07-01-2012 01:52 AM - edited 03-07-2019 07:32 AM
Hi,
I would like to implement VLAN ACL on a layer 3 switch for filtering traffic between servers in the same VLAN. I have a doubt: I have several virtual server in this VLAN and I wonder if the VMware virtual switch will allow the virtual servers to bypass the VACL. Do you have any experience with this kind of implementation?
Thanks,
Matteo
Solved! Go to Solution.
07-01-2012 07:55 AM
Hi Matteo,
With a standard VMware vswitch the virtual servers will still be allowed to talk to each other. To filter traffic within the same vlan you would need to use a solution like the nexus 1000v and pvlans.
http://www.vmware.com/files/pdf/technology/cisco_vmware_virtualizing_the_datacenter.pdf
07-01-2012 01:21 PM
Hi Matteo,
Correct, if the VACL is defined only on the distribution switch and the servers are connected to the same access switch the traffic wouldn't be filtered unless the VACL was defined on the access switch too. Here is a good doc on the placement of VACLs http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_44_se/configuration/guide/swacl.html#wp1600472
07-01-2012 07:55 AM
Hi Matteo,
With a standard VMware vswitch the virtual servers will still be allowed to talk to each other. To filter traffic within the same vlan you would need to use a solution like the nexus 1000v and pvlans.
http://www.vmware.com/files/pdf/technology/cisco_vmware_virtualizing_the_datacenter.pdf
07-01-2012 12:23 PM
Thank you Brian. Just another question. Suppose to have a VACL applied on VLAN 10 the distribution and two servers in VLAN 10 connected to the same access switch. In this case, would the traffic between the two servers be filtered by the VACL? I would say no, but therefore when would the VACLs be applied effectively?
07-01-2012 01:21 PM
Hi Matteo,
Correct, if the VACL is defined only on the distribution switch and the servers are connected to the same access switch the traffic wouldn't be filtered unless the VACL was defined on the access switch too. Here is a good doc on the placement of VACLs http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_44_se/configuration/guide/swacl.html#wp1600472
07-03-2012 01:44 AM
Thanks.
Matteo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide