<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: couple access list questions to seperate vlans subnet in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3823861#M547861</link>
    <description>1.) On each vlan which I only want them to be able to access to the server and dmz vlans but not other client vlan... on the vlan interface, shoudl I use access group IN...or OUT? Without asking here...I may pick IN... If I am wrong.. may you tell me why?&lt;BR /&gt;&lt;BR /&gt;You should configure your SVI acls both IN and OUT. Think of IN meaning coming into the interface from the local subnet &amp;amp; OUT as external subnets coming into that subnet.&lt;BR /&gt;&lt;BR /&gt;2.) For the access-list...&lt;BR /&gt;There are several ways you can accomplish this. You could use object groups to achieve what you want here. I think you will need to create separate acls as you mentioned above. You could potentially look into using Trustsec if you have ISE in your environment.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 21 Mar 2019 16:57:24 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2019-03-21T16:57:24Z</dc:date>
    <item>
      <title>couple access list questions to seperate vlans subnet</title>
      <link>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3823764#M547860</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;Hope you can help!! Currently there are over 30 vlans running on our core switch 4507. They all can see and access to each other. But now my boss wants me to seperate the vlans so each vlan cannot access to other client vlans but certainly it should still be able to access the server vlan and dmz vlan and internet. I am planning to just use access control list to achieve the goal.&lt;/P&gt;
&lt;P&gt;My server vlan is 10.10.0.0/23&lt;/P&gt;
&lt;P&gt;DMZ1 is 172.20.0.0/24&lt;/P&gt;
&lt;P&gt;DMZ2 is 10.1.22.0/24&lt;/P&gt;
&lt;P&gt;My client vlans are:&lt;/P&gt;
&lt;P&gt;10.10.16.0/23&lt;/P&gt;
&lt;P&gt;10.10.32.0/23&lt;/P&gt;
&lt;P&gt;10.10.48.0/23&lt;/P&gt;
&lt;P&gt;... up to 10.10.192.0/23&lt;/P&gt;
&lt;P&gt;　&lt;/P&gt;
&lt;P&gt;Here are something I want to ask:&lt;/P&gt;
&lt;P&gt;1.) On each vlan which I only want them to be able to access to the server and dmz vlans but not other client vlan... on the vlan interface, shoudl I use access group IN...or OUT? Without asking here...I may pick IN... If I am wrong.. may you tell me why?&lt;/P&gt;
&lt;P&gt;2.) For the access-list... if I do the way like this...&lt;/P&gt;
&lt;P&gt;#################################&lt;/P&gt;
&lt;P&gt;ip access-list extended v190_filter&lt;/P&gt;
&lt;P&gt;deny ip any 10.10.16.0 0.0.1.255&lt;/P&gt;
&lt;P&gt;deny ip any 10.10.32.0 0.0.1.255&lt;/P&gt;
&lt;P&gt;deny ip any 10.10.48.0 0.0.1.255&lt;/P&gt;
&lt;P&gt;.....&lt;/P&gt;
&lt;P&gt;deny ip any 10.10.192.0 0.0.1.255&lt;/P&gt;
&lt;P&gt;permit ip any any&lt;/P&gt;
&lt;P&gt;##################################&lt;/P&gt;
&lt;P&gt;This way it will be a long long entry...Plus I need to make the similar list for each client vlan. I would like to ask if anyway I can simplify the entries by summarizing network mask? IF so..may I ask what the answer would be...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your help in advance.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Takami Chiro&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3823764#M547860</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2020-02-21T19:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: couple access list questions to seperate vlans subnet</title>
      <link>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3823861#M547861</link>
      <description>1.) On each vlan which I only want them to be able to access to the server and dmz vlans but not other client vlan... on the vlan interface, shoudl I use access group IN...or OUT? Without asking here...I may pick IN... If I am wrong.. may you tell me why?&lt;BR /&gt;&lt;BR /&gt;You should configure your SVI acls both IN and OUT. Think of IN meaning coming into the interface from the local subnet &amp;amp; OUT as external subnets coming into that subnet.&lt;BR /&gt;&lt;BR /&gt;2.) For the access-list...&lt;BR /&gt;There are several ways you can accomplish this. You could use object groups to achieve what you want here. I think you will need to create separate acls as you mentioned above. You could potentially look into using Trustsec if you have ISE in your environment.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 21 Mar 2019 16:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3823861#M547861</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-21T16:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: couple access list questions to seperate vlans subnet</title>
      <link>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3824001#M547862</link>
      <description>&lt;P&gt;Mike, thank you very much&amp;nbsp; for your response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mentioned "&lt;SPAN&gt;You should configure your SVI acls both IN and OUT." Do you mean i should apply the same access list with in and out to the vlan? Thank you for clarifying the access In and out..as I was always confused about it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For your answer to question #2, may I ask if Trustsec is a product of software? May you provide an example how to implement object group?...would that reduce the number of entries in my ACL?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you very much again!&lt;BR /&gt;&lt;BR /&gt;Riderfaiz&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 21:36:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3824001#M547862</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2019-03-21T21:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: couple access list questions to seperate vlans subnet</title>
      <link>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3824010#M547863</link>
      <description>&lt;P&gt;Hi Mike, I just did a quick search on Trustsec and ISE... we are just a small shop and we do not even have AAA server... so I think I may have to just count on ACL for now...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;May you just help to clarify "Y&lt;SPAN&gt;ou should configure your SVI acls both IN and OUT" and does it mean I need to implement both in and out on the same access list that i will apply to a vlan?&lt;BR /&gt;&lt;BR /&gt;Thank you very much again.&lt;BR /&gt;&lt;BR /&gt;Riderfaiz&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 22:08:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3824010#M547863</guid>
      <dc:creator>riderfaiz</dc:creator>
      <dc:date>2019-03-21T22:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: couple access list questions to seperate vlans subnet</title>
      <link>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3824351#M547868</link>
      <description>Yes you can implement the same acl both in and out on your SVI. For example:&lt;BR /&gt;ip access-list ext ACL&lt;BR /&gt;permit ip host 8.8.8.8 any&lt;BR /&gt;permit ip any host 8.8.8.8 any&lt;BR /&gt;deny ip any any&lt;BR /&gt;&lt;BR /&gt;int vlan 2&lt;BR /&gt;ip access-group ACL in&lt;BR /&gt;ip access-group ACL out&lt;BR /&gt;&lt;BR /&gt;HTH!&lt;BR /&gt;</description>
      <pubDate>Fri, 22 Mar 2019 13:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couple-access-list-questions-to-seperate-vlans-subnet/m-p/3824351#M547868</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-22T13:10:43Z</dc:date>
    </item>
  </channel>
</rss>

