Applying ACL on cisco L3 switches

I really woudl recomment the layer 2 solution for wifi, but if you wanted to use L3 then the ACL will need to deny to all internal networks and permit internet only.

Using Layer 3 at the access layer

To be frank, if you have a 2811 as the core device and a couple of switches to hook up to it, you don''t really need any kind of hierarchy. There is absolutely no need for distribution layer in your setup.

ACL on L3 Switch

BTW, if you had a router, rather than a switch, you could use NBAR to truly restrict access to HTTP (i.e. not just port 80) and/or you might use reflective ACLs to restrict host A to just the port

People also like:

Get In Touch

Connect With Us

📱

Poland (Sales & Engineering HQ)

+48 22 538 72 19

📍

Headquarters & Manufacturing

ul. Postępu 14, 02-676 Warszawa, Poland