cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3774
Views
15
Helpful
6
Replies

What happens if you don't apply an access list to an interface? Does it have any affect on trafic?

David Kosek
Level 1
Level 1

I have quite a few switches that the previous admin created ACLs on but didn't assign them to an interface. These are mostly standard ACLs. Do those ACLs affect traffic? 

2 Accepted Solutions

Accepted Solutions

Reza Sharifi
Hall of Fame
Hall of Fame

If ACL is not applied to a physical interface or an SVI, it will not have any effect.

HTH

View solution in original post

gs.skills
Level 1
Level 1

Hello,

be aware that ACLs could be used for others purposes others than interface traffic filtering: like NAT, VLAN ACL, Policy Based Routing, filtering vty line access,...

So its perfectly valid to have some ACLs not applied to interfaces.

[EDIT]and many of those features do affect traffic[/EDIT]

Regards, Guillaume

View solution in original post

6 Replies 6

Reza Sharifi
Hall of Fame
Hall of Fame

If ACL is not applied to a physical interface or an SVI, it will not have any effect.

HTH

gs.skills
Level 1
Level 1

Hello,

be aware that ACLs could be used for others purposes others than interface traffic filtering: like NAT, VLAN ACL, Policy Based Routing, filtering vty line access,...

So its perfectly valid to have some ACLs not applied to interfaces.

[EDIT]and many of those features do affect traffic[/EDIT]

Regards, Guillaume

Guillaume makes an important point (+5 for that) and I would like to emphasize it. The general answer to the original question is that if an access list is not applied then it will not affect anything. But we need to remember that an access list can be used for many things other than traffic filtering on an interface using ip access-group.

 

HTH

 

Rick

HTH

Rick

Deepak Kumar
VIP Alumni
VIP Alumni

Hi, 

As you mention that he was created some ACL but didn't apply then it is waste of time. But make sure that there are many features/way to use ACL. Maybe he was used in Line VTY, route-map, debug testing, control panel etc. 

 

Regards,

Deepak Kumar

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

Joseph W. Doherty
Hall of Fame
Hall of Fame
Might an unused ACL affect traffic? Possibly, but very, very (very) unlikely.

In the case where an ACL isn't being used for any purpose, it still consumes RAM (the running config). RAM used to store an ACL is RAM unavailable for other usage. Again, though, very, very (very) unlikely.

David Kosek
Level 1
Level 1

Thanks for the replies!