Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

per port ACL on 2950

Hi,

port based ACL is possible on 2950? i mean my requirement as follows on a vlan having diff. network segment, switches are vlan 5, servers vlan 6, clients vlan 7, pc vlan 8,they interconnect each other, layer 3 - 3750, layer 2 - 2950, on one of the switch port fas 0/1 a pc is connected ip address 192.168.1.1/24, only a pc having 192.168.1.1/24 connected on this port can access other pc/server on the network, if the pc ip address is been changed to 192.168.1.2 ,it should not reach other pc/server, i think it is possibile with the following

switch configuration

interface fastethernet 0/1

switchport access vlan 8

switchport mode access

ip access-group 101 in

spanning-tree portfast

interface gigabitethernet 0/1

description ***connected to 3750***

switchport mode trunk

interface vlan 5

ip address 10.1.1.2 255.255.255.0

ip default-gateway 10.1.1.254

access-list 101 permit ip host 192.168.1.1 0.0.0.255 any.

am i right? if not correct.

note: in 3750 vlan is configured, i don't wanted to put any access-list on this,as i wanted a port based access-list on the edge switches only, only then it will satisfy my need.

  • Other Network Infrastructure Subjects
5 REPLIES
Bronze

Re: per port ACL on 2950

Hi anand,

your access list statement

access-list 101 permit ip host 192.168.1.1 0.0.0.255 any

will permit entire 192.168.1.x network with your wild card mask 0.0.0.255

i think you need to change it to

access-list 101 permit ip 192.168.1.1 0.0.0.0 any

or

access-list 101 permit ip host192.168.1.1 any

other config is fine it should work fine.

HTH

Thanks

Raj

Re: per port ACL on 2950

Hi,

If I'm correct, then Switch 2950 is a L-2 switch and doesnt understand anything beyod L-2. Hence I really doubt implementation of a L-3 Access-List on any Physical Port of the 2950 Switch.

Kind Regards,

Wilson Samuel

PS: Please rate if it helps.

Re: per port ACL on 2950

Hi Ananad,

Please let us know the model number of the switch 2950. 2950 switch with EMI (enhanced image) we can set the ACLs.

Following switches are the Enhanced image 2950 swicthes (Catalyst 2950G-48, 2950G-24, 2950G-24-DC, 2950T-24, 2950C-24, 2950G-12.

Please refer the link below:

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12122ea7/scg/swacl.htm#wp1043920

HTH, Please rate if it does.

-amit singh

Re: per port ACL on 2950

Hi Amit,

Thanks for pasting this link.

I'm now updated with the latest developments in the 2950 Series switches.

Kind Regards.

Wilson Samuel

Re: per port ACL on 2950

THankz for the reply,

my 2950 is EMI.

700
Views
0
Helpful
5
Replies
This widget could not be displayed.