cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
877
Views
0
Helpful
2
Replies

Port-channel sub interfaces and acl's

mbellears
Level 1
Level 1

On our 7206VXR I have multiple Port-channel sub

interfaces...i.e ->

interface Port-channel1

no ip address

ip route-cache flow

duplex full

hold-queue 150 in

!

interface Port-channel1.10

description Upstream_ISP_1

encapsulation dot1Q 10

ip address xxx.xxx.xxx.xxx 255.255.255.252

!

interface Port-channel1.20

description Upstream_ISP_2

encapsulation dot1Q 20

ip address xxx.xxx.xxx.xxx 255.255.255.252

!

interface Port-channel1.100

description Colo_Customer_A

encapsulation dot1Q 100

ip address xxx.xxx.xxx.xxx 255.255.255.248

!

interface Port-channel1.700

description Fibre-Client_A

encapsulation dot1Q 700

ip address xxx.xxx.xxx.xxx 255.255.255.252

!

And these are only going to increase!

Is it possible to apply ACL's to individual Port-channel sub interfaces

?

I wanted to implement a generic deny ACL on all sub interfaces that

would deny things like netbios traffic, non-routable IP's, and

definitely telnet access to the router!

Any suggestions/Comments would greatly be appreciated!

Regards,

MB

2 Replies 2

beth-martin
Level 5
Level 5

I don’t have port-channel configured to test for you. Is it not taking the commands? If not, try submitting an enhancement request through Cisco.

Thanks for the reply.

Assigning an ACL to one of the port-channel's sub interfaces seems apply that ACL to all port-channels...which is definitely not what I want! ;)

Regards,

MB

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: