11-10-2009 09:46 AM - edited 03-06-2019 08:32 AM
Hello,
If I create an ACL with one statement "permit IP any any", will this have the effect of blocking all non-IP traffic due to the implicit "deny any any" ? I would like to block all non-IP traffic, IPX in particular, on an older switch.
Dave
11-10-2009 10:50 AM
Hello Dave,
no because you are configuring an IP focused ACL.
I don't think 3500 XL can route IPX but it can bridge IPX frames as they are valid ethernet frames.
what would be needed is an ACL that works on ethertype to describe what upper layer protocol you want to accept.
Again I don't think it is supported on C3500 XL
Hope to help
Giuseppe
11-10-2009 01:51 PM
For starters, 3500XL does not support IP ACL regardless of IOS version. It will support MAC-based ACL.
11-10-2009 02:09 PM
And yet I could configure this on a 3512XL running 12.0(5.4)WC1 :
Extended IP access list 101
permit ip any any
Hmmmmmmm .....
I guess the answer is that the implicit "deny any any" is in reality an implicit "deny IP any any".
I'll figure out another way, thanks for the replies.
Dave
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide