Skip to main content

VACLs

First time I heard about VLAN Access Lists (VACLs) I was pretty intimidated. What's this access-list that can affect traffic at the L2 level? Must be pretty fancy, huh? Turns out not so fancy.

The problem:
Under normal operations, ACLs can only filter traffic at L3 (i.e. they have to be applied to an interface in a specific direction.

The solution:
VACLs use ACLs too, but they stand on the powerful shoulders of the Access-Map format (Route-Map-Looking statements).

Configuration Steps
  1. Create an ACL
  2. Create a VLAN access-map and specify an action
  3. Apply the access-map to a SVI
Configuration commands:
ip access-list extended vacl_test
permit ip host 10.1.1.1 192.168.2.0 0.0.0.255
exit
!
vlan access-map vacl_test_map
match ip address list vact_test
action drop
vlan access-map vacl_test_map 20 (the 20's just a sequence number)
action forward
exit
!
vlan filter vacl_test_map vlan-list 1


Warning:Note that there may be a need to apply another ACL in the other direction (denying traffic from 192.168.2.0/24). In this case, just add that line in the ACL and, since it's already applied, no need to modify the VLAN access-map.

Although I wouldn't recommend filtering at this level in a large enterprise, this tool could be useful for smaller shops without a internal firewalls but with a need to segregate traffic. So go have fun!

Comments

  1. What are the best online casinos for players? | CasinoWow
    Here 메리트 카지노 주소 we look at our favourite casino, giving you the best real money slots, table games, live casinos, and more. 온카지노 Read leovegas more.

    ReplyDelete
  2. Then, the sixty five free spins shall be credited to your account. 7Bit Casino can also be|can be} super versatile in terms of|in relation to} withdrawals. There is extensive range|a variety} of options here, with “regular” fee methods together with EcoPayz, Neteller, Skrill and cryptocurrencies . Meanwhile, the most have the ability to|you possibly can} guess in one go is $10, which ensures you’ll be able to|be capable of|have the power to} make your $40 free chip final slightly longer! Eligible video games are limited to pokies, board video games, scratch cards 온 카지노 and Keno.

    ReplyDelete
  3. In the primary instance, you should to} attain out to the casino’s customer support groups by way of their website. If you can’t discover a resolution by way of customer support, ask to talk to the casino’s manager. If card video games aren’t your velocity, 텐벳 players on the lookout for a comparatively easy win ought to take a look at|try} the roulette and online craps tables. Any game at a casino that lets you make a cash guess , will permit you to win money. Online blackjack,online poker, online roulette, online craps, you name it.

    ReplyDelete

Post a Comment

Popular posts from this blog

Made it to Vegas

Well, I started by modifying my schedule , went all crazy on ACI sessions. Airport It was 107 degrees F when we got here. So very hot. Took a shuttle to the hotel then went to the Mandalay Bay and registered! Got check in PAssed by the Cisco Store and was pleasantly surprised to find the CCDA 200-310 Official Cert Guide, in hardcover. So picked it up! 200-310 DESGN Official Cert Guide I'll read through the book tonight to prepare for the many design sessions that I have. Looking forward to network.

Cisco Live! at Last

Many things have happened since my last post  and I will hopefully get a chance to update the blog. I am going to go to Cisco Live in Las Vegas in July so if you'd like to meet up just let me know. Here is my full schedule per now: Enterprise High Availability Design and Architecture - Sunday Troubleshooting BGP  | Extending ACI to Multiple Sites - Dual Site Deployment Deep Dive Opening Keynote - Accelerating Digital Transformation, Chuck Robbins, CEO, Cisco Systems, Inc Enterprise Campus Design: Multilayer Architectures and Design Principles Campus Wired LAN Deployment Using Cisco Validated Designs Workforce Experience Intelligent WAN (IWAN) Architecture  | How to setup an ACI fabric from scratch Is Your Branch and WAN Ready for Digital Transformation? Coding Class - Introduction to Git  | IWAN Design and Deployment Workshop OpenDNS Customer Story...