cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1207
Views
0
Helpful
2
Replies

ACL in/out

chinpohpang851
Level 1
Level 1

using figure below, if I apply access-group <> in at interface gi0/0 which direction will router filter A or B?

acl.png

2 Accepted Solutions

Accepted Solutions

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

The ACL will filter in direction A.

 

cheers,

Seb.

View solution in original post

GRANT3779
Spotlight
Spotlight

It will take action in the direction of LAN to WAN (A).

 

Way I always remembered when I first started out - Picture yourself sitting at the interface in question facing the network it connects to.

 

Traffic coming IN towards your face would be matched against an Inbound access List.

 

Traffic coming from behind you (e.g traffic from other interfaces on the device) to then be sent out the Interface you are sitting at will be matched against an Outbound Access List.

 

In your case below.

 

You are sitting on Interface A looking out at the LAN. Traffic from the LAN comes towards you (Matches Inbound ACL).

If traffic were to come from the WAN to a device in the LAN - It would come from behind you, to then be forwarded Out towards the LAN.

View solution in original post

2 Replies 2

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

The ACL will filter in direction A.

 

cheers,

Seb.

GRANT3779
Spotlight
Spotlight

It will take action in the direction of LAN to WAN (A).

 

Way I always remembered when I first started out - Picture yourself sitting at the interface in question facing the network it connects to.

 

Traffic coming IN towards your face would be matched against an Inbound access List.

 

Traffic coming from behind you (e.g traffic from other interfaces on the device) to then be sent out the Interface you are sitting at will be matched against an Outbound Access List.

 

In your case below.

 

You are sitting on Interface A looking out at the LAN. Traffic from the LAN comes towards you (Matches Inbound ACL).

If traffic were to come from the WAN to a device in the LAN - It would come from behind you, to then be forwarded Out towards the LAN.

Review Cisco Networking for a $25 gift card