cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1035
Views
0
Helpful
5
Replies

Ip access list for L2 interface

fgasimzade
Level 4
Level 4

Simple question:

Is it possible to apply an ip access list to a Layer2 switchport configured as a trunk?

1 Accepted Solution

Accepted Solutions

Tshi M
Level 5
Level 5

I haven't done this but here is what i found:

"When applied to a trunk port, the ACL filters traffic on all VLANs present on the trunk port. When applied to a port with voice VLAN, the ACL filters traffic on both data and voice VLANs."

http://www.ciscopress.com/articles/article.asp?p=1181682&seqNum=4

View solution in original post

5 Replies 5

fgasimzade
Level 4
Level 4

Guys, its urgent, please..))

Hello,

You can use VACLs. The basic syntax is "vlan access-map" or check

http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/configuration/guide/vacl.html

Tshi M
Level 5
Level 5

I haven't done this but here is what i found:

"When applied to a trunk port, the ACL filters traffic on all VLANs present on the trunk port. When applied to a port with voice VLAN, the ACL filters traffic on both data and voice VLANs."

http://www.ciscopress.com/articles/article.asp?p=1181682&seqNum=4

Thank you!

Another question: is it possible to apply a policy-map configured with ACL to a trunk port?

This is what I found:

Unlike regular Cisco IOS standard or extended ACLs that are configured on router interfaces only and are applied on routed packets only, VACLs apply to all packets and can be applied to any VLAN or WAN interface.

It seems it doesnt to right with

"When applied to a trunk port, the ACL filters traffic on all VLANs present on the trunk port. When applied to a port with voice VLAN, the ACL filters traffic on both data and voice VLANs."

Review Cisco Networking for a $25 gift card