cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
262
Views
0
Helpful
1
Replies

Reflexive ACLs on SVIs

jason.henderson
Level 1
Level 1

I can configure a RACL on a physical interface, but it doesn't work on an SVI. Can anyone explain why it doesn't work?

1 Reply 1

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Jason,

I suppose you are using an ISR router with an etherswitch module.

the reflexive ACL is a "router" security feature and so it can be applied to a "router" interface.

Besides this, an SVI can receive traffic from L2 ports associated with the broadcast domain and from other L3 devices so it is a less clear context.

Hope to help

Giuseppe

Review Cisco Networking products for a $25 gift card