08-31-2006 06:38 AM - edited 03-03-2019 04:45 AM
Sorry about the elementary nature of this question. When an ACL is applied to say a VLAN's SVI in this way;
interface Vlan111
ip address 10.10.10.10 255.255.255.0
ip access-group 111 in
or
ip access-group 112 out
..does the traffic direction "in" refer to traffic towards the SVI from Vlan111 only or also towards the networks and associated SVIs from other VLANs across the routing engine as well? Similarly, would "out" refer to traffic towards VLAN 111 only from (through) it's SVI or also towards other SVI's across the routing engine? Thank you for any information.
08-31-2006 06:40 AM
Sorry the first sentence in my last paragraph should read;
..does the traffic direction "in" refer to traffic towards the SVI from Vlan111 only or also towards it from the networks and associated SVIs from other VLANs across the routing engine as well?
08-31-2006 06:53 AM
Bob
The direction in which the access list is applied is from the prespective of the router/switch. So an access list applied "in" will filter traffic from the devices attached in that VLAN coming into the router/switch to be routed. And an access list applied "out" will filter traffic from other VLANs routed out that VLAN to the attached devices.
HTH
Rick
08-31-2006 07:34 AM
Thank you Rick!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide