01-06-2011 06:28 AM - edited 03-06-2019 02:51 PM
Hi,
I have a small question concerning in and out traffic direction on vlan interfaces, in combination with access lists
We have an 3845 integrated services router that has a network module installed
Specs of the network module
NME-XD-48ES-2S-P 12.2(35)SE5 C3750-IPBASE-M
On the network module I have created two vlans with a vlan interface for each vlan
vlan 500
name DEMO
!
vlan 516
name EDUCATION
interface Vlan500
ip address 10.5.0.1 255.255.240.0
!
interface Vlan516
ip address 10.5.16.1 255.255.240.0
I want to permit traffic from demo to education (and returning traffic) but i want to deny traffic originating from education to demo
What is the best way to implement this ?
----------------------
Second question is regarding traffic direction
Suppose traffic is coming from education and going to demo
Once the traffic has been routed on the switch from the eduction vlan interface and arrives at the demo vlan interface
Is this traffic going out of the demo interface or coming in on the demo interface (with access lists in mind)
Do I need to define this to apply an access list to that traffic ?
SW01(config)#interface vlan500
SW01(config-if)#ip acc
SW01(config-if)#ip acces
SW01(config-if)#ip access-group MYLIST out
Or do I need to define this to apply an access list to that traffic ?
BEVILro02-SW01(config)#interface vlan500
BEVILro02-SW01(config-if)#ip acc
BEVILro02-SW01(config-if)#ip acces
BEVILro02-SW01(config-if)#ip access-group MYLIST in
Or maybe both or possible ?
Thanks in advance !
Kind Regards
Stijn
01-09-2011 07:38 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide