<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Server to Server access list in the same vlan in Switching</title>
    <link>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018884#M374406</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you help me to implement a server to server access list in the same VLAN. Can you give me a sample configuration?&amp;nbsp;Please find attached file for sample network design&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sample server-server access list in the same VLAN&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #1&amp;nbsp;IP Address&amp;nbsp;192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #2 IP Address&amp;nbsp;192.168.1.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #3 IP Address 192.168.1.3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #4 IP Address&amp;nbsp;192.168.1.4&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;This access-list sample how to config in the same VLAN.&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;scenario:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;1.) Server #1 can access Server #2 then denied Server #3 &amp;amp; Server #4&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;2.) Server #2 can access Server #3 then denied Server #1 &amp;amp; Server #4&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;3.) Server #3 can access Server #1 and Server #2 then denied Server #4&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;3.) Server #4 denied access to Server #1 and Server #2 and Server #3&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Thanks in advance.&amp;nbsp;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Mar 2019 17:53:56 GMT</pubDate>
    <dc:creator>kupsroach182</dc:creator>
    <dc:date>2019-03-08T17:53:56Z</dc:date>
    <item>
      <title>Server to Server access list in the same vlan</title>
      <link>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018884#M374406</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you help me to implement a server to server access list in the same VLAN. Can you give me a sample configuration?&amp;nbsp;Please find attached file for sample network design&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sample server-server access list in the same VLAN&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #1&amp;nbsp;IP Address&amp;nbsp;192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #2 IP Address&amp;nbsp;192.168.1.2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #3 IP Address 192.168.1.3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server #4 IP Address&amp;nbsp;192.168.1.4&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;This access-list sample how to config in the same VLAN.&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;scenario:&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;1.) Server #1 can access Server #2 then denied Server #3 &amp;amp; Server #4&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;2.) Server #2 can access Server #3 then denied Server #1 &amp;amp; Server #4&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;3.) Server #3 can access Server #1 and Server #2 then denied Server #4&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;3.) Server #4 denied access to Server #1 and Server #2 and Server #3&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Thanks in advance.&amp;nbsp;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 17:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018884#M374406</guid>
      <dc:creator>kupsroach182</dc:creator>
      <dc:date>2019-03-08T17:53:56Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018885#M374407</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;you should use a mac acl in same vlan , resolve the ips to there macs and block and permit them that way&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://bizzard2000.wordpress.com/2012/04/05/mac-access-list-extended/&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_acl/configuration/xe-3s/asr903/sec-data-acl-xe-3s-asr903-book/mac-access-control-lists.html#concept_A0793814F55647FBAE4B3A3E67E10DBB&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;mac access-list extended example&lt;/P&gt;
&lt;P&gt;permit host 0042.68fc.fc20 host 0042.68fc.fc21&lt;/P&gt;
&lt;P&gt;permit host 0042.68fc.fc21 host 0042.68fc.fc20&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 08:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018885#M374407</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2017-03-24T08:47:06Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018886#M374408</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you, i will try it to my test environment. I got also follow up question is mac access-list can define port control also like eq www, eq 21 or eq &lt;G class="gr_ gr_343 gr-alert gr_spell gr_run_anim gr_inline_cards ContextualSpelling ins-del multiReplace" id="343" data-gr-id="343"&gt;icmp&lt;/G&gt;? and the last thing where do I put the mac extended access-list?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;a. ) mac access-list extended &lt;G class="gr_ gr_465 gr-alert gr_gramm gr_run_anim gr_inline_cards Grammar only-ins doubleReplace replaceWithoutSep" id="465" data-gr-id="465"&gt;example&lt;/G&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;permit host 0042.68fc.fc20 host 0042.68fc.fc21 eq icmp&lt;/P&gt;
&lt;P&gt;permit host 0042.68fc.fc21 host 0042.68fc.fc20&amp;nbsp;&lt;SPAN&gt;eq&amp;nbsp;8080&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;b. )&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;interface Vlan2&lt;BR /&gt;description *** Server Farm ***&lt;BR /&gt;ip address 192.168.1.200 255.255.255.0&lt;BR /&gt;ip access-group &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;"mac access-list extended example"&lt;/STRONG&gt;&lt;/SPAN&gt; in&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;is this correct?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 09:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018886#M374408</guid>
      <dc:creator>kupsroach182</dc:creator>
      <dc:date>2017-03-24T09:13:15Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018887#M374409</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;no it would be like the doc example below , you can apply it to layer 2 port or layer 3 if your device supports it , there is also VACLs as another option&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You don't get the same eq options in macls as ip acls&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/15-0SY/configuration/guide/15_0_sy_swcg/vlan_acls.html#pgfId-1148259&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;switch#configure terminal&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;switch(config)#mac access-list extended cisco&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch(config-ext-macl)#permit host 0011.&lt;SPAN class="skimlinks-unlinked"&gt;abcd.abcd&lt;/SPAN&gt; host 0011.1111.1111&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch(config-ext-macl)#exit&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch(config)#access-list 101 deny ip 10.10.1.0 0.0.0.255 host 10.10.2.2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch(config)#access-list 101 permit ip any any&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch(config)#interface f0/23&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch(config-if)#switchport mode trunk&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch(config-if)#ip access-group 101 in&lt;/EM&gt;&lt;BR /&gt;&lt;SPAN style="color: rgb(255, 0, 0);"&gt;&lt;STRONG&gt;&lt;EM&gt;switch(config-if)#mac access-group cisco in&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;EM&gt;switch(config-if)#end&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch#show access-lists&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;switch#show access-group interface f0/23&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 09:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/server-to-server-access-list-in-the-same-vlan/m-p/3018887#M374409</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2017-03-24T09:34:41Z</dc:date>
    </item>
  </channel>
</rss>

