<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help Configuring VLan for Internet Only Traffic in Switching</title>
    <link>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277856#M264868</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;ip access-list extended TO-The-Net&lt;/P&gt;&lt;P&gt;deny ip &lt;SPAN style="font-size: 10pt;"&gt;172.18.20.0 0.0.3.255&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;172.16.2.0 0.0.1.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;deny ip 172.18.20.0 0.0.3.255&amp;nbsp; 172.16.4.0 0.0.1.255&lt;/P&gt;&lt;P&gt;deny ip 172.18.20.0 0.0.3.255&amp;nbsp; 172.16.6.0 0.0.0.255&lt;/P&gt;&lt;P&gt;deny ip 172.18.20.0 0.0.3.255&amp;nbsp; 172.16.10.0 0.0.0.255&lt;/P&gt;&lt;P&gt;permit ip &lt;SPAN style="font-size: 10pt;"&gt;172.18.20.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;0 0.0.3.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This acl , applyed in ingress to the SVI, should meet your needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Carlo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate all helpful posts &lt;BR /&gt; &lt;BR /&gt;"The more you help the more you learn"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Sep 2013 14:25:32 GMT</pubDate>
    <dc:creator>Carlo Poggiarelli</dc:creator>
    <dc:date>2013-09-30T14:25:32Z</dc:date>
    <item>
      <title>Help Configuring VLan for Internet Only Traffic</title>
      <link>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277853#M264865</link>
      <description>&lt;P&gt;I have a Cisco Catalyst 3750 Switch with a 2500 series Wireless Controller. I have multiple vlans, and 3 wireless networks. I have created a new vlan and wireless network, both work just like the other vlans and wireless. The problem is when I try to apply ACLs to limit traffic to internet only neither will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subnets I don’t what access to:&lt;/P&gt;&lt;P&gt;172.16.2.0/23&lt;/P&gt;&lt;P&gt;172.16.4.0/23&lt;/P&gt;&lt;P&gt;172.16.6.0/24&lt;/P&gt;&lt;P&gt;10.10.10.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Subnet to go to Internet:&lt;/P&gt;&lt;P&gt;172.18.20. 0/22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goals are these:&lt;/P&gt;&lt;P&gt;1. Limit the new subnet to Internet only access&lt;/P&gt;&lt;P&gt;2. Be able to receive DHCP addresses on new subnet&lt;/P&gt;&lt;P&gt;3. DNS is optional as I have external DNS servers in the DHCP options&lt;/P&gt;&lt;P&gt;4. Be able to use wired or wireless on new subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 23:43:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277853#M264865</guid>
      <dc:creator>jhiggins2001</dc:creator>
      <dc:date>2019-03-07T23:43:07Z</dc:date>
    </item>
    <item>
      <title>Help Configuring VLan for Internet Only Traffic</title>
      <link>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277854#M264866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Write an ACL with a source of 172.18.20.0/22 that does the following in this order:&lt;/P&gt;&lt;P&gt;Permits DHCP to specific DHCP server(s)&lt;/P&gt;&lt;P&gt;Deny IP to the subnets that you want to protect&lt;/P&gt;&lt;P&gt;Permit internet traffic (www,https,dns at a minimum) to anywhere&lt;/P&gt;&lt;P&gt;Apply ACL to the SVI for 172.18.20.0/22&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Sep 2013 18:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277854#M264866</guid>
      <dc:creator>rfalconer.sffcu</dc:creator>
      <dc:date>2013-09-27T18:48:06Z</dc:date>
    </item>
    <item>
      <title>Help Configuring VLan for Internet Only Traffic</title>
      <link>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277855#M264867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Robert, Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK, I tried doing as you said, but I still can'e get an IP when I have ACL applied. What should my Permit DHCP statement look like? I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 120 permit udp host 10.10.10.5 any eq bootpc&lt;/P&gt;&lt;P&gt;access-list 120 permit udp host 10.10.10.5 any eq bootps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where 10.10.10.5 is my DHCP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I have deny statements on the rest of my subnets followed by Permit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 120 permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 14:05:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277855#M264867</guid>
      <dc:creator>jhiggins2001</dc:creator>
      <dc:date>2013-09-30T14:05:03Z</dc:date>
    </item>
    <item>
      <title>Help Configuring VLan for Internet Only Traffic</title>
      <link>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277856#M264868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;ip access-list extended TO-The-Net&lt;/P&gt;&lt;P&gt;deny ip &lt;SPAN style="font-size: 10pt;"&gt;172.18.20.0 0.0.3.255&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;172.16.2.0 0.0.1.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;deny ip 172.18.20.0 0.0.3.255&amp;nbsp; 172.16.4.0 0.0.1.255&lt;/P&gt;&lt;P&gt;deny ip 172.18.20.0 0.0.3.255&amp;nbsp; 172.16.6.0 0.0.0.255&lt;/P&gt;&lt;P&gt;deny ip 172.18.20.0 0.0.3.255&amp;nbsp; 172.16.10.0 0.0.0.255&lt;/P&gt;&lt;P&gt;permit ip &lt;SPAN style="font-size: 10pt;"&gt;172.18.20.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;0 0.0.3.255 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This acl , applyed in ingress to the SVI, should meet your needs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Carlo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate all helpful posts &lt;BR /&gt; &lt;BR /&gt;"The more you help the more you learn"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 14:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277856#M264868</guid>
      <dc:creator>Carlo Poggiarelli</dc:creator>
      <dc:date>2013-09-30T14:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Help Configuring VLan for Internet Only Traffic</title>
      <link>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277857#M264869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have the source and destination flipped for DHCP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 120 permit udp any host 10.10.10.5 eq bootpc&lt;/P&gt;&lt;P&gt;access-list 120 permit udp any host 10.10.10.5 eq bootps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, as the last line of the ACL, you can add the line:&lt;/P&gt;&lt;P&gt;deny ip any any log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will create a log of traffic that doesn't hit one of the rules. It can be helpful in diagnosing issues with ACLs. You don't need to leave it there permanently. I typically will add it only if/when there are issues with traffic hitting an element in the ACL. You'll need to remove the permit any any to make this work. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 15:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277857#M264869</guid>
      <dc:creator>rfalconer.sffcu</dc:creator>
      <dc:date>2013-09-30T15:07:23Z</dc:date>
    </item>
    <item>
      <title>Help Configuring VLan for Internet Only Traffic</title>
      <link>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277858#M264870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That did the trick. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to Carlo as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 16:51:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/help-configuring-vlan-for-internet-only-traffic/m-p/2277858#M264870</guid>
      <dc:creator>jhiggins2001</dc:creator>
      <dc:date>2013-09-30T16:51:08Z</dc:date>
    </item>
  </channel>
</rss>

