09-13-2018 03:08 AM - edited 09-13-2018 03:10 AM
Solved! Go to Solution.
09-13-2018 03:26 AM
Don't know why you cannot apply an acl outbound but you can apply the acl inbound on your LAN interface.
Don't forget "permit ip any any" in your acl for all the other traffic.
Jon
09-13-2018 04:04 AM - edited 09-13-2018 04:19 AM
Thanks.
But isn't "permit ip any any" implicitly added on all lists.
I was expecting implicit permit for all other traffic.
Then, if you need to customise you could use:
"no permit any any" on the ACLs.
Also, I understand that ACLs rules are better written for INBOUND traffic because the rules are applied before reaching the router/core network. Thereby preventing unnecessary congestion.
Tell me, I’ll forget; Show me, I’ll remember; Involve me, I’ll understand
~ Chinese Proverb
09-13-2018 03:26 AM
Don't know why you cannot apply an acl outbound but you can apply the acl inbound on your LAN interface.
Don't forget "permit ip any any" in your acl for all the other traffic.
Jon
09-13-2018 04:04 AM - edited 09-13-2018 04:19 AM
Thanks.
But isn't "permit ip any any" implicitly added on all lists.
I was expecting implicit permit for all other traffic.
Then, if you need to customise you could use:
"no permit any any" on the ACLs.
Also, I understand that ACLs rules are better written for INBOUND traffic because the rules are applied before reaching the router/core network. Thereby preventing unnecessary congestion.
Tell me, I’ll forget; Show me, I’ll remember; Involve me, I’ll understand
~ Chinese Proverb
09-13-2018 05:08 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide