01-20-2014 05:35 AM - edited 03-07-2019 05:40 PM
Hi
I have 2 switches available to use, a 2960 or 2950. Ideally I wish to use the 2950 if possible.
What I want to achive is for a few ports to be limted to Internet only traffic, and dns lookups from a selected internal dns server. So when a machine is plugged into one of these ports the user cannot see any of the internal network.
The setup of the site I need this for prevents me from using multiple vlans as everyone must be on the same /27 subnet.
Can this be done on a 2950 or 2960?
Solved! Go to Solution.
01-20-2014 05:46 AM
You can use the 2950 but there are quite a few limitations in terms of how many entries you can have in the acl. However your acl could be very simple eg.
assuming your subnet was 192.168.5.0 255.255.255.224
access-list 101 permit udp host
access-list 101 deny ip host
access-list 101 permit ip host
then you apply it to the physical port -
int fa0/1
ip access-group 101 in
you should refer to this document for full details including all the restrictions/limitations -
Jon
01-20-2014 05:46 AM
You can use the 2950 but there are quite a few limitations in terms of how many entries you can have in the acl. However your acl could be very simple eg.
assuming your subnet was 192.168.5.0 255.255.255.224
access-list 101 permit udp host
access-list 101 deny ip host
access-list 101 permit ip host
then you apply it to the physical port -
int fa0/1
ip access-group 101 in
you should refer to this document for full details including all the restrictions/limitations -
Jon
01-20-2014 07:17 AM
Worked a treat, thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide