03-27-2018 08:23 AM - edited 03-08-2019 02:25 PM
I have quite a few switches that the previous admin created ACLs on but didn't assign them to an interface. These are mostly standard ACLs. Do those ACLs affect traffic?
Solved! Go to Solution.
03-27-2018 08:28 AM
If ACL is not applied to a physical interface or an SVI, it will not have any effect.
HTH
03-27-2018 08:29 AM - edited 03-27-2018 08:34 AM
Hello,
be aware that ACLs could be used for others purposes others than interface traffic filtering: like NAT, VLAN ACL, Policy Based Routing, filtering vty line access,...
So its perfectly valid to have some ACLs not applied to interfaces.
[EDIT]and many of those features do affect traffic[/EDIT]
Regards, Guillaume
03-27-2018 08:28 AM
If ACL is not applied to a physical interface or an SVI, it will not have any effect.
HTH
03-27-2018 08:29 AM - edited 03-27-2018 08:34 AM
Hello,
be aware that ACLs could be used for others purposes others than interface traffic filtering: like NAT, VLAN ACL, Policy Based Routing, filtering vty line access,...
So its perfectly valid to have some ACLs not applied to interfaces.
[EDIT]and many of those features do affect traffic[/EDIT]
Regards, Guillaume
03-27-2018 08:39 AM
Guillaume makes an important point (+5 for that) and I would like to emphasize it. The general answer to the original question is that if an access list is not applied then it will not affect anything. But we need to remember that an access list can be used for many things other than traffic filtering on an interface using ip access-group.
HTH
Rick
03-27-2018 08:38 AM
Hi,
As you mention that he was created some ACL but didn't apply then it is waste of time. But make sure that there are many features/way to use ACL. Maybe he was used in Line VTY, route-map, debug testing, control panel etc.
Regards,
Deepak Kumar
03-27-2018 10:46 AM
06-05-2018 12:44 PM
Thanks for the replies!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide