02-17-2011 01:04 PM - edited 03-06-2019 03:36 PM
Does Vlan ACL's restricts traffic only between hosts in the same vlan or does it also have the feature to restrict traffic between two different vlans?
For example if there are 4 layer 3 switches and all 4 switches have Vlan 10 spanned. We have configured Vlan ACL for Vlan 10 in one switch (suppose in switch 1). So when other switches (where vlan ACL is not configured) receive packet destined for vlan 10, at that point whether vlan ACl is executed or not in those switches where vlan ACL is not configured
02-17-2011 06:54 PM
Good question!
I haven't tested this but I would say it will work and it should be a benefit of using vlan map instead of normal acl,
I think all incoming traffic on the vlan will be checked by acl anyway.
02-17-2011 11:09 PM
Hi,
Does Vlan ACL's restricts traffic only between hosts in the same vlan or does it also have the feature to restrict traffic between two different vlans?
It is completely depends on how we configured ACL's, we can restrict traffic between vlans and also can restrict between host and host.
When all 4 switches have vlan 10 spanned and packet received from anyone switch that will pass untill ACL restricted.
Hope this clear you..
Please rate the helpfull posts.
Regards,
Naidu.
02-18-2011 01:49 AM
Hi,
VLAN ACL's can either check Layer 2 information or Layer 3 information but only in a VLAN, so for tracing traffic inter VLAN routed you have to setup normal ACL with Layer 3 information from the VLAN Interface IP.
But for more information look here:
Regards Martin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide