09-10-2019 10:45 PM
using figure below, if I apply access-group <> in at interface gi0/0 which direction will router filter A or B?
Solved! Go to Solution.
09-10-2019 11:49 PM
09-11-2019 12:48 AM
It will take action in the direction of LAN to WAN (A).
Way I always remembered when I first started out - Picture yourself sitting at the interface in question facing the network it connects to.
Traffic coming IN towards your face would be matched against an Inbound access List.
Traffic coming from behind you (e.g traffic from other interfaces on the device) to then be sent out the Interface you are sitting at will be matched against an Outbound Access List.
In your case below.
You are sitting on Interface A looking out at the LAN. Traffic from the LAN comes towards you (Matches Inbound ACL).
If traffic were to come from the WAN to a device in the LAN - It would come from behind you, to then be forwarded Out towards the LAN.
09-10-2019 11:49 PM
Hi there,
The ACL will filter in direction A.
cheers,
Seb.
09-11-2019 12:48 AM
It will take action in the direction of LAN to WAN (A).
Way I always remembered when I first started out - Picture yourself sitting at the interface in question facing the network it connects to.
Traffic coming IN towards your face would be matched against an Inbound access List.
Traffic coming from behind you (e.g traffic from other interfaces on the device) to then be sent out the Interface you are sitting at will be matched against an Outbound Access List.
In your case below.
You are sitting on Interface A looking out at the LAN. Traffic from the LAN comes towards you (Matches Inbound ACL).
If traffic were to come from the WAN to a device in the LAN - It would come from behind you, to then be forwarded Out towards the LAN.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide