- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- access list on a vlan interface wont work!
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-21-2021 10:47 PM - last edited on тАО09-23-2021 08:38 AM by support_s
тАО09-21-2021 10:47 PM - last edited on тАО09-23-2021 08:38 AM by support_s
access list on a vlan interface wont work!
I have a core switch "HP 8206" connected through vlan 2 to an isp router which in turn connects me to my branch on subnet 192.168.2.1/24 through an isp router, im trying to control my vlan 1 traffic 192.168.1.1/24 to vlan 2 through an access list on the vlan 1 interface but it simply isn't working even after trying ip access-group acl in,out,vlan please help
ip access-group extended test
Deny ip 192.168.1.25 255.255.255.255 192.168.2.7 255.255.255.255
Permit ip any any
vlan 1
name "Server-VLAN"
untagged Trk45
ip address 192.168.1.1 255.255.255.0
ip access-group test in
vrrp vrid 1
virtual-ip-address 192.168.1.1
priority 255
enable
exit
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-21-2021 10:51 PM
тАО09-21-2021 10:51 PM
Re: access list on a vlan interface wont work!
Hi @dmsman !
This ACL should deny traffic sourced from single IP 192.168.1.25 to single IP 192.168.2.7, the rest is allowed. Is it really what you need to achieve? Just block IP traffic between those two single IP addresses?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-22-2021 12:42 AM - edited тАО09-22-2021 12:43 AM
тАО09-22-2021 12:42 AM - edited тАО09-22-2021 12:43 AM
Re: access list on a vlan interface wont work!
no this isn't the full acl this is just an example , the thing is the traffic is stil going as the acl isnt there
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-22-2021 04:26 AM - edited тАО09-22-2021 04:26 AM
тАО09-22-2021 04:26 AM - edited тАО09-22-2021 04:26 AM
Re: access list on a vlan interface wont work!
You need to be sure your hosts in Vlan 1 are using 192.168.1.1 as default gateway.
Another issue, sorry, I've overlooked it - you are using subnet masks in the ACL while you must use wildcard masks instead:
ip access-group extended test
Deny ip 192.168.1.25 0.0.0.0 192.168.2.7 0.0.0.0
Permit ip any any
Thus, if you want to block the whole subnet and the subnet has /24 mask (255.255.255.0), then the correct wildcard mask will be 0.0.0.255
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО09-25-2021 11:01 PM
тАО09-25-2021 11:01 PM
Re: access list on a vlan interface wont work!
-please is there a way to find hits on the access list on the vlan when i use access-group in or out? i could only find hits using show statistics aclv4 vlan x vlan
-what is the difference between access-group in/out/vlan?