Hot Downloads

×

Notice

The forum is in read only mode.
Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1
  • 2

TOPIC: VLAN traffic blocking from and to other VLANS Cisco

Re: VLAN traffic blocking from and to other VLANS Cisco 10 years 3 weeks ago #33580

  • dxmen
  • dxmen's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 5
  • Thank you received: 0
Thanks Ammar, one more question and taking your example, if I need to block another VLAN for example VLAN3 (192.168.3.0) can I just add the subnet to the same ACL and then apply it to the VLAN3 interface or does it need to be another ACL's for example access-list 200?
code:
access-list 100 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 permit ip any any

applied
interface vlan1
ip access-group 100 in
interface vlan3
ip access-group 100 in

or

access-list 100 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 permit ip any any
access-list 200 deny ip 192.168.3.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 200 permit ip any any

applied
interface vlan1
ip access-group 100 in
interface vlan3
ip access-group 200 in


thanks so much in advance to everybody!

Re: VLAN traffic blocking from and to other VLANS Cisco 10 years 3 weeks ago #33581

  • S0lo
  • S0lo's Avatar
  • Offline
  • Moderator
  • Moderator
  • Posts: 1577
  • Karma: 3
  • Thank you received: 7
You're welcome dxmen :)

Both ways will work. But the second (i.e two separate ACLs) is more efficient. Because, having only one ACL with two deny statements will force the router to check both statements every time a packet passes through, one of the statements is always redundant, so that's a waste of CPU time.
Studying CCNP...

Ammar Muqaddas
Forum Moderator
www.firewall.cx

Re: VLAN traffic blocking from and to other VLANS Cisco 10 years 2 weeks ago #33585

  • dxmen
  • dxmen's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 5
  • Thank you received: 0
Great! thanks so much to all for all your help, now I have everything I need to complete what I need. Cheers!!
Regards

Re: VLAN traffic blocking from and to other VLANS Cisco 9 years 7 months ago #35011

I have 4 VLANs on a Cisco 4500 L3 switch
VLAN 2
VLAN 3
VLAN 4
VLAN 5
I want to block in / out traffic from VLAN 4 & 5 to VLAN 3, any suggestions? thanks


enjoy

www.ciscosysteme.com/en/US/products/hw/s...186a008013565f.shtml
  • Page:
  • 1
  • 2
Time to create page: 0.109 seconds

CCENT/CCNA

Cisco Routers

  • SSL WebVPN
  • Securing Routers
  • Policy Based Routing
  • Router on-a-Stick

VPN Security

  • Understand DMVPN
  • GRE/IPSec Configuration
  • Site-to-Site IPSec VPN
  • IPSec Modes

Cisco Help

  • VPN Client Windows 8
  • VPN Client Windows 7
  • CCP Display Problem
  • Cisco Support App.

Windows 2012

  • New Features
  • Licensing
  • Hyper-V / VDI
  • Install Hyper-V

Linux

  • File Permissions
  • Webmin
  • Groups - Users
  • Samba Setup