VLAn 11
Do I have access-list 12 deny b.b.b.b
access-list 12 permit any
Interface Vlan 11
ip access-group 12 in
Is this correct?
How can I write it ok.
11-20-2006 06:54 AM
If you are doing L3, you can simply add a route for this network to a null0 device.
ip route a.a.a.a 255.255.0.0 null0
For ACL, use inward ACLs on your interfaces closest to the entry point for that network.
Thanks.
11-20-2006 08:20 AM
Thanks. What does null0 do?.
My main issue is the OUT/IN position. Yes Vlan10 and Vlan11 are the nesrest vlan to these networks.
11-20-2006 08:25 AM
Hi friend,
Null0 is a imaginary interface which does not exist. Routes forwarded to Null0 are thus dropped.
This is often referred to as "Black Hole Routing"
HTH, rate if it does
Narayan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide