Go Back   TechArena Community > Technology > Networking & Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , , ,

Sponsored Links



Access control list and Virtual Local Area Networks Maps

Networking & Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 11-11-2008
Member
 
Join Date: Nov 2008
Posts: 45
Access control list and Virtual Local Area Networks Maps

The 3750 Command Reference states: "There can be only one VLAN map per VLAN and it is applied as packets are received by a VLAN."

Does "received by a VLAN" mean a packet that the 3750 forwards from one SVI to another or does it mean a packet that comes into a Gigabit Ethernet port that's a member of the VLAN? For access-groups, do the keywords IN and OUT always refer to physical ports (and never to SVIs or to the process of forwarding packets from one VLAN to another)?
Reply With Quote
  #2  
Old 11-11-2008
Marco-D's Avatar
Member
 
Join Date: May 2008
Posts: 181
Re: Access control list and Virtual Local Area Networks Maps

Quote:
Originally Posted by Nobleman View Post
The 3750 Command Reference states: "There can be only one VLAN map per VLAN and it is applied as packets are received by a VLAN."

Does "received by a VLAN" mean a packet that the 3750 forwards from one SVI to another or does it mean a packet that comes into a Gigabit Ethernet port that's a member of the VLAN? For access-groups, do the keywords IN and OUT always refer to physical ports (and never to SVIs or to the process of forwarding packets from one VLAN to another)?
Since a Vlan is Logical, It Means Comes IN and is processed by a Logical Vlan interface, which would be at any number of physical ingress points based on trunks or access ports. Since I really didn't answer your bigger question, an access-list is 'routed' traffic being processed by the SVI. The VACL or vlan map will impact intra-vlan traffic which an access-list does not. L2 vs L3.
Reply With Quote
  #3  
Old 11-11-2008
Member
 
Join Date: Nov 2008
Posts: 333
Re: Access control list and Virtual Local Area Networks Maps

Quote:
Originally Posted by Marco-D View Post
Since a Vlan is Logical, It Means Comes IN and is processed by a Logical Vlan interface, which would be at any number of physical ingress points based on trunks or access ports. Since I really didn't answer your bigger question, an access-list is 'routed' traffic being processed by the SVI. The VACL or vlan map will impact intra-vlan traffic which an access-list does not. L2 vs L3.
It seems to me that forwarding process from say, VLAN 10 to VLAN 20 would be another ingress point for VLAN 20.If this is not true, why not?
Reply With Quote
  #4  
Old 11-11-2008
Marco-D's Avatar
Member
 
Join Date: May 2008
Posts: 181
Re: Access control list and Virtual Local Area Networks Maps

Quote:
Originally Posted by The Edge View Post
It seems to me that forwarding process from say, VLAN 10 to VLAN 20 would be another ingress point for VLAN 20.If this is not true, why not?
I would agree with that, so I would assume that in that case, a vacl and an acl would both apply to that traffic.However, if it is vlan 10 to vlan 10, only a vacl would impact that traffic.I have never tried both at the same time, as I use ACLs for layer 3, and VACLs for sniffer ports, etc.Perhaps someone can correct me if a VACL only applies to intra-vlan traffic.
Reply With Quote
Reply

  TechArena Community > Technology > Networking & Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Access control list and Virtual Local Area Networks Maps"
Thread Thread Starter Forum Replies Last Post
discretionary access control list vs System Access Control List aconti Active Directory 2 13-10-2009 06:58 PM
Can't access "local area connection properties" on Windows Vista AK_Chopra Networking & Security 3 04-06-2009 12:04 AM
ACL ( Access Control List ) entry allowing tracert and traceroute Daljeet Networking & Security 3 02-12-2008 06:37 PM
Ethernet Multiple Networks detected, Local access only, Only one exists ghayman Windows Vista Network 2 29-06-2008 12:22 AM
Configuring Local Security Policy to control access to MSSQL DesktopEd daz_oldham Windows Server Help 4 03-06-2008 02:23 AM


All times are GMT +5.5. The time now is 05:43 AM.