cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1927
Views
0
Helpful
2
Replies

Are the ACLs stateful?

kurian
Level 1
Level 1

If I create an ACL on VLAN1 that allows traffic to destination IP:PORT on VLAN 2, will I be able to open a TCP connection to it? Will returning packets from the destination IP:PORT automatically be allowed back into VLAN1?

2 Replies 2

Tom Watts
VIP Alumni
VIP Alumni

Hi Kurian, on small business switch, the ACL applies as ingress only. So if you have an ACL applied to VLAN 1 that is permit to VLAN 2 there will not be any drop traffic.

 

I see what is your point that the traffic return from VLAN 2 back in to VLAN 1 therefore should be dropped, that is not the case - otherwise it would make the ACL nearly impossible to use with any efficiencies.

-Tom Please mark answered for helpful posts http://blogs.cisco.com/smallbusiness/

This is true if I only have ACLs on VLAN 1, but I will also have different ACLs on VLAN 2. Then ingress filtering will be applied on VLAN 2 and the response packets from VLAN 1 connections will not be allowed back unless I create matching rules on VLAN 2 right?