Dear all,
I have a problem understanding the acls applied to my 3550 L3-Switch SMI.
I want to separate different VLANs on the 3550 enabled for routing. VLAN 10 = 192.168.10.0 255.255.255.0 VLAN 20 = 192.168.20.0 255.255.255.0
The Default Gateways are the L3 SVI interface 192.168.10.254 and
192.168.20.254If I apply below acl inbound to the SVI of VLAN20
ip access-group 120 in
I can still ping from 10 to 20 and vice versa.
I have added a similar acl for subnet/VLAN 10. Same effect.
If I apply it to in and out. Access is effectively blocked. ip access-group 120 in ip access-group 120 out
Why does it not already work if I apply it inbound only??
I already checked the TCAM usage which is reported to show problems with the 3550. There are still enough free and the switch is processing in hardware.
Thanks for your hints, Alex
int vlan 20 ip address 192.168.20.254 255.255.255.0 ip access-group 120 in
ip access-list extended 120 remark --------------------------- remark Access to VLAN 20 remark allow DHCP permit udp any any eq bootpc permit udp any any eq bootpS remark - remark Access from the switch' L3 SVI, the Gateway itself permit ip 192.168.20.0 0.0.0.255 any remark Access from those VLANs permit ip 192.168.10.0 0.0.0.255 any exit