cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
467
Views
2
Helpful
5
Replies

Where to place a VACL

glsparks
Level 1
Level 1

Hi 

I'm looking to implement a VACL on a vlan to prevent three hosts talking to each other.

Now on hosts is on different switches connected via the core/distribution switch, the core hosts the VLAN SVI and default gateway.

So my question is. Does the VACL need to be on all 3 switches? 

Thanks in advance

5 Replies 5

host in same VLAN ? or in different VLAN ?

Same VLAN.

then use VLAN access-map
try use MAC if the three host get IP from DHCP server not static config 
VLAN access-map (VACL) Example Configuration on Cisco Switch (networkstraining.com)

you can also use Port ACL in each port connect to host to permit or deny traffic 

My question is actually not how to do it but where to put the configuration.

Is the configuration applied to all switches that have the VLAN on or only switches that have the hosts attached?

if that case then you need to config in VLAN in all SW, if the host in SW1 connect to host in SW2 the there is chance that the traffic bridge in SW2 not in SW1
So
I prefer you use Port ACL. 

Review Cisco Networking for a $25 gift card