08-12-2005 12:44 PM - edited 03-02-2019 11:42 PM
Catalyst 3560
I'm want to block one particular local IP address from communicating with a server on a switch port, but allow all other IP addresses to communicate with it. Here is the ACL on the port the server is on:
deny host 10.16.5.138
permit any
Everything gets blocked when I put this ACL in place. How should the ACL read so I can do what I want to do?
08-14-2005 11:33 PM
Strange, this looks correct.
try :
permit any any
Does the 10.16.5.138 host get blocked at least ?
08-15-2005 12:40 AM
Did you consider if the trafic's direction is IN or OUT?
Maybe you only have to change IN to OUT with your access-group-command.
08-15-2005 12:44 AM
oops, traFFic of couse...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide