cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5167
Views
0
Helpful
5
Replies

access-lists on layer 3 switch

Benjamin Waldon
Level 1
Level 1

Hello,

I am going to be installing some layer three switches. I have a question about how access-lists work in this enviornment.

Enviornment:

Single switch, uses VLAN 10. Host1 is connected to port 1 and host 2 is connected to port 2. both ports are access ports for vlan 10. can I put an acl on vlan 10 that prevents host1 from talking to host 2? In other words, does the traffic have to flow from one vlan to another for the switch to compare it against the acl?

I am pretty sure that the acl wouldn't affect the traffic, but I just want to make sure.

Thanks,

Ben

1 Accepted Solution

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

benwaldon wrote:

Hello,

I am going to be installing some layer three switches. I have a question about how access-lists work in this enviornment.

Enviornment:

Single switch, uses VLAN 10. Host1 is connected to port 1 and host 2 is connected to port 2. both ports are access ports for vlan 10. can I put an acl on vlan 10 that prevents host1 from talking to host 2? In other words, does the traffic have to flow from one vlan to another for the switch to compare it against the acl?

I am pretty sure that the acl wouldn't affect the traffic, but I just want to make sure.

Thanks,

Ben

Ben

An acl applied to the L3 SVI for vlan 10 would not affect traffic between hosts in the same vlan. If you want limit traffic between hosts in the same vlan then you need use a VACL (Vlan acl).

Jon

View solution in original post

5 Replies 5

Jon Marshall
Hall of Fame
Hall of Fame

benwaldon wrote:

Hello,

I am going to be installing some layer three switches. I have a question about how access-lists work in this enviornment.

Enviornment:

Single switch, uses VLAN 10. Host1 is connected to port 1 and host 2 is connected to port 2. both ports are access ports for vlan 10. can I put an acl on vlan 10 that prevents host1 from talking to host 2? In other words, does the traffic have to flow from one vlan to another for the switch to compare it against the acl?

I am pretty sure that the acl wouldn't affect the traffic, but I just want to make sure.

Thanks,

Ben

Ben

An acl applied to the L3 SVI for vlan 10 would not affect traffic between hosts in the same vlan. If you want limit traffic between hosts in the same vlan then you need use a VACL (Vlan acl).

Jon

ooh very nice. thanks!

do you know of any white papers on virtual acls. I will do a search for it too, but if you have it handy, that would be great.

Does virtual ACLs require any specific licensing on the switch or a specific IOS version, etc?

Thanks,

Ben

benwaldon wrote:

ooh very nice. thanks!

do you know of any white papers on virtual acls. I will do a search for it too, but if you have it handy, that would be great.

Does virtual ACLs require any specific licensing on the switch or a specific IOS version, etc?

Thanks,

Ben

Ben

When you say virtual acls do you mean vlan acls ?

If so you can use the config guides for your relevant switch and there will be examples in their. Presumably you know how to find config docs for your switch ?

Jon

yeah, vlan acls, sorry. Okay thanks

Ben

No problem. Forgot to answer last question. They should come as standard on your switch so no special license or specific IOS.

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card