cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
633
Views
0
Helpful
1
Replies

Without Reflexive ACL

AntonyNewbie
Beginner
Beginner

Hi All...

I want to ask some question related with ACL.

There is a vlan Finance in my office. The requrement : Vlan Finance is allow to access internet and selected host/network and not allow to access internal network. But from internal network can access to Vlan Finance (Full access). I want to configure using Reflexive ACL, but from Datasheet 4500 doesn't support Reflexive ACL. Intervlan routing is in 4500.

Is there any ACL configuration to support my requirement without using Reflexive ACL?

Thanks...

1 Accepted Solution

Accepted Solutions

Jon Marshall
VIP Community Legend VIP Community Legend
VIP Community Legend

Antony

Unfortunately this is a job for reflexive acls as i suspect you know. If you need restrict finance from accessing the LAN but allow LAN to access finance you really do need reflexive acls or a stateful firewall either an ASA or a router running CBAC.

If the connections were only TCP you may be able to use the "established" keyword if the 4500 supports it but that won't help with non-TCP connections.

Jon

View solution in original post

1 Reply 1

Jon Marshall
VIP Community Legend VIP Community Legend
VIP Community Legend

Antony

Unfortunately this is a job for reflexive acls as i suspect you know. If you need restrict finance from accessing the LAN but allow LAN to access finance you really do need reflexive acls or a stateful firewall either an ASA or a router running CBAC.

If the connections were only TCP you may be able to use the "established" keyword if the 4500 supports it but that won't help with non-TCP connections.

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers