05-07-2018 01:29 PM - edited 03-08-2019 02:56 PM
We plan on replacing our Nexus 7010 with a Nexus 9508
One challenge is that the Nexus 9508 does not support IPv4 ACL on Egress of the SVI
One solution is remove the VLAN interface and route to the traffic to a Firewall .
We are looking for other solutions
The purpose of the ACL is to limit traffic destined to the VLAN devices.
A restrictive vlan.
Thanks
05-07-2018 01:37 PM
The purpose of the ACL is to limit traffic destined to the VLAN devices.
How do you limit the traffic today using 7010?
If it is qos, firewalls may have more limited functionalities when it comes to QOS.
HTH
05-07-2018 01:42 PM
05-07-2018 01:59 PM
Another suggestion was a VACL.
VACL is used for blocking and forwarding within a vlan and not inbound or outbound to a vlan.
ip access-group LIMITACCESSOUT out
You did not post the ACL statement but if you have a deny statement, this will block all traffic and not limit traffic. Is that what you are trying to do?
HTH
05-15-2018 06:23 AM
by removing the logging option in the acl, we were able to apply the ACL
The posts were very helpful.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide