10-12-2021 01:29 PM - edited 10-12-2021 01:29 PM
Hi all,
we'd like to implement ACLs in our C9500 core switches. Could you please help with two (presumably quite easy) questions:
Thanks, BR,
mk24
Solved! Go to Solution.
10-12-2021 01:38 PM
Hello @mk24 ,
just a question are you going to apply ACLs to the SVI interfaces or you mean VLAN ACL VACLs ?
in first case (SVI) 2) is not needed as intra VLAN traffic does not hit the SVI
and 1) an implicit deny ip any any there should be at the end of the ACL
if you mean VACL 2) intra VLAN traffic needs to be permitited
Hope to help
Giuseppe
10-12-2021 01:38 PM
Hello @mk24 ,
just a question are you going to apply ACLs to the SVI interfaces or you mean VLAN ACL VACLs ?
in first case (SVI) 2) is not needed as intra VLAN traffic does not hit the SVI
and 1) an implicit deny ip any any there should be at the end of the ACL
if you mean VACL 2) intra VLAN traffic needs to be permitited
Hope to help
Giuseppe
10-13-2021 03:23 AM
Hi Giuseppe,
we are planning to apply the ACLs to the SVIs. So we won't need the permit for inter-vlan traffic and have to add an explicit deny at the end of every ACL.
Thanks for your help!
BR,
mk24
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide