09-30-2014 09:47 AM - edited 03-07-2019 08:55 PM
Will this access list applied in the manner shown below prevent any traffic from traversing between or visitor network and production?
I really do not want guest network to be able to access production. There will be many production vlans that are 10.x.x.x something.
interface Vlan103
des visitor
ip address 192.168.2.254 255.255.255.0
ip access-group no-visit in
interface vlan 10
des production vlan
ip address 10.49.1.0 255.255.255.0
Extended IP access list no-visit
10 deny ip 192.168.2.0 0.0.0.255 10.0.0.0 0.255.255.255
20 permit ip any any
Solved! Go to Solution.
09-30-2014 11:09 AM
09-30-2014 11:09 AM
Yes this should work.
09-30-2014 11:32 AM
Thank you very much
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide