cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
719
Views
0
Helpful
1
Replies

Without Reflexive ACL

AntonyNewbie
Level 1
Level 1

Hi All...

I want to ask some question related with ACL.

There is a vlan Finance in my office. The requrement : Vlan Finance is allow to access internet and selected host/network and not allow to access internal network. But from internal network can access to Vlan Finance (Full access). I want to configure using Reflexive ACL, but from Datasheet 4500 doesn't support Reflexive ACL. Intervlan routing is in 4500.

Is there any ACL configuration to support my requirement without using Reflexive ACL?

Thanks...

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

Antony

Unfortunately this is a job for reflexive acls as i suspect you know. If you need restrict finance from accessing the LAN but allow LAN to access finance you really do need reflexive acls or a stateful firewall either an ASA or a router running CBAC.

If the connections were only TCP you may be able to use the "established" keyword if the 4500 supports it but that won't help with non-TCP connections.

Jon

View solution in original post

1 Reply 1

Jon Marshall
Hall of Fame
Hall of Fame

Antony

Unfortunately this is a job for reflexive acls as i suspect you know. If you need restrict finance from accessing the LAN but allow LAN to access finance you really do need reflexive acls or a stateful firewall either an ASA or a router running CBAC.

If the connections were only TCP you may be able to use the "established" keyword if the 4500 supports it but that won't help with non-TCP connections.

Jon