cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1167
Views
0
Helpful
4
Replies

Isolation a vlan with only internet access.

Kanwar
Level 1
Level 1

Hi,

I like to create one vlan and allow only tcp port 80. I am running layer three switches. we have multiple vlans running within the network. my question is that do I just apply an access list on layer three vlan interface inbound or both in and out. Thanks in advance

4 Replies 4

glen.grant
VIP Alumni
VIP Alumni

That should be all you need on your l3 switch . Whether you apply it both in or out is really up to you and how you want it to affect your traffic , if want only port 80 in and out then apply it in and out .

Thanks, how about the packets that are switched and not routed. does the access-list applies to them too.

Thanks

Hi,

you can apply ACLs to L2 interfaces and even VLANs.

But there are pretty complicated rules and limitations on 3550s.

See http://www.cisco.com/univercd/cc/td/doc/product/lan/c3550/12225se/3550scg/swacl.htm#wp1046692

for details.

Regards,

Milan

we have more then one vlan. I like to use an exteneded access-list on that perticular vlan.I like to allow dhcp request and port 80 only. what is best vlan map or exteneded access-list. so anyone who is on that vlan will have internet access only. Thanks